VPN Jurisdiction & Five Eyes Guide 2026
Understand how VPN jurisdiction, Five Eyes, Nine Eyes, and Fourteen Eyes surveillance alliances affect your privacy. Complete provider jurisdiction map and analysis.
What Is VPN Jurisdiction?
VPN jurisdiction refers to the country where a VPN provider is legally incorporated and operates. This determines which government has legal authority over the company - and by extension, what data laws, surveillance obligations, and court orders the provider must comply with.
Jurisdiction matters for three reasons:
- Data retention laws: Some countries legally require companies to store user data for months or years. If your VPN is based in such a country, they may be forced to log your activity regardless of their privacy policy.
- Government compulsion: Law enforcement and intelligence agencies can issue legal demands (subpoenas, national security letters, court orders) requiring providers to hand over data or begin monitoring specific users.
- Surveillance alliances: Countries in intelligence-sharing agreements (Five Eyes, Nine Eyes, Fourteen Eyes) share collected data with partner nations - meaning your data could be accessed by foreign governments even if your own country didn't collect it.
Five Eyes Surveillance Alliance
The Five Eyes alliance is the world's most powerful intelligence-sharing partnership, dating back to post-WWII signals intelligence cooperation. These five countries share virtually all collected intelligence data with each other:
- United States - NSA (National Security Agency)
- United Kingdom - GCHQ (Government Communications Headquarters)
- Canada - CSE (Communications Security Establishment)
- Australia - ASD (Australian Signals Directorate)
- New Zealand - GCSB (Government Communications Security Bureau)
What this means for VPN users: A VPN based in a Five Eyes country could theoretically be compelled to monitor users on behalf of any partner nation. The US could request the UK's GCHQ to surveil a US citizen, then share the data back - circumventing domestic surveillance restrictions. Edward Snowden's leaks confirmed this practice.
However: Jurisdiction alone does not determine privacy. PIA is based in the United States (Five Eyes) yet has proven in court - twice - that it stores zero user data. A verified no-log policy means there is nothing to hand over, regardless of legal demands.
Nine Eyes & Fourteen Eyes Alliances
Nine Eyes
The Nine Eyes extends the Five Eyes partnership with four additional countries that share intelligence on a more limited basis:
- All Five Eyes members, plus:
- Denmark
- France
- Netherlands
- Norway
Notable: Surfshark is based in the Netherlands (Nine Eyes member). Despite this, Dutch privacy laws under GDPR are strong, and Surfshark has been audited by Deloitte confirming no-log practices.
Fourteen Eyes (SIGINT Seniors Europe)
The broadest known surveillance alliance adds five more countries:
- All Nine Eyes members, plus:
- Germany
- Belgium
- Italy
- Spain
- Sweden
These countries share intelligence on a case-by-case basis rather than the blanket sharing of Five Eyes. The risk is lower than Five Eyes but still elevated compared to non-member nations.
Best VPN Jurisdictions
The ideal VPN jurisdiction has no data retention laws, sits outside all surveillance alliances, and has a legal framework that protects privacy. Here are the top jurisdictions and the major VPN providers based there:
| Jurisdiction | Provider | Alliance | Data Retention | Why It's Good |
|---|---|---|---|---|
| Panama | NordVPN | None | No mandatory retention | No surveillance alliances, no data retention laws, no legal mechanism to compel logging |
| British Virgin Islands | ExpressVPN | None | No mandatory retention | UK Overseas Territory but self-governing - UK surveillance laws do not apply. No data retention legislation. |
| Switzerland | ProtonVPN | None | No mandatory retention for VPNs | Constitutional right to privacy, world's strongest data protection laws, centuries of neutrality |
| Romania | CyberGhost | None | Struck down by courts | Romania's Constitutional Court invalidated data retention laws twice (2009, 2014) as unconstitutional |
Risk-free - 30-day money-back guarantee
Provider Jurisdiction Map
Here's where every major VPN provider is legally based, along with their surveillance alliance status and whether this creates practical privacy concerns:
| Provider | Jurisdiction | Alliance Status | Risk Level | Mitigating Factors |
|---|---|---|---|---|
| NordVPN | Panama | Outside all alliances | Low | No data retention laws, triple audited (Deloitte + PwC) |
| ExpressVPN | British Virgin Islands | Outside all alliances | Low | Self-governing territory, RAM-only servers, KPMG audited |
| Surfshark | Netherlands | Nine Eyes | Medium | GDPR protections, Deloitte audited no-log, strong Dutch privacy law |
| CyberGhost | Romania | Outside all alliances | Low | Data retention struck down twice, Deloitte audited |
| PIA | United States | Five Eyes | Medium | Court-proven no logs (FBI subpoena), Deloitte audited, fully open-source |
| ProtonVPN | Switzerland | Outside all alliances | Low | Constitutional privacy rights, Securitum audited, fully open-source |
Key insight: The "best" jurisdiction is one where a verified no-log policy operates. Panama, BVI, and Switzerland offer the strongest legal privacy frameworks - but even PIA in the United States has demonstrated that operational practices (keeping no data) matter more than geographic location. Choose a VPN with both a good jurisdiction and verified no-log audits for maximum privacy assurance. See our full no-log VPN rankings for detailed analysis.