← Back to Blog

    Can a Country Force Your VPN to Hand Over Data?

    A country-by-country assessment of the CLOUD Act, UK investigatory powers, EU e-evidence, Swedish and Swiss surveillance rules, Canadian preservation orders, Australia's assistance regime and India's VPN record mandate - joined to the companies that actually operate major VPN brands.

    Privacy TechnologyPublished · Updated · 22 min read· By TheVPNMatrix.com

    Evidence-based review per our 28-criteria methodology · affiliate disclosure

    VPN provider groups connected across national legal jurisdictions and evidence routes
    Ownership is only the first node. Legal reach depends on the operator, controller, records, order and cross-border route that connect to it.

    Direct answer

    Yes, a country can compel a VPN provider to preserve, produce or in some systems begin collecting specified data when the provider and order fall within that law.But a flag does not answer the case. The decisive questions are which legal entity runs the service, whether it is covered, which records exist, who controls them, what process was used and whether a cross-border route is valid.

    The US CLOUD Act is not a global VPN logging mandate. Five Eyes is not a magic warrant passport. GDPR is not a shield against every criminal order. Switzerland is not immune from surveillance law. A RAM-only server is not the same thing as a company with no account, payment, support or real-time operational data. Each shortcut removes the fact that actually decides the result.

    Country enforcement matrix for major VPN brands

    Country or regimeMajor provider connectionWhat authorities can seekWhat not to infer
    United StatesIPVanish/Ziff Davis, Point Wild brands, and US-linked group entitiesStored records under 18 U.S.C. 2703; preservation of specified existing records under 2703(f); records in a covered provider's possession, custody or control regardless of storage location under 2713.No universal duty for every consumer VPN to create browsing logs; a US parent does not automatically control every foreign subsidiary record.
    United KingdomKape's UK-headquartered group; HMA's historic UK nexusSeparate regimes for communications data, targeted retention, interception, equipment interference and technical capability. The 2024 Act strengthened overseas enforcement of retention notices and clarified complex-group capability notices.Not every UK-linked VPN has received a notice, and section 87 is notice-based rather than an automatic 12-month log for every provider.
    EU: Netherlands, Lithuania, Romania, CyprusNord Security/Cyberspace B.V., NordVPN/Surfshark operations, CyberGhost, AdGuard VPNCurrent national production and preservation process within EU rights limits; from 18 August 2026, European Production and Preservation Orders through a designated establishment or representative.GDPR does not ban lawful disclosure. EU law also does not permit a simple blanket claim that all providers retain all traffic.
    SwedenMullvad/Amagicom; Mullvad infrastructure used by Mozilla VPNCovered operators can face subscriber and internet-access retention duties, disclosure, and temporary preservation. PTS says temporary preservation applies only to data already stored.Mullvad's Swedish address alone does not prove that it is covered for every duty or that it stores browsing history. Mozilla's account layer must be assessed separately.
    SwitzerlandProton VPN and other Swiss providersThe SPTA creates cooperation duties for telecommunications providers and may reach some derived communications services; Swiss authorities use real-time and retrospective surveillance measures."Swiss privacy" is not immunity. The provider's classification, reduced-obligation status, stored data and target order still decide the result.
    CanadaTunnelBear's Canadian operating history under a US parentPreservation demands and orders can freeze computer data already in possession or control; separate production orders cover subscriber, transmission or other records.Preservation is not a general command to create future logs, and US parentage alone does not prove US control of Canadian records.
    AustraliaAustralian services and providers serving the marketTechnical assistance requests, notices and capability notices under the Assistance and Access framework, subject to the Act's tests and systemic-weakness limitation.The statute is not accurately described as an automatic universal encryption backdoor, and applicability to a foreign consumer VPN needs a nexus analysis.
    IndiaMajor providers including ExpressVPN, NordVPN and Surfshark changed their physical-server approach after the 2022 directionCERT-In requires VPN service providers within scope to keep validated customer and service-allocation information for five years, while organisations covered by the logging direction must keep ICT-system logs for 180 days in India.A virtual Indian location operated from another country is not the same as a physical Indian server, and provider exit does not settle every remote-service jurisdiction question.
    BVI and PanamaExpressVPN and NordVPN marketing or contracting layersDomestic orders, server-country action, mutual assistance and other cooperation routes may still matter.An offshore address is not proof of zero legal cooperation, zero parent control or zero retained records. We do not assign a safe-harbour grade without current primary-law and entity evidence.

