← All posts

VPN Jurisdiction and the 14 Eyes: What It Actually Means

Five Eyes, Nine Eyes, Fourteen Eyes — and what they actually change about VPN privacy. A grounded look at jurisdiction, compulsion, and the gap between marketing and reality.

By VeilTun Team


Why jurisdiction matters at all

A VPN provider operates under the laws of whichever country its company is registered in. Those laws determine:

  • Whether the government can compel the provider to hand over user data.
  • Whether the provider can be forced to silently start logging a specific user.
  • Whether court orders to do either can come with a gag order preventing the provider from telling anyone.
  • What intelligence-sharing arrangements the country has with foreign agencies.

For most people, this is academic. For people whose threat model includes state actors — journalists, activists, dissidents, researchers with sensitive sources — jurisdiction is one of the more consequential choices in their VPN selection.

This article walks through what the "Eyes" arrangements actually are, what jurisdiction changes in practice, and why the answer is more nuanced than the marketing copy makes it sound.

The Eyes arrangements

The "Eyes" terminology refers to a series of expanding intelligence-sharing alliances rooted in a 1946 agreement between the US and UK.

Five Eyes

The original and tightest. Members: United States, United Kingdom, Canada, Australia, New Zealand.

These five countries have extensively integrated intelligence apparatuses. The Snowden disclosures in 2013 documented the depth: shared signals-intelligence collection, joint surveillance programs (PRISM, Tempora, XKeyscore), and routine bilateral exchanges of intercepted data. Within Five Eyes, an intelligence agency in one country can often access data collected by another country's program — including data on its own citizens that domestic law would otherwise restrict.

Nine Eyes

Five Eyes plus: Denmark, France, Netherlands, Norway.

A looser arrangement. Members share intelligence but with more bilateral selectivity and less programmatic integration. Still significant: a request routed through Nine Eyes channels can reach data residents of those countries assume is local.

Fourteen Eyes

Nine Eyes plus: Germany, Belgium, Italy, Spain, Sweden.

The widest published tier. Also called SIGINT Seniors Europe (SSEUR). Cooperation here is more limited and topic-specific (terrorism, organized crime), but the relevant fact is: a VPN provider in any of these countries operates under government infrastructure that has established legal and operational pathways for sharing communications data with foreign partners.

Beyond Fourteen

Israel, Japan, Singapore, and South Korea are reported "third-party" partners with varying degrees of access. The line between formal alliance and informal cooperation gets fuzzy here.

What the Eyes designation actually means for a VPN

The common framing — "avoid VPNs in Fourteen Eyes countries" — is too coarse. The real question is layered:

1. Can the government compel logs that don't exist?

No. If the VPN truly keeps no logs, no warrant can produce logs. This is why no-logs architecture matters more than jurisdiction: it removes the data, so jurisdiction stops mattering. (VPN No-Logs Policy: What It Really Means covers this in detail.)

The harder question: can the government compel the VPN to start logging a specific user going forward?

In the US, the answer is yes, via National Security Letters (NSLs) or FISA orders. These usually come with gag orders preventing the provider from disclosing them. The Lavabit precedent (2013) showed that a US provider asked to silently compromise a user has very few options other than shutting down.

Most Five/Nine/Fourteen Eyes jurisdictions have analogous legal mechanisms.

2. Warrant canaries

Some VPN providers publish "warrant canaries" — periodic statements that they have not received a secret order. The theory is that the canary disappearing signals (without the provider technically violating a gag order) that something happened.

In practice, warrant canaries have legal ambiguity. The DOJ has never tested whether removing a canary constitutes a disclosure that violates a gag order. Several providers have quietly stopped maintaining them after legal advice. Treat their presence as a positive signal but not a guarantee.

3. Data retention laws

Some countries require data retention even of providers that would otherwise not log. The EU's prior Data Retention Directive (struck down in 2014) forced ISPs to retain metadata; some national equivalents still apply. France, Germany, and others have intermittently enforced retention regimes that could in principle apply to VPN providers.

This is one of the strongest specific reasons to consider jurisdiction: a no-logs architecture only matters if no-logs is legal in that jurisdiction.

