PrivacyPick
In This Article
VPN BasicsJurisdictionSurveillance

What the 14 Eyes Actually Means for VPN Jurisdiction (2026)

'Based outside the 14 Eyes' is a marketing line, not a guarantee. What VPN jurisdiction actually decides, the cases that break the logic, and the 2026 laws in play.

Published August 27, 2026By Juan Martinez

What the 14 Eyes Actually Means for VPN Jurisdiction (2026)

If you have read more than one VPN review, you have seen the phrase: “based outside the 14 Eyes.” It is presented as a clean pass/fail — inside the alliance, your data is exposed; outside it, you are safe. That framing is wrong in both directions. VPN jurisdiction does matter, but not as a fourteen-country blocklist, and not nearly as much as what the provider actually logs and how it has behaved when a real legal order arrived. Here is what the term actually refers to, and what it does and doesn’t decide.

What “Five Eyes” Actually Is

The Five Eyes is a real agreement with a real name and a declassified paper trail. It began as the BRUSA Agreement, signed between the United States and the United Kingdom in March 1946, and developed into the UKUSA Agreement of 1956, which later extended to Canada, Australia and New Zealand. Neither government officially acknowledged its existence until April 2010, when the NSA declassified the 1940-1956 documents and GCHQ released its parallel set to the UK National Archives two months later. It is a standing arrangement for sharing signals intelligence — intercepted communications and the metadata around them — among five national agencies.

That much is documented. The important limitation: the agreement covers intelligence agencies sharing intercepted signals with each other. It is not a mechanism for one member government to reach into another member’s courts, and it does not create a legal obligation on a private company in one member country to hand data to another member country’s police.

Where “9 Eyes” and “14 Eyes” Come From

Here is the part the aggregator pages skip. There is no treaty called the “Nine Eyes.” There is no treaty called the “Fourteen Eyes.” These are labels the privacy community attached to a wider set of intelligence-sharing relationships, most of which run through a grouping the NSA’s own documents call SIGINT Seniors Europe.

SIGINT Seniors Europe was founded in 1982, during the Cold War, to pool intelligence on the Soviet military. Its existence became public through NSA documents provided by Edward Snowden and reported in 2018. As of the documents’ 2013 snapshot, its members were the five Five Eyes agencies plus Belgium, Denmark, France, Germany, Italy, the Netherlands, Norway, Spain and Sweden — fourteen agencies in total, which is where “14 Eyes” comes from. The “9 Eyes” is just a smaller slice of the same list: the Five Eyes plus Denmark, France, the Netherlands and Norway.

The distinction that matters: the reporting on these documents describes an arrangement among SIGINT agencies, not a ratified treaty with binding terms. Sharing within these groupings is discretionary. A country being on the 14-agency list tells you its signals-intelligence service sits at the same table as the NSA’s a few times a year. It does not tell you that a VPN company incorporated in that country will, or legally must, log your traffic and forward it.

Jurisdiction Sets the Ceiling, Not the Outcome

What jurisdiction actually determines is narrower and more useful to state plainly: which government’s courts and surveillance laws can compel the company, and whether that country has a law forcing data retention regardless of the company’s own policy.

On the first point, several providers reviewed on this site sit in places with no mandatory data-retention law for VPNs: ExpressVPN in the British Virgin Islands, NordVPN in Panama, Proton VPN in Switzerland (outside both the EU and every Eyes grouping), hide.me in Malaysia. Others sit squarely inside: Private Internet Access and IPVanish are both incorporated in the United States, a founding Five Eyes member; Windscribe is in Canada; Mullvad is in Sweden, on the 14-agency list. IVPN is the genuinely disputed case — it is registered in Gibraltar and argues that UK surveillance law does not extend there, a position independent analysts are split on rather than settled either way.

But jurisdiction only sets a ceiling on what a government could demand. Whether anything is actually handed over depends on whether the company kept records worth seizing. That is where the real-world cases stop matching the map.

Three Cases That Break the Simple Version

PureVPN, Hong Kong — outside every Eyes grouping, produced logs anyway. In 2017, an FBI affidavit in a Massachusetts cyberstalking case stated that PureVPN “was able to determine that their service was accessed by the same customer from two originating IP addresses” — the suspect’s home connection and his workplace — along with connection timestamps. PureVPN was operating from Hong Kong at the time and marketed a no-logs policy, while its actual privacy policy disclosed that it retained connection times and bandwidth. A jurisdiction outside the Five, Nine and Fourteen Eyes lists produced usable connection records for a US investigation, because the company was keeping them.