    United States: stored records and the CLOUD Act

    For ordinary criminal process, the Stored Communications Act is usually a more concrete starting point than FISA 702. Section 2703 sets different process for content and non-content records. Section 2703(f) can require a provider to preserve specified records already in its possession for 90 days, renewable once. Section 2713, added by the CLOUD Act, says covered providers must preserve, back up or disclose records in their possession, custody or control even when the record is outside the United States.

    The hard word is control. If a US parent can access a foreign product's account or operations database, that relationship may matter. If the companies have genuine legal, technical and access separation, ownership alone does not prove control. The provider's architecture and corporate evidence are therefore part of the legal analysis, not a side issue.

    The US-UK CLOUD Act agreement, in force since October 2022, provides a direct route for qualifying orders between designated authorities and covered providers in the other country for serious-crime investigations. It has targeting, certification and review conditions. It is neither a bulk feed nor proof that every US or UK group company is the same legal recipient.

    United Kingdom: notices, interception and overseas reach

    The Investigatory Powers Act contains different powers with different safeguards. A section 87 retention notice can require specified relevant communications data for no more than 12 months. That is not the same as saying every UK provider automatically keeps 12 months of browsing history. Interception, equipment interference, communications-data acquisition and technical-capability notices must be assessed under their own provisions.

    The 2024 amendments matter to multinational VPN groups. They made retention-notice enforcement expressly extraterritorial and clarified that a technical-capability notice can be issued to one group entity in relation to another entity's capability. That still does not prove a notice has been served or that a parent can technically produce records. It changes the questions Kape, HMA and any UK-linked operator should answer publicly.

    European Union: national law now, e-evidence from August 2026

    The CJEU has rejected general and indiscriminate retention of traffic and location data for ordinary crime while allowing narrower categories under safeguards, including targeted or expedited preservation and limited IP-address or civil-identity retention. A provider conclusion therefore requires the national law, the service classification and the data category. "EU-based" is not a legal result.

    Regulation (EU) 2023/1543 applies from 18 August 2026. It will allow judicially issued or validated European Production and Preservation Orders to be addressed to designated establishments or legal representatives of covered service providers offering services in the Union. Preservation concerns data stored by or on behalf of the provider when the order arrives; it is not a general command to invent historical data. Notification, refusal, privilege and conflict rules remain relevant.

    Sweden, Switzerland and Canada

    Sweden: operator classification before slogan

    PTS says operators with notifiable activities have law-enforcement retention duties and lists ten months for internet-access data. It also explains that temporary preservation can freeze data for up to 90 days, renewable once, but cannot require future data creation. That official position must be joined to whether a particular VPN is a covered operator and what its system generates. Mullvad's 2023 report that police left without customer data is strong real-world evidence for that event, not a perpetual exemption from Swedish law.

    Switzerland: privacy law and surveillance law coexist

    Swiss OFCOM guidance says the Surveillance of Postal and Telecommunications Traffic Act creates cooperation obligations for telecommunications providers and can also reach some services derived from telecommunications. Providers may have reduced obligations depending on classification. Official 2025 statistics record both real-time and retrospective surveillance measures. Proton's Swiss base is relevant; it is not the conclusion. Its VPN data design, legal entity, audit scope and request history complete the assessment.

    Canada: preserve what exists, then use the right production order

    Canada's Criminal Code distinguishes preservation from production. A preservation demand freezes specified computer data already in possession or control; it does not require a company to begin generating future traffic history. Subscriber, transmission and other records have separate production routes. TunnelBear therefore needs both a Canadian operator analysis and a US-parent control analysis.

    Australia, India and offshore marketing jurisdictions

    Australia's Assistance and Access Act created voluntary technical assistance requests, compulsory technical assistance notices and technical capability notices. The statute includes necessity, proportionality and systemic-weakness constraints. Those are serious powers, but "Australia can force every VPN to install a backdoor" is not a sufficiently precise legal conclusion.

    India is the clearest provider-record rule in this comparison. CERT-In's 2022 direction requires covered VPN providers to retain validated subscriber identity, service period, allocated IP, onboarding IP and timestamp, purpose, address, contact and ownership-pattern information for five years or longer where law requires. It separately directs covered organisations to keep ICT-system logs for 180 days in India. Several major providers removed physical Indian servers rather than accept that model. That operational response is evidence of burden, not proof that every remote offering falls outside Indian reach.

    British Virgin Islands and Panama addresses are often sold as privacy features. We treat them as one input. A marketed jurisdiction does not answer who operates the service, where processors and servers sit, whether a parent controls records, or which mutual-assistance and treaty routes are available. Offshore should mean "investigate further," not "immune."

