Pages here are compiled from public provider materials and third-party reports, with editorial review. Pricing figures were last checked September 2, 2026 and can change — confirm on the provider site before you buy. First-party tests appear on review pages when dated results are published. Corrections: contact@ccll-digital.com. How we rank.

VPN Guide

VPN Jurisdiction Explained

Reviewed April 15, 2026

The country where a VPN is **legally headquartered** affects what data the company can be compelled to share with governments. A VPN based in Switzerland operates under different laws than one based in the United States — and those laws determine whether your provider can be forced to log, retain, or hand over user data. This guide explains the **5 Eyes**, **9 Eyes**, and **14 Eyes** intelligence-sharing alliances, the privacy-friendly jurisdictions VPNs prefer, and why jurisdiction is one of the most important — but most misunderstood — factors in VPN selection.

Editorial shortlist

Need a VPN recommendation now?

Skip the theory — compare our top-rated VPNs for US users, with pricing, privacy notes, and setup guides.

See all VPN reviewsCompare providers

The 5/9/14 Eyes Alliances

These are intelligence-sharing agreements between governments. Member countries share signals intelligence with each other, including communications data collected from companies based in their jurisdiction.

Five Eyes (FVEY) — United States, United Kingdom, Canada, Australia, New Zealand. The original Cold War-era alliance, with the deepest intelligence-sharing arrangements.

Nine Eyes — Adds Denmark, France, Netherlands, Norway to the Five Eyes.

Fourteen Eyes (SIGINT Seniors Europe) — Adds Belgium, Germany, Italy, Spain, Sweden to the Nine Eyes.

If a VPN is based in any of these countries, it may be subject to data requests, gag orders, and intelligence-sharing arrangements that could compromise user privacy. This is why many privacy advocates recommend VPNs based outside these alliances.

Privacy Havens: Switzerland, Panama, BVI, and Beyond

Several VPN providers have intentionally based themselves in countries with strong privacy laws and no mandatory data-retention requirements:

  • Switzerland — ProtonVPN. Strong constitutional privacy protections, no mandatory data retention for VPNs, and outside all Eyes alliances.
  • Panama — NordVPN. No data retention laws, strong privacy protections, no Eyes membership.
  • British Virgin Islands (BVI) — ExpressVPN, Surfshark. UK overseas territory but with its own privacy-friendly laws and no data retention requirements. (Surfshark merged with Nord Security but retains BVI incorporation.)
  • Romania — CyberGhost. EU member but historically resistant to data retention mandates (its constitutional court struck down EU data retention laws).
  • Sweden — Mullvad. Despite being a 14 Eyes member, Mullvad's RAM-only servers and no-account-required signup make logs structurally impossible.

A US-based provider like Private Internet Access can still maintain credible privacy policies — Private Internet Access has had its policy reported in two federal court cases — but it operates under a fundamentally different legal regime than a Swiss or Panamanian provider.

Why US Jurisdiction Isn't Always Bad

The US doesn't have mandatory VPN data retention laws (unlike the EU's now-struck-down Data Retention Directive). A US-based VPN with a true privacy policy and RAM-only servers can refuse data requests by simply having nothing to provide.

Private Internet Access is the case study here. Despite being US-based, Private Internet Access's privacy policy has been reported twice in federal court (2016 and 2018) — when subpoenaed, the company had no user data to hand over. This 'publicly documented' status is in some ways stronger evidence than any reported.

The lesson: jurisdiction is one factor, but it's not deterministic. A US-based provider with strong technical privacy enforcement can be more private than a Panamanian provider with sloppy security practices.

What About Russia, China, and Other High-Risk Jurisdictions?

Avoid VPN providers based in countries with mandatory cooperation with state surveillance or active hostility to encryption:

  • Russia — Mandatory VPN registration with state authorities; non-compliant VPNs are blocked. Several providers have shut down Russian operations rather than comply.
  • China — VPNs require government approval; unauthorized providers are blocked or compromised.
  • Iran, North Korea, Belarus — Similar restrictive regimes.

Reputable VPNs do not market services to or operate in these jurisdictions. StatesVPN's editorial policy excludes recommendations for any provider operating in sanctioned or surveillance-mandated markets.

Jurisdiction vs. Audit: What Matters More?

If you have to choose between two factors, a recent published disclosure + RAM-only servers is generally stronger evidence of privacy than jurisdiction alone. A Swiss provider that has never been reported is less trustworthy than a US provider with multiple public provider materials and court-published privacy.

That said, the best VPNs combine both: privacy-friendly jurisdiction (BVI, Panama, Switzerland) plus published disclosures plus RAM-only architecture. ExpressVPN (BVI + public provider materials/public provider materials/public provider materials + TrustedServer), NordVPN (Panama + public provider materials/public provider materials + RAM-only), and ProtonVPN (Switzerland + public provider materials audits + open-source clients) all check every box.

Frequently Asked Questions

Continue comparing

Reviewed Sep 2026 · Public-source research · First-party tests appear on review pages when dated results are published · Verify details on provider sites. Editorial policy & scoring