VPN Guide
VPN Jurisdiction Explained
The country where a VPN is **legally headquartered** affects what data the company can be compelled to share with governments. A VPN based in Switzerland operates under different laws than one based in the United States — and those laws determine whether your provider can be forced to log, retain, or hand over user data. This guide explains the **5 Eyes**, **9 Eyes**, and **14 Eyes** intelligence-sharing alliances, the privacy-friendly jurisdictions VPNs prefer, and why jurisdiction is one of the most important — but most misunderstood — factors in VPN selection.
Editorial shortlist
Need a VPN recommendation now?
Skip the theory — compare our top-rated VPNs for US users, with pricing, privacy notes, and setup guides.
See all VPN reviewsCompare providersThe 5/9/14 Eyes Alliances
These are intelligence-sharing agreements between governments. Member countries share signals intelligence with each other, including communications data collected from companies based in their jurisdiction.
Five Eyes (FVEY) — United States, United Kingdom, Canada, Australia, New Zealand. The original Cold War-era alliance, with the deepest intelligence-sharing arrangements.
Nine Eyes — Adds Denmark, France, Netherlands, Norway to the Five Eyes.
Fourteen Eyes (SIGINT Seniors Europe) — Adds Belgium, Germany, Italy, Spain, Sweden to the Nine Eyes.
If a VPN is based in any of these countries, it may be subject to data requests, gag orders, and intelligence-sharing arrangements that could compromise user privacy. This is why many privacy advocates recommend VPNs based outside these alliances.
Privacy Havens: Switzerland, Panama, BVI, and Beyond
Several VPN providers have intentionally based themselves in countries with strong privacy laws and no mandatory data-retention requirements:
- Switzerland — ProtonVPN. Strong constitutional privacy protections, no mandatory data retention for VPNs, and outside all Eyes alliances.
- Panama — NordVPN. No data retention laws, strong privacy protections, no Eyes membership.
- British Virgin Islands (BVI) — ExpressVPN, Surfshark. UK overseas territory but with its own privacy-friendly laws and no data retention requirements. (Surfshark merged with Nord Security but retains BVI incorporation.)
- Romania — CyberGhost. EU member but historically resistant to data retention mandates (its constitutional court struck down EU data retention laws).
- Sweden — Mullvad. Despite being a 14 Eyes member, Mullvad's RAM-only servers and no-account-required signup make logs structurally impossible.
A US-based provider like Private Internet Access can still maintain credible privacy policies — Private Internet Access has had its policy reported in two federal court cases — but it operates under a fundamentally different legal regime than a Swiss or Panamanian provider.
Why US Jurisdiction Isn't Always Bad
The US doesn't have mandatory VPN data retention laws (unlike the EU's now-struck-down Data Retention Directive). A US-based VPN with a true privacy policy and RAM-only servers can refuse data requests by simply having nothing to provide.
Private Internet Access is the case study here. Despite being US-based, Private Internet Access's privacy policy has been reported twice in federal court (2016 and 2018) — when subpoenaed, the company had no user data to hand over. This 'publicly documented' status is in some ways stronger evidence than any reported.
The lesson: jurisdiction is one factor, but it's not deterministic. A US-based provider with strong technical privacy enforcement can be more private than a Panamanian provider with sloppy security practices.
What About Russia, China, and Other High-Risk Jurisdictions?
Avoid VPN providers based in countries with mandatory cooperation with state surveillance or active hostility to encryption:
- Russia — Mandatory VPN registration with state authorities; non-compliant VPNs are blocked. Several providers have shut down Russian operations rather than comply.
- China — VPNs require government approval; unauthorized providers are blocked or compromised.
- Iran, North Korea, Belarus — Similar restrictive regimes.
Reputable VPNs do not market services to or operate in these jurisdictions. StatesVPN's editorial policy excludes recommendations for any provider operating in sanctioned or surveillance-mandated markets.
Jurisdiction vs. Audit: What Matters More?
If you have to choose between two factors, a recent published disclosure + RAM-only servers is generally stronger evidence of privacy than jurisdiction alone. A Swiss provider that has never been reported is less trustworthy than a US provider with multiple public provider materials and court-published privacy.
That said, the best VPNs combine both: privacy-friendly jurisdiction (BVI, Panama, Switzerland) plus published disclosures plus RAM-only architecture. ExpressVPN (BVI + public provider materials/public provider materials/public provider materials + TrustedServer), NordVPN (Panama + public provider materials/public provider materials + RAM-only), and ProtonVPN (Switzerland + public provider materials audits + open-source clients) all check every box.
Frequently Asked Questions
Continue comparing
Full reviews
Reviewed Sep 2026 · Public-source research · First-party tests appear on review pages when dated results are published · Verify details on provider sites. Editorial policy & scoring