    What no-logs and RAM-only servers can actually prevent

    A no-logs architecture can make a valid order return less. It cannot make the order invalid. RAM-only servers can reduce persistent data on an individual server and make redeployment more consistent. They do not automatically remove central authentication events, account identifiers, payment records, support tickets, abuse controls, crash analytics or data visible during a live session.

    There are four separate proof questions. Does the provider normally retain the record? Can an existing record be preserved? Can the provider be ordered to collect a defined record prospectively? Can an authority or server host observe the connection outside the provider's claimed log store? A trustworthy audit names the systems, data categories, sampling window and limitations needed to test those questions.

    Provider assessment: evidence, not flags

    Provider or groupLegal-reach assessmentEvidence burden
    Kape / ExpressVPN / PIA / CyberGhostUK parent, US-linked and EU/BVI product layers create several possible routes; no one flag resolves the group.Entity-by-entity contracts, controller map, group access boundaries, post-acquisition audits and request statistics.
    Nord Security / NordVPN / SurfsharkDutch, Lithuanian and product-facing layers make current national process and the incoming EU e-evidence route relevant.Regional contracting entities, designated representative, separation controls and product-specific audit scope.
    Proton VPNSwiss law applies to the Swiss operator; absence of a US or EU parent removes one corporate route but not Swiss process or cooperation.Service-specific audit, classification, retained-data inventory and legal-request outcomes.
    Mullvad / Mozilla VPNSwedish operator law matters; Mozilla's separate customer and account relationship creates an additional data path.Keep Mullvad and Mozilla controllers, account records and legal responses separate.
    IPVanish / Ziff DavisUS ownership and operation make US production and preservation powers directly relevant to records held or controlled.Current server-side audit, precise retention schedule and current transparency reporting.
    TunnelBear / McAfeeCanadian operator history and US parentage require both domestic-process and parent-control tests.Current entities, database control, processor map and jurisdiction-split request statistics.

    These are exposure assessments, not accusations that a secret order exists. The strongest opposing case is important: a large provider may have better legal teams, reproducible infrastructure and more frequent audits than a small offshore operator. The answer is not to reward independence automatically. It is to demand more proof wherever ownership, record control or legal reach becomes more complex.

    What readers should do

    1. Find the operator and controller in the current terms and privacy policy.
    2. Use our ownership map to trace the parent, sister brands and review-site conflicts.
    3. Open the legal tracker, but treat its country colour as a research indicator rather than a provider verdict.
    4. List the records the VPN, payment processor, app store, support system and analytics stack actually create.
    5. Read the latest audit scope and transparency report. Do not accept an app test as proof of server-side non-retention.
    6. Match the remaining exposure to your threat model. A traveller on hotel Wi-Fi and a journalist facing a state investigation need different evidence.

    Want a provider that publishes more of the evidence?

    Our current evidence-led shortlist includes Proton VPN, NordVPN and Surfshark for different budgets and use cases. Compare their operator, audit and jurisdiction evidence before buying; none is immune from lawful process and none replaces Tor or specialist advice for a high-risk target.

    Affiliate disclosure: Those three links may earn The VPN Matrix a commission at no extra cost to you. Commission does not change the Matrix score, legal assessment or inclusion. Mullvad and IVPN are also discussed in our evidence set, and we currently earn no commission from their direct links. Read our full disclosure and editorial policy.

    Compare provider evidence and current scores

    Frequently asked questions

    Can the CLOUD Act force every VPN to hand over data?

    No. The relevant US rule reaches a covered provider subject to US process for records in its possession, custody or control, even when those records are stored abroad. It does not put every foreign VPN under US law merely because it has US customers or rents a US server, and it does not require a provider to create a permanent browsing log that does not exist.

    Does Five Eyes membership mean one country's warrant works in every member country?

    No. Intelligence sharing is not a substitute for legal authority over the provider. Cross-border requests still need a lawful route, such as domestic process against an entity with control, mutual legal assistance, a qualifying direct-access agreement or another implemented evidence mechanism.

    Can a no-logs VPN ignore a valid court order?

    No. A provider must respond according to the law that applies. A defensible no-logs design changes the response because it reduces the records available to produce. It does not cancel legal process, protect payment or support records automatically, or prove that prospective collection cannot be ordered.

    Is Switzerland automatically safer than the United States or United Kingdom?

    No. Switzerland has its own surveillance statute and cooperation duties, and official guidance says telecommunications and some derived communications services may have to cooperate. The useful question is whether the particular VPN is covered, what data it creates, and what the order can lawfully require.

    Does the EU ban communications-data retention?

