VPN Jurisdiction and the 14 Eyes: Does It Really Matter?
A VPN's jurisdiction — the country whose laws it answers to — decides which governments can legally compel it to hand over data and gag it from talking about it. That is why the 5, 9 and 14 Eyes intelligence-sharing alliances come up in almost every VPN discussion. But here is the honest headline: jurisdiction matters far less than the industry implies, because a provider that genuinely keeps no logs has nothing to compel no matter where it is based. It is a real factor, just not the first one.
What the 5, 9 and 14 Eyes are
They are overlapping intelligence-sharing arrangements between governments. The Five Eyes — the United States, United Kingdom, Canada, Australia and New Zealand — is the core, dating back to post-war signals-intelligence cooperation. The Nine Eyes adds Denmark, France, the Netherlands and Norway. The Fourteen Eyes, formally known as SIGINT Seniors Europe, adds Germany, Belgium, Italy, Spain and Sweden. The concern for VPN users is that data collected or compelled in one member country can, in principle, be shared with the others.
What jurisdiction actually controls
Jurisdiction determines three concrete things: whether a government can legally order a provider to hand over data it holds, whether it can compel the provider to start logging a specific user going forward, and whether it can gag the provider from disclosing any of this. Those are genuine powers. A provider in a member country can be served with a valid legal order and must comply with whatever it can. The crucial phrase is “whatever it can” — which brings us straight to the reason jurisdiction is weaker than it sounds.
Why it matters less than you think
A legal order can only extract data that exists. A provider that genuinely keeps no activity logs and runs RAM-only servers has nothing to hand over, whether it sits in the United States or on a tropical island. This is not theory: Private Internet Access, a US company squarely inside Five Eyes territory, was subpoenaed twice and produced nothing, because there was nothing to produce. Meanwhile a VPN registered in a “privacy-friendly” country that quietly logs your traffic is far more dangerous than an audited no-logs provider in a Fourteen Eyes state. Verified behaviour beats a flag on a map. Our comparison of audited no-logs VPNs is built around exactly that principle.
Jurisdiction is a tie-breaker between two providers with equally strong, audited no-logs records — not a substitute for that record. A great policy in a “bad” country beats a vague policy in a “good” one, every time.
Jurisdiction can change — the Proton example
A country's reputation is not fixed, and Switzerland is the cautionary tale. Long treated as a privacy haven and home to Proton, it advanced a surveillance ordinance that would expand data-retention and identification duties for larger online services. Proton responded by publicly moving much of its infrastructure to Germany and Norway. The lesson is twofold: even a “good” jurisdiction can tighten, and what protects you in that moment is not the country label but a provider willing to keep almost nothing and to move when the law turns. A static list of “safe countries” ages badly.
“Best VPN outside 14 Eyes” — the honest answer
If you specifically want a provider outside the Fourteen Eyes, there are reasonable options — Mullvad in Sweden is technically inside the alliance yet keeps so little that it survived a police raid, while providers based in places like Panama or the British Virgin Islands sit outside it. But do not let the search for an “outside 14 Eyes” badge override the fundamentals. A provider outside the alliance with no independent audit is a worse bet than an audited one inside it. Use jurisdiction to break a tie among providers that have already passed the audit and no-logs tests, not as your opening filter.
How to weigh jurisdiction
Put jurisdiction third on your list, after an independent audit and RAM-only, no-logs infrastructure. For most people it barely moves the needle. For a narrow group with a serious adversary — where even the existence of a gagged order matters — jurisdiction and a maintained warrant canary become more relevant, because they shape what secret pressure a provider can face and disclose. For everyone else, choose the audited provider you trust and stop worrying about the map.
Data-sharing is not automatic — but assume the worst
It is worth being precise about what the Eyes alliances do and do not mean, because both the marketing and the panic overstate it. The alliances are frameworks for sharing signals intelligence between governments; they do not give every member automatic, on-demand access to every company's data in every other member. A legal request still has to be made through some lawful process, and much of what the alliances share is bulk intelligence collection rather than targeted business records. That said, for planning purposes it is sensible to assume that data obtained by one member could reach the others, because the whole point of the arrangement is cooperation. The practical takeaway does not change: since a well-audited no-logs provider holds nothing to share in the first place, the alliance question becomes moot for the data that matters most — your activity. Where jurisdiction genuinely bites is on the ability to compel a provider to begin logging a specific user going forward, and to gag it from saying so. That is a real risk for a narrow set of high-stakes users, and it is the scenario where country, transparency reporting and a warrant canary actually earn their place in the decision. For everyone else, the alliance map is interesting background rather than a reason to rule a well-audited provider in or out.
Jurisdiction and the Eyes alliances
What countries are in the 14 Eyes?
Should I avoid VPNs based in 14 Eyes countries?
Does a privacy-friendly jurisdiction guarantee my data is safe?
What is the best VPN outside the 14 Eyes?
The through-line to everything here: a VPN shifts trust to its provider. See which no-logs claims are actually audited, or read the honest threat model.