Skip to main content

VPN Logging Policies - What Providers Keep

Every VPN claims no logs - few prove it. We break down what VPNs can log, what no-log really means, and which providers have verified logging policies.

Updated August 15, 2026 VPN Daddy Team Fact-checked

What VPNs Can Log

Understanding logging starts with knowing what's technically possible to record. VPN logs fall into three categories:

  • Connection logs: when you connected and disconnected, your real IP, the VPN IP assigned, session duration
  • Activity logs: websites visited, files downloaded, DNS queries, per-site bandwidth - the most invasive type
  • Aggregate logs: total bandwidth or server load with no link to any individual - generally considered harmless

What "No-Log" Should Mean

A genuine no-log VPN keeps no connection logs and no activity logs. If subpoenaed or breached, there's simply nothing to reveal about who did what. Some providers retain minimal aggregate data (like total bandwidth for capacity planning), which is acceptable because it can't identify individual activity. The problem is that every VPN claims "no logs" - so the claim is only meaningful when it's verified.

Logging Policies by Provider

ProviderNo-Log ClaimVerified ByLast AuditJurisdiction
Mullvad Yes Cure53, Assured, Radically Open Security 2024-06 Sweden
ProtonVPN Yes Securitum 2024-04 Switzerland
NordVPN Yes Deloitte, PricewaterhouseCoopers 2024-06 Panama
IVPN Yes Cure53 2022-02 Gibraltar
ExpressVPN Yes KPMG, PricewaterhouseCoopers, Cure53 2024-09 British Virgin Islands
Surfshark Yes Deloitte, Cure53 2023-11 Netherlands
CyberGhost Yes Deloitte 2024-03 Romania
Private Internet Access Yes Deloitte + court-proven 2024-01 United States
Windscribe Yes Cure53 2024-05 Canada
hide.me Yes DefenseCode 2023-04 Malaysia
VyprVPN Yes Leviathan Security 2018-11 Switzerland
PrivadoVPN Yes Switzerland
Mozilla VPN Yes Cure53 2023-03 United States
TunnelBear Yes Cure53 2023-01 Canada
PureVPN Yes KPMG, Altius IT 2023-08 British Virgin Islands
IPVanish Yes Leviathan Security 2022-01 United States
ZoogVPN Yes Greece
FastestVPN Yes Altius IT 2023-02 Cayman Islands
StrongVPN Yes United States
Hotspot Shield Yes AV-TEST 2022-06 United States

All six maintain no-log policies verified by reputable auditors. The standouts: PIA is the only one court-proven, and NordVPN and ExpressVPN carry the most audits over the longest period.

72% Off Try NordVPN - $3.09/mo

Risk-free - 30-day money-back guarantee

How Policies Get Verified

  1. Independent audits: firms like Deloitte, KPMG, PwC, Cure53, and Securitum inspect servers, code, and data-handling processes
  2. Court records: when a provider is legally compelled and produces nothing (as PIA did), that's the strongest proof possible
  3. Open-source code: lets anyone confirm the app isn't logging behind the scenes
  4. RAM-only servers: hardware that can't retain data across a reboot makes long-term logging physically impossible

Logging Red Flags

Avoid a VPN if you spot any of these:

  • No independent audit - an unverified no-log claim is just marketing
  • Vague or contradictory policy - claims "no logs" but the privacy policy lists connection data it collects
  • Free VPNs with hidden costs - many fund themselves by logging and selling user data
  • History of handing over data - past incidents where a provider produced user logs despite a no-log claim

For the full breakdown of who audited whom and what each report covered, see our no-log VPN guide and VPN audits page.

Frequently Asked Questions

What does a VPN log?

It depends on the provider. Logs fall into three groups: connection logs (timestamps, your real IP, session length), activity logs (sites visited, files downloaded, DNS queries), and aggregate logs (total bandwidth for capacity planning, with no link to individuals). A true no-log VPN keeps no connection or activity logs at all.

Which VPNs have a verified no-log policy?

All six providers we review advertise a no-log policy and have been independently audited: NordVPN (Deloitte, PwC), ExpressVPN (KPMG, PwC, Cure53), Surfshark (Deloitte, Cure53), CyberGhost (Deloitte), PIA (Deloitte + court-proven), and ProtonVPN (Securitum). NordVPN and ExpressVPN have the most extensive audit histories.

Has a no-log policy ever been tested in court?

Once, decisively. Private Internet Access was subpoenaed by the FBI and had nothing to hand over. That real-world outcome carries more weight than any audit, because it shows behavior under actual legal pressure rather than a promise on paper.

Does jurisdiction affect logging?

It affects the legal pressure to log. Providers in Panama (NordVPN), the British Virgin Islands (ExpressVPN), or Switzerland (ProtonVPN) face no mandatory data-retention laws. US-based PIA sits in Five Eyes territory, yet its court-proven record shows actual data practices matter more than jurisdiction alone.