Millions of people choose a VPN to keep their online activity private. Most providers promise a strict no-logs policy, yet that promise only means something once you understand the law behind it. VPN jurisdiction is the country whose courts, intelligence agencies and data retention rules a provider must answer to, and it can decide whether a “we don’t keep logs” claim actually holds up when a government agency comes asking.

Many guides on this topic stop at listing the Five Eyes, Nine Eyes and 14 Eyes alliances. That’s a useful starting point, but it misses two things that matter just as much: the specific rules that apply to VPN users in the UK and Ireland, and the fact that a company’s marketed home base is often not the same as who actually owns and controls it. This article works through both, then gives you a practical checklist so you can check any provider’s legal footing for yourself.

What Is VPN Jurisdiction and Why It Matters

VPN jurisdiction refers to the country where a VPN company is legally registered and where its parent business is headquartered. That location determines which laws the provider has to follow: what data it can be ordered to hand over, whether it must retain connection logs by default, and how much say a court in that country has over its operations.

This matters because a VPN’s privacy promises are only as strong as the law standing behind them. A provider can build genuinely private software and still be legally required to log user activity if it operates from a country with mandatory data retention rules. A provider based somewhere with no such requirement has nothing to hand over even if a court orders it to, provided its no-logs claim is accurate and has been independently audited.

It helps to separate two related ideas here. The first is legal jurisdiction: which country’s courts and agencies can compel the company. The second is server location, which mostly affects things like which streaming library you can access, not your legal exposure. A VPN registered in Panama with a server in London still falls under Panamanian law for its own conduct, though UK authorities can, in some circumstances, act against the physical hardware located within UK borders. We’ll return to that distinction in the Corporate Ownership section below.

The Five, Nine, and 14 Eyes Alliances

Before looking at UK-specific law, it helps to understand the wider intelligence-sharing agreements a VPN’s home country might belong to. These alliances don’t create new logging rules by themselves, but they do determine which foreign governments can request the data a provider’s own country already holds.

Alliance Membership and Data-Sharing Treaties

The Five Eyes alliance links the United States, the United Kingdom, Canada, Australia and New Zealand in a long-standing intelligence-sharing arrangement. The Nine Eyes alliance extends that same cooperation to Denmark, France, the Netherlands and Norway, while the 14 Eyes (also called SSEUR) adds Germany, Belgium, Italy, Sweden and Spain.

Membership in one of these groups doesn’t automatically mean a VPN provider hands over user data. It means that if a member government requests information through the proper legal channels, allied countries have agreed, in principle, to cooperate on intelligence matters. For a VPN with no logs and no legal obligation to keep them, that cooperation has nothing to act on.

AllianceMember CountriesWhat It Means for VPN Users
Five EyesUS, UK, Canada, Australia, New ZealandClosest intelligence-sharing ties; the strongest reason to look outside these countries if avoiding alliance membership is a priority
Nine EyesFive Eyes plus Denmark, France, Netherlands, NorwayWider sharing network, though cooperation is less centralised than Five Eyes
14 EyesNine Eyes plus Germany, Belgium, Italy, Sweden, SpainBroadest network; an independently audited no-logs policy matters more than avoiding every member state

Why the Eyes Alliances Are Sometimes Overstated

Privacy marketing often treats alliance membership as the single most important factor in choosing a VPN, but that overstates what these agreements actually do. A no-logs provider based in a Five Eyes country with nothing recorded has no data to disclose, audited or not. A provider based well outside any alliance that secretly keeps logs offers no real protection at all.

Independent audits, published transparency reports and a provider’s track record when actually served with a request tell you far more than its postal address. Our piece on the myth of private browsing looks at how far VPNs and private browsing modes can genuinely protect you, and where their limits start. Alliance membership is one input among several, not a single test to pass or fail.

The UK and Ireland: Local Privacy Rules

The UK and Ireland deserve their own section because most guides written for a US audience skip over them entirely. Both countries sit inside overlapping legal systems: UK domestic surveillance law, EU-style data protection rules, and informal intelligence relationships that don’t map neatly onto the Eyes alliances above, and that make VPN jurisdiction work differently here than it does elsewhere.

The Investigatory Powers Act and Its Recent Changes

The Investigatory Powers Act 2016, sometimes called the IPA, is the main UK law governing bulk data collection, equipment interference and communications data retention by public authorities. It requires certain UK-based communication service providers to retain specific records and allows agencies to apply for bulk collection warrants under judicial oversight.