4. Court order compulsion

Courts in any jurisdiction can issue orders compelling cooperation with investigations. The difference between jurisdictions is:

  • Procedural protections. How easy is it to get such an order? What standard of evidence is required?
  • Scope. Can the order compel ongoing surveillance, or only existing data?
  • Transparency. Can the provider disclose that an order was received?

"Privacy-friendly" jurisdictions — what they actually mean

Common VPN-industry choices outside the Eyes:

Switzerland

Strong constitutional privacy protections, no mandatory data retention for VPN providers, no membership in Eyes alliances. Switzerland does cooperate with international investigations under treaty, but each request goes through judicial review. ProtonVPN is the highest-profile example.

The caveat: Switzerland has been known to issue local court orders compelling cooperation in specific cases. A Swiss jurisdiction is not a magic shield — it's a procedural improvement over Five Eyes.

Panama

No mandatory data retention. Outside Eyes alliances. Latin American jurisdiction (mutually less convenient for North American/European investigators). NordVPN is registered here. The downside: less robust rule-of-law protections than European alternatives — if you ended up in an adversarial situation with a wealthy or well-connected opponent, Panama's legal system is less predictable.

British Virgin Islands

A common offshore registration. No data retention. Outside Eyes. UK Overseas Territory (legally complex; in some matters the UK can extend its reach). ExpressVPN is registered here.

Romania, Bulgaria

EU members but historically more privacy-protective in implementation than Western European peers. Inside the EU's mutual-assistance frameworks, but with local enforcement that some providers consider more friendly to no-logs operation.

Iceland, Estonia

Both have strong constitutional privacy protections and active privacy-rights legal cultures. Smaller jurisdictions, less common for major VPN providers, but appearing in some new entrants.

The honest framework

Stop thinking about jurisdiction as a binary "in Eyes / out of Eyes." Instead ask:

1. What's the worst-case adversary in your threat model?

  • If it's "my ISP showing me too many ads" — jurisdiction doesn't matter. Use anyone reputable.
  • If it's "a small-time investigator on a civil matter" — any jurisdiction outside the requesting country's reach is fine.
  • If it's "a Five Eyes intelligence agency with patience and resources" — no commercial VPN is reliably sufficient. Consider Tor or operational measures beyond a VPN.

2. Does the provider hold data your adversary would want?

If the provider truly logs nothing about you specifically, jurisdiction matters less for retrospective requests. It still matters for prospective compulsion to start logging.

3. What's the legal procedure to compel the provider?

A jurisdiction where compulsion requires public judicial review is materially different from one where it can happen via secret administrative order.

4. Is the provider transparent about requests received?

Transparency reports (like those published by ProtonVPN, Mullvad, and a handful of others) tell you how often the provider gets requests and how it responds. A provider that has handled zero requests is either lucky, very new, or quietly compliant — the report itself is the useful artifact.

Where VeilTun stands

VeilTun is registered in [redacted until incorporation finalized — Marat]. We will publish:

  • The legal jurisdiction the operating entity is in.
  • The compulsion regime that applies to us (what kinds of orders we can be served).
  • A transparency report covering requests received and how we responded.
  • Documentation of the no-logs architecture (what is and isn't stored, with code-level specifics).

We don't think jurisdiction alone is a privacy story. The story is: no data exists to compel; the infrastructure prevents collection at the architectural level, not just the policy level. Jurisdiction is part of the picture, not the whole of it.

The bottom line

The "avoid Fourteen Eyes" rule of thumb captures something real but oversimplifies it. The actual question is: given your threat model, which combination of jurisdiction, no-logs architecture, transparency, and operational practice gives you the protection you need?

For most users, any reputable VPN with verified no-logs and a jurisdiction outside their own country is sufficient. For people with serious threat models, no commercial VPN is enough by itself — they need to think about the whole stack, including operational security beyond what any VPN provider can offer.

Pick a provider that's transparent about its jurisdiction and what that jurisdiction means. Be wary of any provider whose answer to "what jurisdiction are you in" is vague or evolving.