Skip to main content

VPN Jurisdiction & Five Eyes Guide 2026

Understand how VPN jurisdiction, Five Eyes, Nine Eyes, and Fourteen Eyes surveillance alliances affect your privacy. Complete provider jurisdiction map and analysis.

Updated August 15, 2026 VPN Daddy Team Fact-checked

What Is VPN Jurisdiction?

VPN jurisdiction refers to the country where a VPN provider is legally incorporated and operates. This determines which government has legal authority over the company - and by extension, what data laws, surveillance obligations, and court orders the provider must comply with.

Jurisdiction matters for three reasons:

  • Data retention laws: Some countries legally require companies to store user data for months or years. If your VPN is based in such a country, they may be forced to log your activity regardless of their privacy policy.
  • Government compulsion: Law enforcement and intelligence agencies can issue legal demands (subpoenas, national security letters, court orders) requiring providers to hand over data or begin monitoring specific users.
  • Surveillance alliances: Countries in intelligence-sharing agreements (Five Eyes, Nine Eyes, Fourteen Eyes) share collected data with partner nations - meaning your data could be accessed by foreign governments even if your own country didn't collect it.

Five Eyes Surveillance Alliance

The Five Eyes alliance is the world's most powerful intelligence-sharing partnership, dating back to post-WWII signals intelligence cooperation. These five countries share virtually all collected intelligence data with each other:

  • United States - NSA (National Security Agency)
  • United Kingdom - GCHQ (Government Communications Headquarters)
  • Canada - CSE (Communications Security Establishment)
  • Australia - ASD (Australian Signals Directorate)
  • New Zealand - GCSB (Government Communications Security Bureau)

What this means for VPN users: A VPN based in a Five Eyes country could theoretically be compelled to monitor users on behalf of any partner nation. The US could request the UK's GCHQ to surveil a US citizen, then share the data back - circumventing domestic surveillance restrictions. Edward Snowden's leaks confirmed this practice.

However: Jurisdiction alone does not determine privacy. PIA is based in the United States (Five Eyes) yet has proven in court - twice - that it stores zero user data. A verified no-log policy means there is nothing to hand over, regardless of legal demands.

Nine Eyes & Fourteen Eyes Alliances

Nine Eyes

The Nine Eyes extends the Five Eyes partnership with four additional countries that share intelligence on a more limited basis:

  • All Five Eyes members, plus:
  • Denmark
  • France
  • Netherlands
  • Norway

Notable: Surfshark is based in the Netherlands (Nine Eyes member). Despite this, Dutch privacy laws under GDPR are strong, and Surfshark has been audited by Deloitte confirming no-log practices.

Fourteen Eyes (SIGINT Seniors Europe)

The broadest known surveillance alliance adds five more countries:

  • All Nine Eyes members, plus:
  • Germany
  • Belgium
  • Italy
  • Spain
  • Sweden

These countries share intelligence on a case-by-case basis rather than the blanket sharing of Five Eyes. The risk is lower than Five Eyes but still elevated compared to non-member nations.

Best VPN Jurisdictions

The ideal VPN jurisdiction has no data retention laws, sits outside all surveillance alliances, and has a legal framework that protects privacy. Here are the top jurisdictions and the major VPN providers based there:

JurisdictionProviderAllianceData RetentionWhy It's Good
Panama NordVPN None No mandatory retention No surveillance alliances, no data retention laws, no legal mechanism to compel logging
British Virgin Islands ExpressVPN None No mandatory retention UK Overseas Territory but self-governing - UK surveillance laws do not apply. No data retention legislation.
Switzerland ProtonVPN None No mandatory retention for VPNs Constitutional right to privacy, world's strongest data protection laws, centuries of neutrality
Romania CyberGhost None Struck down by courts Romania's Constitutional Court invalidated data retention laws twice (2009, 2014) as unconstitutional
72% Off Try NordVPN - $3.09/mo

Risk-free - 30-day money-back guarantee

Provider Jurisdiction Map

Here's where every major VPN provider is legally based, along with their surveillance alliance status and whether this creates practical privacy concerns:

ProviderJurisdictionAlliance StatusRisk LevelMitigating Factors
NordVPN Panama Outside all alliances Low No data retention laws, triple audited (Deloitte + PwC)
ExpressVPN British Virgin Islands Outside all alliances Low Self-governing territory, RAM-only servers, KPMG audited
Surfshark Netherlands Nine Eyes Medium GDPR protections, Deloitte audited no-log, strong Dutch privacy law
CyberGhost Romania Outside all alliances Low Data retention struck down twice, Deloitte audited
PIA United States Five Eyes Medium Court-proven no logs (FBI subpoena), Deloitte audited, fully open-source
ProtonVPN Switzerland Outside all alliances Low Constitutional privacy rights, Securitum audited, fully open-source

Key insight: The "best" jurisdiction is one where a verified no-log policy operates. Panama, BVI, and Switzerland offer the strongest legal privacy frameworks - but even PIA in the United States has demonstrated that operational practices (keeping no data) matter more than geographic location. Choose a VPN with both a good jurisdiction and verified no-log audits for maximum privacy assurance. See our full no-log VPN rankings for detailed analysis.

Frequently Asked Questions

Does VPN jurisdiction really matter?

Yes, but less than you might think. Jurisdiction determines what laws the provider must obey - data retention mandates, government compulsion for data, and surveillance alliance membership. However, a VPN that keeps no logs (verified by audits) has nothing to hand over regardless of jurisdiction. PIA proved this in US courts. Jurisdiction is a secondary concern after verified no-log policies.

What is the best country for a VPN to be based in?

Panama (NordVPN), British Virgin Islands (ExpressVPN), and Switzerland (ProtonVPN) are the best VPN jurisdictions. All three have no mandatory data retention laws, are outside surveillance alliances, and have legal frameworks that protect privacy. Switzerland additionally has constitutional privacy protections and a centuries-long tradition of neutrality.

Is NordVPN safe despite being in Panama?

NordVPN is safe precisely because it is in Panama. Panama has no data retention laws, is not a member of any surveillance alliance, and has no legal mechanism to compel VPN providers to log user data. Combined with triple independent audits (Deloitte, PwC) confirming no logs, Panama is an ideal VPN jurisdiction.

Should I avoid VPNs based in Five Eyes countries?

Not necessarily. PIA (US-based, Five Eyes) has proven in court it keeps zero logs. If a VPN truly stores no data, jurisdiction becomes less relevant - there is nothing to hand over. However, all else being equal, a privacy-friendly jurisdiction reduces theoretical risk. Five Eyes VPNs face more legal pressure to start logging in the future.