The Investigatory Powers (Amendment) Act 2024 changed several parts of this framework. It extended the maximum duration of bulk personal dataset warrants from six to twelve months and introduced a lighter-touch approval process for datasets where individuals have a low or no reasonable expectation of privacy, requiring sign-off from a Judicial Commissioner rather than a full warrant. The full text of these changes is available on the government’s legislation website.

For VPN users, the practical point is this: a VPN company registered and operated in the UK falls under this framework and can be compelled, through the proper legal process, to assist an investigation. A VPN registered outside the UK, with no UK operating entity, generally sits outside its reach, though the physical servers it rents inside UK borders can still be a target for other legal tools, such as equipment interference warrants.

Northern Ireland and Post-Brexit Data Divergence

Northern Ireland sits in an unusual position. It follows UK surveillance law under the Investigatory Powers Act, but its trading relationship with the EU under the post-Brexit arrangements means some data flows continue to reference EU adequacy decisions. This creates a layered compliance picture that few VPN guides address directly.

For a VPN user in Belfast or elsewhere in Northern Ireland, day-to-day advice doesn’t differ much from the rest of the UK: choose a provider with an independently audited no-logs policy, based outside the jurisdictions discussed here, and keep an eye on how UK data adequacy arrangements with the EU develop, since any change could affect how cross-border data requests are handled in future.

Ireland as a Tech Hub With Intelligence Caveats

The Republic of Ireland is a full EU member state and is therefore subject to the GDPR, giving residents strong formal data protection rights. Our guide to understanding GDPR implications covers what those rights mean in practice.

Ireland is not a formal member of the Five Eyes, Nine Eyes or 14 Eyes alliances. That said, its close economic and diplomatic ties to both the UK and the US mean informal intelligence cooperation is widely assumed to exist, even without a public treaty naming Ireland alongside those groups. Users based in Ireland benefit from strong GDPR rights on paper, but should still apply the same audited no-logs standard to any VPN provider, regardless of where it or its parent company is registered.

Corporate Ownership vs VPN Jurisdiction

Corporate Ownership vs VPN Jurisdiction

VPN jurisdiction on paper is not always where the decisions about a provider are actually made. Ownership structures can layer a privacy-friendly registration on top of a parent company based in a jurisdiction with far weaker protections, and that gap rarely appears in a provider’s marketing copy.

The Parent Company Problem

Consider ExpressVPN, which markets its jurisdiction as the British Virgin Islands, a location with no mandatory data retention law. ExpressVPN’s ultimate parent company, however, is Kape Technologies, which also owns CyberGhost and Private Internet Access. Kape itself was taken fully private in 2023 by Unikmind Holdings, a company controlled by businessman Teddy Sagi.

None of this means ExpressVPN’s privacy claims are false. It does mean that the entity setting corporate policy sits several layers away from the jurisdiction printed on the marketing page, and that a single owner can control several VPN brands that appear, on the surface, to be independent competitors. Before trusting a jurisdiction claim at face value, check who actually owns the company behind it, not just where its terms of service say it operates.

Can a Court Reach Across Borders?

Whether a court in one country can force a company registered in another to hand over data is a genuinely complicated area of law, and the answer depends heavily on the specific countries, treaties and type of data involved. Mutual legal assistance treaties allow governments to formally request cooperation from each other, and a parent company with assets or staff inside a requesting country’s borders can sometimes be pressured through that connection, even if the VPN entity itself is registered elsewhere.

This is why a VPN’s own audited no-logs status matters more than any single jurisdiction claim. If a company genuinely holds no identifying logs, there is nothing for any court, anywhere, to compel it to disclose. This isn’t legal advice for any specific situation, and readers with serious legal concerns about data requests should speak to a qualified privacy lawyer rather than rely on general guidance like this.

Which Jurisdictions Are Considered Safer for Privacy

VPN Jurisdiction, Which Jurisdictions

With the alliances and corporate structures covered, it’s useful to look at which VPN jurisdictions privacy advocates commonly point to as safer, and why those locations keep coming up.

Switzerland, Panama, and the British Virgin Islands

Switzerland sits outside the EU and outside any of the Eyes alliances. Its Federal Act on Data Protection, revised in 2023, gives residents GDPR-like rights, and Swiss law does not require VPN providers to retain connection logs by default. Proton VPN is one well-known example of a provider registered there.

