VPN marketing often mentions GDPR compliance as a badge of trust, but it’s worth understanding what that legal framework actually requires of a VPN provider — and what it doesn’t. GDPR (the General Data Protection Regulation) and its UK equivalent, UK GDPR, are data protection laws, not privacy-marketing labels, and they apply to any organisation processing personal data of people in the EU or UK, VPN providers included.
Why your IP address is the starting point
GDPR’s protections only kick in where “personal data” is actually being processed, so the first question is whether anything a VPN provider handles counts as personal data at all. This was directly tested at the EU’s highest court: in the 2016 Breyer ruling (Case C-582/14), the Court of Justice of the European Union held that a dynamic IP address constitutes personal data for an organisation that holds it, provided that organisation has a legal means of obtaining additional information from a third party (such as an internet service provider) that could identify the individual behind it. VPN providers sit in an unusually direct relationship with IP addresses — they see the user’s real IP address on connection, and assign an exit IP address for outgoing traffic — so this ruling matters more for a VPN provider than for most ordinary websites.
Controller or processor: a real distinction, not a technicality
UK data protection guidance from the Information Commissioner’s Office (ICO) draws a firm line between a data controller, who decides the purposes and means of processing personal data, and a data processor, who processes it only on a controller’s instructions. A VPN provider handling its own subscribers’ account data — email addresses, billing details, connection metadata it chooses to retain — is generally acting as a controller for that data, since it’s deciding why and how that data is processed. The ICO’s guidance on processor obligations sets out that a processor “can only process the personal data on instructions from a controller” and must have a binding contract in place setting out defined provisions; a VPN provider is more typically the controller in its relationship with its own subscribers, meaning the fuller set of GDPR obligations (lawful basis for processing, data subject rights, breach notification to the regulator) generally falls on the provider directly, not on some upstream party.
What GDPR actually obliges a VPN provider to do
Stripped of marketing language, the core obligations are fairly specific. A controller must have a lawful basis for any personal data it processes — typically, for a VPN provider, this is the contract with the subscriber (for billing and account administration) or legitimate interests (for basic security and abuse prevention). The principle of data minimisation means a provider should only collect and retain what it genuinely needs for a defined purpose, which is the legal hook behind “no-logs” claims: a provider that doesn’t need to retain detailed connection logs for its stated purposes has a harder time justifying keeping them under GDPR’s minimisation principle, separate from whatever the provider also promises in its own privacy policy. If a provider suffers a data breach exposing personal data, ICO guidance on processor and controller obligations confirms there’s a duty to notify affected parties and, where required, the relevant supervisory authority, without undue delay.
Where GDPR compliance and “no-logs” marketing diverge
GDPR compliance and a genuine no-logs policy are related but not the same thing. A VPN provider can be fully GDPR compliant while still retaining connection logs, provided it has a lawful basis, discloses the retention clearly in its privacy policy, and doesn’t keep the data longer than necessary for that stated purpose. Conversely, a provider’s marketing claim of being “no-logs” is a commercial and technical promise, not a GDPR certification — GDPR doesn’t require zero logging, it requires that whatever is logged is lawful, minimised, and disclosed. This is why an independent, technical audit of a provider’s actual server configuration and logging practices tells you something different from, and arguably more useful than, a statement that the provider is “GDPR compliant.”
Why jurisdiction still matters alongside GDPR
GDPR applies based on whose data is being processed (EU or UK residents), not based on where the VPN company itself is headquartered, so a provider based outside the EU or UK can still be bound by GDPR if it processes personal data of people there. That said, a provider genuinely headquartered outside EU/UK jurisdiction, particularly outside intelligence-sharing arrangements, may still be a meaningfully different proposition from a compliance and government-request standpoint than one operating from within it — GDPR governs how personal data must be handled, but it doesn’t override a country’s own separate legal powers to compel disclosure of data a company holds within its jurisdiction.
The bottom line
GDPR gives VPN users a real, enforceable set of rights and obligations, not just a badge providers can claim — a VPN provider handling EU or UK users’ data is generally a data controller with direct obligations around lawful basis, data minimisation and breach notification, and the Breyer ruling means the IP addresses at the core of a VPN’s own function count as personal data in the first place. But GDPR compliance is a legal minimum, not proof of a genuine no-logs practice; for that, look for an independent audit of the provider’s actual infrastructure alongside whatever compliance claims it makes.
Sources
- Court of Justice of the European Union, Patrick Breyer v Bundesrepublik Deutschland, Case C-582/14 (2016), on dynamic IP addresses as personal data — iapp.org
- Information Commissioner’s Office (ICO), “What does it mean if you are a processor?” — ico.org.uk