VPN marketing frequently mentions being based “outside the Five Eyes” as a privacy selling point. The underlying concept is real and documented, but it is often presented without enough context to judge how much it should actually influence a choice of provider. Here is what the alliances are, what they actually do, and what that means for VPN jurisdiction.
What the alliances actually are
The Five Eyes is an intelligence-sharing alliance between the United States, United Kingdom, Canada, Australia and New Zealand, with roots going back to post-war signals intelligence cooperation. The Nine Eyes and Fourteen Eyes extend that same sharing arrangement to additional countries (commonly cited as including Denmark, France, Netherlands, Norway for Nine Eyes, and further countries including Germany, Belgium, Italy, Spain and Sweden for Fourteen Eyes, though the exact composition and formal status of the wider groupings is less precisely documented publicly than the original Five Eyes agreement). The Electronic Frontier Foundation has published extensively on how these countries function as intelligence partners, including that they “commonly share tools and techniques, and in some occasions also collectively develop new surveillance capabilities” (EFF, 2017).
Why this matters for VPN jurisdiction
A VPN provider is a company, and companies are subject to the laws of the country where they are legally based, including data retention laws, government data-request powers, and gag orders that can prevent a company from disclosing that it received a request at all. A provider based in a Five Eyes country is potentially subject to legal processes that compel data disclosure, backed by an intelligence-sharing relationship that means data obtained by one member’s request can, in principle, be shared with partner agencies in the other member countries � the EFF’s reporting on Five Eyes cooperation documents this kind of shared collection and tooling directly.
This is a legal and structural argument, not a claim that any specific provider is compromised. A “no-logs” VPN that genuinely does not retain connection or activity logs has, in principle, nothing to hand over even if legally compelled � jurisdiction matters most as a secondary risk factor for providers whose no-logs claims are unverified or unaudited, not as a standalone red flag on its own.
Why gag orders make jurisdiction harder to assess from the outside
One detail that complicates evaluating any provider’s jurisdiction claims is that legal processes in several Five Eyes countries can include a gag order provision, legally barring the recipient company from disclosing that a data request was ever made at all. This means a provider’s public silence on having received government requests is not itself reassuring � silence is the expected outcome whether no request was ever made, or a request was made and the company is legally forbidden from saying so. Some providers have responded to this specific problem with “warrant canary” statements (a regularly updated public statement confirming no secret request has been received, which would need to be quietly removed or left unrenewed if that stopped being true) or by publishing periodic transparency reports detailing the volume and type of legal requests received where disclosure is permitted. Neither mechanism is foolproof, but both are more informative than jurisdiction alone in judging how a provider would likely respond under legal pressure.
What jurisdiction does not solve on its own
- It does not replace a verified no-logs policy. A provider based outside all surveillance alliances that still logs identifiable user activity offers no real protection � the logs exist regardless of jurisdiction, and could still be exposed through a breach, a court order in whatever country it does operate in, or an internal leak.
- It does not account for corporate ownership. Some VPN companies are owned by parent entities based in different jurisdictions than the operating brand, which can shift the practical legal exposure regardless of where the service is marketed as “based.”
- It does not address server locations. A provider’s home jurisdiction and the jurisdictions where its physical servers operate are two different legal exposures � data can be subject to local laws wherever it is physically processed, not just at the company’s registered headquarters.
How this became a VPN marketing point in the first place
Public awareness of Five Eyes intelligence sharing rose sharply following Edward Snowden’s 2013 disclosures of classified NSA documents, which revealed the scale of bulk data collection and the extent of cooperation between agencies in these countries. That period is when “jurisdiction” first became a mainstream VPN marketing angle. Several well-known providers have since built part of their brand around being based outside the alliances, though in practice this is usually a deliberate incorporation choice rather than a company physically relocating away from a Five Eyes country: ExpressVPN has been headquartered in the British Virgin Islands, which has no mandatory data-retention law, since its founding in 2009; Proton VPN operates under Swiss law, which requires a Swiss court order before user data can be disclosed and sits outside the Five/Nine/Fourteen Eyes networks; and NordVPN’s consumer service is run through a Panama-incorporated entity, Panama having no mandatory data-retention law of its own, even though its day-to-day operations are based in Lithuania. On the data-retention point specifically, this is not a single uniform “Five Eyes” regime — the laws vary by country and only some alliance members have enacted them, such as the UK’s Investigatory Powers Act 2016, which lets the government issue data retention notices to telecoms and ISPs, and Australia’s Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015, which mandates around two years of metadata retention by telecoms providers. Those laws are aimed at telecoms and internet providers rather than VPN companies directly, which is part of why jurisdiction outside them is treated as a risk-reduction factor rather than a guarantee. The EFF’s continued reporting on Five Eyes cooperation since then reflects an ongoing pattern rather than a single historical event — the alliance’s data-sharing and joint tooling arrangements have continued to develop in the years since the original disclosures.
How to weigh it realistically
Jurisdiction outside the Five/Nine/Fourteen Eyes alliances is a reasonable factor to prefer, all else being equal, particularly for users with a specific threat model involving state-level surveillance. For most users, it is one input among several � independently audited no-logs claims, a transparent security track record, and RAM-only or otherwise minimal-retention server infrastructure � rather than a single decisive factor on its own.
Sources
- Five Eyes Unlimited: What a Global Anti-Encryption Regime Could Look Like. Electronic Frontier Foundation, 2017.
- BVI Jurisdiction: Why It Matters. ExpressVPN.
- Why is Proton based in Switzerland? Proton.
- Where is NordVPN based. NordVPN Support.
- Investigatory Powers Act 2016, Part 4. legislation.gov.uk.