Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
MizbanCloud is an Iranian cloud infrastructure and CDN provider offering hosting, DNS, object storage and video streaming, with all data residing on servers inside Iran.
MizbanCloud is an Iranian cloud infrastructure provider that delivers content delivery network services, cloud DNS, virtual servers, cloud object storage and video and live streaming. Its primary market is organisations operating inside Iran, including both private companies and public sector clients. When a website is served through MizbanCloud, page assets and traffic are routed through edge nodes and origin servers that the company operates within Iranian territory.
As a CDN and hosting layer, MizbanCloud necessarily processes connection metadata such as IP addresses, request headers, user agent strings and timestamps in order to route, cache and protect traffic. The hosted application and its control panel may set first party session cookies for authentication and load balancing. Edge logging retains access records that can identify individual visitors, which makes the underlying data personal data under the GDPR even where MizbanCloud frames it as purely technical.
Under the ePrivacy Directive, any non essential cookies set on the visitor device require prior consent, while strictly necessary session and security cookies can rely on an exemption. Under the GDPR the dominant issue is location: routing personal data to servers inside Iran is a transfer to a third country with no European Commission adequacy decision. Controllers must therefore identify an appropriate safeguard, and in practice the standard contractual clause route is very hard to operationalise with Iranian providers.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because adequacy and standard contractual clauses are not realistically available, a controller relying on MizbanCloud for EU facing services would likely have to fall back on the narrow derogations in Article 49, such as explicit informed consent for the specific transfer. That consent must be granular, freely given and clearly explain the risks of sending data to Iran. Organisations should also confirm that sanctions and export control rules do not prohibit the arrangement before processing begins.
For EU and EEA audiences the safest path is usually to serve traffic through an adequacy covered or EU hosted CDN rather than through Iranian infrastructure. Where MizbanCloud is genuinely required, document a data protection impact assessment, map exactly which personal data leaves the EEA, minimise log retention, and present clear consent and notice to visitors. Maintain records of processing and review the arrangement regularly against changing sanctions and supervisory authority guidance.
Websites using MizbanCloud must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is strongly recommended. Hosting and CDN delivery from servers inside Iran means EU personal data is transferred to a third country with no adequacy decision and no practical standard contractual clause route, creating significant transfer risk. Assess the categories of personal data routed through Iranian edge nodes, log retention, government access exposure, sanctions screening, and whether equivalent EU or adequacy covered providers can be used instead.
Sample consent text
This site is delivered through MizbanCloud, a content delivery and hosting provider with infrastructure located in Iran. By continuing you consent to your connection data and any non essential cookies being processed on servers outside the European Economic Area. You can withdraw consent at any time in our cookie settings.
Third-party domains contacted
mizbancloud.comcdn.mizbancloud.companel.mizbancloud.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| session | Necessary | Session | Maintains the authenticated session for the MizbanCloud control panel and hosted application. |
| csrftoken | Necessary | 1 year | Protects control panel forms against cross site request forgery. |
| __cf_edge | Necessary | Session | Edge routing and load balancing token used to direct the request to the correct CDN node. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
MizbanCloud itself, as a CDN and hosting layer, mainly relies on strictly necessary cookies such as a session cookie, a CSRF protection token and an edge routing token. The hosted website may add its own analytics or marketing cookies on top, which are the publisher's responsibility.
Consent is not required for the strictly necessary session and security cookies that keep the service working. Consent is required for any non essential analytics or marketing cookies set by the hosted site, and a clear notice should also cover the transfer of connection data to Iran.
Strictly necessary operational and security logging can rely on legitimate interest, while any non essential tracking needs consent under the ePrivacy Directive. Because data is hosted in Iran, controllers also need a valid Article 49 transfer basis, typically explicit consent.
Yes. MizbanCloud operates its infrastructure inside Iran, which is a third country without an EU adequacy decision. Serving EU visitors through MizbanCloud sends their connection data to Iran and triggers Chapter V transfer obligations.
A DPIA is strongly advised whenever you route EU personal data through Iranian infrastructure, because the transfer risk and potential government access are high. The assessment should document the data flows, safeguards and whether an EU based alternative is feasible.
Map exactly which personal data passes through MizbanCloud, minimise log retention, and provide a clear consent and notice explaining the Iran transfer. For EU audiences, strongly consider an adequacy covered or EU hosted CDN instead, and complete sanctions screening before use.
EU or EEA hosted CDNs and adequacy covered providers such as Cloudflare, Bunny, Fastly or a regional European CDN avoid the Iran transfer problem entirely. These offer standard contractual clauses and clearer data residency for European audiences.
List the strictly necessary MizbanCloud cookies with their purpose and duration, disclose that hosting and delivery occur on servers in Iran, and name the third country transfer. Keep the policy aligned with your consent banner and review it whenever the setup changes.