    No. EU case law rejects general and indiscriminate traffic or location retention for ordinary crime, but permits defined forms of targeted, expedited, IP-address or civil-identity retention under safeguards. National law and service classification still matter. The EU e-Evidence Regulation will add cross-border production and preservation orders from 18 August 2026.

    What is the best evidence that a VPN cannot identify a user?

    A current server-side audit, a precise retention schedule, transparent account and payment data flows, public legal-request reporting, and real cases in which authorities obtained no useful customer record are stronger than a country badge or a broad no-logs slogan.

    Sources

    Sources are ordered by authority: statutes and official government or regulator guidance first, then the provider's own incident account. Provider statements are evidence of what the provider reported, not independent proof of every system state.

    References

    1. [1]Australian Parliament (2018) 'Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018', Federal Register of Legislation. Available at: https://www.legislation.gov.au/C2018A00148/latest/text (Accessed: 26 July 2026).
    2. [2]Council of Europe (2022) 'Second Additional Protocol to the Convention on Cybercrime', Cybercrime Convention Committee. Available at: https://www.coe.int/en/web/cybercrime/second-additional-protocol (Accessed: 26 July 2026).
    3. [3]Court of Justice of the European Union (2024) 'Case C-470/21, La Quadrature du Net and others', EUR-Lex. Available at: https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:62021CJ0470 (Accessed: 26 July 2026).
    4. [4]European Parliament and Council (2023) 'Regulation (EU) 2023/1543 on European Production and Preservation Orders', EUR-Lex. Available at: https://eur-lex.europa.eu/eli/reg/2023/1543/oj/eng (Accessed: 26 July 2026).
    5. [5]Government of Canada (2026) 'Criminal Code, preservation demands and production orders', Justice Laws Website. Available at: https://laws-lois.justice.gc.ca/eng/acts/c-46/ (Accessed: 26 July 2026).
    6. [6]Indian Computer Emergency Response Team (2022) 'Directions under section 70B of the Information Technology Act', CERT-In. Available at: https://cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (Accessed: 26 July 2026).
    7. [7]Mullvad VPN (2023) 'Mullvad VPN was subject to a search warrant: customer data not compromised', Mullvad Blog. Available at: https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised/ (Accessed: 26 July 2026).
    8. [8]Swedish Post and Telecom Authority (2026) 'Data retention for law-enforcement purposes', PTS. Available at: https://pts.se/internet-och-telefoni/sakerhet-och-skydd-av-uppgifter/datalagring/ (Accessed: 26 July 2026).
    9. [9]Swiss Federal Department of Justice and Police (2026) 'Telecommunications surveillance statistics for 2025', FDJP. Available at: https://www.ejpd.admin.ch/de/newnsb/In7wcvFLifhBDFtjfsjMq (Accessed: 26 July 2026).
    10. [10]Swiss Federal Office of Communications (2024) 'Registration and publication as a telecommunications service provider', OFCOM. Available at: https://www.bakom.admin.ch/en/registration-and-publication-as-a-tsp (Accessed: 26 July 2026).
    11. [11]UK Parliament (2016) 'Investigatory Powers Act 2016', legislation.gov.uk. Available at: https://www.legislation.gov.uk/ukpga/2016/25/contents (Accessed: 26 July 2026).
    12. [12]UK Parliament (2024) 'Investigatory Powers (Amendment) Act 2024: Explanatory Notes, Part 4', legislation.gov.uk. Available at: https://www.legislation.gov.uk/ukpga/2024/9/notes/division/7/index.htm (Accessed: 26 July 2026).
    13. [13]United States Department of Justice (2022) 'CLOUD Act Agreement between the United States and the United Kingdom', Office of International Affairs. Available at: https://www.justice.gov/criminal/criminal-oia/cloud-act-agreement-between-governments-us-united-kingdom-great-britain-and-northern (Accessed: 26 July 2026).
    14. [14]United States House of Representatives (2024) '18 U.S.C. 2713: Required preservation and disclosure of communications and records', United States Code. Available at: https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section2713 (Accessed: 26 July 2026).
    15. [15]United States House of Representatives (2024) '18 U.S.C. 2703: Required disclosure of customer communications or records', United States Code. Available at: https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section2703 (Accessed: 26 July 2026).

    NordVPN

    Top-rated VPN with excellent features

    Get Deal

    Cookie Preferences

    We use essential storage and anonymous aggregate site metrics. Optional event analytics only run if you opt in.

    Learn more
    Questions or concerns?

    Contact us via X, Substack, or see our Cookie Policy for full details.