so if i visiting xy.com and they trigger a cloudfalre challenge before showing me the data privacy rules and allow me to opt out they are violating the GDPR
the hoster of the website is allwoed to store the ip adress if: - the owner of the site has a "avv" (dont find the english term, data protection agreement)
but most privacy statements include a condition to allow free use of the ip adress. BUT if i want to do this i have to show the privacy statement BEFORE i collect the data. Same with 3-Party calls like challenges.cloudflare.com