Panama has no mandatory data retention law for VPN providers and is not a party to the international intelligence-sharing treaties discussed above, which is why several audited no-logs providers, including NordVPN, chose it as a base.

The British Virgin Islands, a UK overseas territory, has its own separate legal system with no domestic data retention requirement placed on VPN companies. It’s a common choice for VPN registration, though, as the ExpressVPN example above shows, the registration location doesn’t always tell you where a company’s actual decisions get made.

None of these locations makes a provider automatically trustworthy. They remove one legal pressure point, but an independent audit of the provider’s actual no-logs practice still matters more than the flag on its registration certificate.

Does VPN Jurisdiction Actually Matter for You? A Three-Tier Test

Not every VPN user faces the same level of risk, so it helps to work out which tier you fall into before worrying too much about VPN jurisdiction.

Tier one covers general browsing and streaming. If you’re mainly using a VPN to protect your connection on public WiFi or access a different country’s streaming library, jurisdiction is close to irrelevant. Server location for streaming performance matters more than the company’s legal home. Our guide on how VPNs work covers the basics of what encryption and IP masking actually do for you day to day.

Tier two covers remote workers and people bypassing local censorship, particularly if they travel to or live in a country with strict internet controls. Here, jurisdiction starts to matter more, since you want a provider whose home country isn’t allied with the government you’re trying to route around, and whose no-logs claim has been independently checked.

Tier three covers investigative journalists, activists, and anyone facing genuine legal or physical risk from having their online activity traced. At this level, jurisdiction, audited no-logs status, warrant canaries and the provider’s history of actually resisting legal requests all matter, and a single VPN alone probably isn’t enough protection without wider operational security practices.

Before trusting any provider with your traffic, run through these five checks.

  • VPN jurisdiction: find the company’s official registration, not just its marketing page, and check whether that country has mandatory data retention laws for VPN services.
  • Parent company ownership: search for who actually owns the brand, since a single parent can control several competing-looking VPN services.
  • Independent audit history: look for a published, dated audit from a recognised security firm, not just an internal claim of being no-logs.
  • Warrant canary or transparency report: check whether the provider publishes regular updates on legal requests received, and how it responds.
  • Track record under pressure: search for any documented case where the provider was asked to hand over data, and what actually happened as a result.

Run through this list for any provider before you commit to a subscription, and repeat it periodically, since ownership and audit status can change after you’ve already signed up.

Before You Choose a Provider

VPN jurisdiction is one part of a bigger picture, not the whole answer. Pair the checks above with good general habits, such as regularly reviewing your device and browser privacy settings. Our guide to open-source privacy tools for UK users is a good next step if you want to build a more complete privacy setup.

Have you checked your own VPN’s ownership and jurisdiction before? Tell us what you found, or ask a question about a specific provider, in the comments below. We read every comment and use them to shape what we cover next.

Frequently Asked Questions

Is it illegal to use a VPN in the UK?

No. Using a VPN is legal in the UK. What can be illegal is using one to carry out an activity that would already be illegal without a VPN, such as accessing copyrighted content without permission.

Does my VPN’s jurisdiction matter for streaming Netflix?

Not much. For streaming, the location of the server you connect to matters far more than where the company is legally based. Jurisdiction becomes relevant mainly when you’re worried about legal requests for your data, not about content libraries.

Can the UK government force a VPN to hand over my data?

A UK-based VPN provider can be compelled, through proper legal channels under the Investigatory Powers Act, to assist an investigation if it holds relevant data. A genuinely audited no-logs provider based outside the UK has nothing to hand over even if approached, though its actual response would still depend on the specific circumstances.

What is a warrant canary?

A warrant canary is a regularly published statement confirming a company hasn’t yet received a secret government data request. If the statement stops being updated or disappears, it can, though it doesn’t always, signal that something has changed.

Is Switzerland a better jurisdiction than Panama for a VPN?

Both are commonly recommended by privacy advocates. Switzerland offers GDPR-like protections under its Federal Act on Data Protection, while Panama has no mandatory data retention law at all. Neither is objectively better; both remove the specific legal pressure associated with Eyes alliance membership.

Does a 14 Eyes VPN jurisdiction automatically mean a provider is unsafe?

No. It raises the theoretical risk of intelligence cooperation between member governments, but a provider with a genuinely audited no-logs policy has no data to share regardless of which alliance its home country belongs to. Ownership structure and audit history matter as much as the country on the registration certificate.