If you're in Europe and it happens on the website of a European company: make it a GDPR case. If you need to solve a captcha to access the privacy policy, they are clearly in violation.
Privacy policies need to be immediately accessible to users. Hiding your privacy info page behind captchas, using unclear names for links ("service status" as a link to privacy info for example), making users click through multiple pages to find it etc makes you non-compliant.
Basically: you cannot hide the information, you cannot make users jump through hoops (captchas, require signup/login, pay for accessing) to read them.
It really shouldn't, because the site owner is the one making the choice to use CF; CF is acting on their behalf (and the security-settings the site owner chooses at CF does influence whether and how often captchas are shown to users, i.e. "I'm under attack" mode). It would be different if the user's ISP did this.
This is another related issue, too, as CF is a data processor, so the controller (=site owner) needs to make users aware that their data is being shared with CloudFlare, as SSL terminates at CF, the content is analyzed and it's then (optionally re-encrypted) transmitted to the origin.
I route all my traffic via mmy own vpn server at Hetzner for privacy and security reasons and this Cloudflare bullshit is infuriating at times.
Besides I guess 95% sites that use their free tier either don't actually need it or would be better off without it.