HideMyAss, United Kingdom — Five Eyes, complied with a court order. In 2011, a LulzSec member named Cody Kretsinger was identified partly through logs that HideMyAss, a UK-based provider, produced under a UK court order. Kretsinger pleaded guilty in April 2012 to conspiracy and unauthorized impairment of a protected computer over the SQL-injection attack on Sony Pictures, and was sentenced in April 2013 to a year and a day in federal prison. HideMyAss’s public response at the time was that it complies with court orders and does retain logs that such an order can reach. This is the case the “avoid Five Eyes” advice is built on — and it is a real data point, but the operative fact is that the company retained connection logs, not the flag it operated under.

Private Internet Access, United States — founding Five Eyes, had nothing to give. PIA is incorporated in the US, the worst jurisdiction on this page by the aggregator logic. In 2016, a subpoena tied to an FBI investigation reached PIA’s then-parent company and produced nothing beyond a shared IP address cluster. In 2018, PIA’s own general counsel testified under oath in a federal hacking trial that the company had no customer activity logs to hand over. Separately, when Russian authorities seized PIA hardware in 2016 under a new data-retention law, PIA reported that nothing was compromised because nothing was logged, and pulled out of the Russian market rather than start logging to comply. Three hostile parties, three attempts, nothing found — in the jurisdiction the simple version says to avoid.

The pattern across all three: the jurisdiction predicted the wrong outcome each time. What predicted the right one was whether the provider actually kept logs, which is a question about the company, not the country.

The Map Is Being Redrawn Right Now

There is a further reason not to treat “based outside the 14 Eyes” as a durable fact: the underlying laws are in active flux in 2026, including in places currently sold as safe.

The European Union. Under its “ProtectEU” internal-security strategy, the European Commission launched a process in May 2025 to prepare EU-wide data-retention rules. Reporting in December 2025 indicated member states are pushing for one year of retained communications metadata, a six-month minimum, and that VPN providers are already considered reachable under existing EU evidence rules. The Commission’s impact assessment was expected to conclude in the first quarter of 2026 with a legislative proposal at the end of the first half of the year. As of this article, no proposal has been formally tabled — it is in preparation, not law — but it would apply to providers in EU jurisdictions that are marketed today as having no retention obligation.

Canada. Bill C-22, the Lawful Access Act, was introduced in March 2026. As described by University of Ottawa law professor Michael Geist, it would require electronic service providers to retain metadata for one year and to build technical capabilities for authorized access, under a definition of “electronic service provider” broad enough to cover VPNs. Committee hearings began in May 2026; the bill is not law. Signal, Windscribe, NordVPN, Apple and Meta have all publicly stated they would leave the Canadian market rather than comply. Windscribe — reviewed on this site, and currently Canadian — has said the same.

Neither of these is settled. The point is that a jurisdiction’s status is a snapshot, and a provider that is “outside mandatory retention” this year may not be next year, which is a weak foundation for a decision you are making now.

Warrant Canaries: Weaker Than They Look

One more jurisdiction-adjacent signal worth understanding: the warrant canary. It is a statement a provider publishes and regularly re-publishes, saying it has not received a secret legal demand it would be gagged from disclosing. The theory, as the Electronic Frontier Foundation described it in 2014, rests on the First Amendment: a government may be able to gag a company, but may not be able to compel it to actively lie by stating it has received nothing when it has.

The EFF’s own FAQ is blunt that this theory has never been upheld in court — its advice to a provider served with gagged process is to get a lawyer and litigate, not to rely on a canary. And the removal of a canary does not explain itself: in 2016, Silent Circle took its canary down and said the reason was a business decision, not a received demand. A missing canary could mean a secret order arrived. It could also mean the provider changed its policy, forgot to update the page, or decided the mechanism was more liability than value. It is a soft signal, not proof of anything, and it should be read that way.

What to Actually Do With Jurisdiction

Jurisdiction is worth knowing, in this order of importance:

Check for a mandatory data-retention law first. A provider in a country that legally forces logging is a real problem regardless of its privacy policy, because the policy loses. This is the part of “jurisdiction” that has teeth. Panama, the British Virgin Islands, Switzerland and Malaysia currently have no such law for VPNs; the EU and Canada situations above are why “currently” is load-bearing.

Then look at what the provider actually logs, and whether that has been independently checked. A no-logs claim that has survived a real subpoena or a courtroom — as PIA’s has, more than once — is worth more than a clean jurisdiction with an unaudited policy. An independent no-logs audit is the next-best evidence when there is no court case to point to.

Treat the Eyes groupings as the loosest possible tiebreaker. If two providers are otherwise equal — same retention picture, same audit history, same logging policy — then yes, the one in Panama is marginally preferable to the one in the Netherlands. That is the actual weight the “14 Eyes” question deserves: a tiebreaker between equals, not a filter you apply first.

The provider in a Five Eyes country that keeps no logs and has proven it in court is a safer choice than the provider outside every alliance that quietly retains your connection records. The cases above are what that looks like in practice.