
Direct answer
Yes, a country can compel a VPN provider to preserve, produce or in some systems begin collecting specified data when the provider and order fall within that law.But a flag does not answer the case. The decisive questions are which legal entity runs the service, whether it is covered, which records exist, who controls them, what process was used and whether a cross-border route is valid.
The US CLOUD Act is not a global VPN logging mandate. Five Eyes is not a magic warrant passport. GDPR is not a shield against every criminal order. Switzerland is not immune from surveillance law. A RAM-only server is not the same thing as a company with no account, payment, support or real-time operational data. Each shortcut removes the fact that actually decides the result.
The six questions that decide legal reach
- Entity: Who contracts with the user, operates the VPN and controls the relevant system?
- Coverage: Is that entity a telecommunications, electronic-communications, remote-computing or other covered service provider?
- Data: Does the requested account, payment, support, connection, destination or live-interception record exist?
- Process: Is this a production order, preservation demand, retention notice, interception warrant, assistance notice or intelligence authority?
- Reach: Can the issuing state reach the operator directly, a parent that controls the record, a local representative or a processor?
- Safeguards: What offence threshold, judicial authorisation, notice, challenge, minimisation, secrecy and remedy rules apply?
This is the legal version of the ownership method in our VPN ownership map. A parent company can matter without automatically possessing every subsidiary record. A server location can create a seizure or processor route without moving the whole service into that country's law. A marketed headquarters can be less important than the entity named in the current terms and privacy policy.
Country enforcement matrix for major VPN brands
| Country or regime | Major provider connection | What authorities can seek | What not to infer |
|---|---|---|---|
| United States | IPVanish/Ziff Davis, Point Wild brands, and US-linked group entities | Stored records under 18 U.S.C. 2703; preservation of specified existing records under 2703(f); records in a covered provider's possession, custody or control regardless of storage location under 2713. | No universal duty for every consumer VPN to create browsing logs; a US parent does not automatically control every foreign subsidiary record. |
| United Kingdom | Kape's UK-headquartered group; HMA's historic UK nexus | Separate regimes for communications data, targeted retention, interception, equipment interference and technical capability. The 2024 Act strengthened overseas enforcement of retention notices and clarified complex-group capability notices. | Not every UK-linked VPN has received a notice, and section 87 is notice-based rather than an automatic 12-month log for every provider. |
| EU: Netherlands, Lithuania, Romania, Cyprus | Nord Security/Cyberspace B.V., NordVPN/Surfshark operations, CyberGhost, AdGuard VPN | Current national production and preservation process within EU rights limits; from 18 August 2026, European Production and Preservation Orders through a designated establishment or representative. | GDPR does not ban lawful disclosure. EU law also does not permit a simple blanket claim that all providers retain all traffic. |
| Sweden | Mullvad/Amagicom; Mullvad infrastructure used by Mozilla VPN | Covered operators can face subscriber and internet-access retention duties, disclosure, and temporary preservation. PTS says temporary preservation applies only to data already stored. | Mullvad's Swedish address alone does not prove that it is covered for every duty or that it stores browsing history. Mozilla's account layer must be assessed separately. |
| Switzerland | Proton VPN and other Swiss providers | The SPTA creates cooperation duties for telecommunications providers and may reach some derived communications services; Swiss authorities use real-time and retrospective surveillance measures. | "Swiss privacy" is not immunity. The provider's classification, reduced-obligation status, stored data and target order still decide the result. |
| Canada | TunnelBear's Canadian operating history under a US parent | Preservation demands and orders can freeze computer data already in possession or control; separate production orders cover subscriber, transmission or other records. | Preservation is not a general command to create future logs, and US parentage alone does not prove US control of Canadian records. |
| Australia | Australian services and providers serving the market | Technical assistance requests, notices and capability notices under the Assistance and Access framework, subject to the Act's tests and systemic-weakness limitation. | The statute is not accurately described as an automatic universal encryption backdoor, and applicability to a foreign consumer VPN needs a nexus analysis. |
| India | Major providers including ExpressVPN, NordVPN and Surfshark changed their physical-server approach after the 2022 direction | CERT-In requires VPN service providers within scope to keep validated customer and service-allocation information for five years, while organisations covered by the logging direction must keep ICT-system logs for 180 days in India. | A virtual Indian location operated from another country is not the same as a physical Indian server, and provider exit does not settle every remote-service jurisdiction question. |
| BVI and Panama | ExpressVPN and NordVPN marketing or contracting layers | Domestic orders, server-country action, mutual assistance and other cooperation routes may still matter. | An offshore address is not proof of zero legal cooperation, zero parent control or zero retained records. We do not assign a safe-harbour grade without current primary-law and entity evidence. |
United States: stored records and the CLOUD Act
For ordinary criminal process, the Stored Communications Act is usually a more concrete starting point than FISA 702. Section 2703 sets different process for content and non-content records. Section 2703(f) can require a provider to preserve specified records already in its possession for 90 days, renewable once. Section 2713, added by the CLOUD Act, says covered providers must preserve, back up or disclose records in their possession, custody or control even when the record is outside the United States.
The hard word is control. If a US parent can access a foreign product's account or operations database, that relationship may matter. If the companies have genuine legal, technical and access separation, ownership alone does not prove control. The provider's architecture and corporate evidence are therefore part of the legal analysis, not a side issue.
The US-UK CLOUD Act agreement, in force since October 2022, provides a direct route for qualifying orders between designated authorities and covered providers in the other country for serious-crime investigations. It has targeting, certification and review conditions. It is neither a bulk feed nor proof that every US or UK group company is the same legal recipient.
United Kingdom: notices, interception and overseas reach
The Investigatory Powers Act contains different powers with different safeguards. A section 87 retention notice can require specified relevant communications data for no more than 12 months. That is not the same as saying every UK provider automatically keeps 12 months of browsing history. Interception, equipment interference, communications-data acquisition and technical-capability notices must be assessed under their own provisions.
The 2024 amendments matter to multinational VPN groups. They made retention-notice enforcement expressly extraterritorial and clarified that a technical-capability notice can be issued to one group entity in relation to another entity's capability. That still does not prove a notice has been served or that a parent can technically produce records. It changes the questions Kape, HMA and any UK-linked operator should answer publicly.
European Union: national law now, e-evidence from August 2026
The CJEU has rejected general and indiscriminate retention of traffic and location data for ordinary crime while allowing narrower categories under safeguards, including targeted or expedited preservation and limited IP-address or civil-identity retention. A provider conclusion therefore requires the national law, the service classification and the data category. "EU-based" is not a legal result.
Regulation (EU) 2023/1543 applies from 18 August 2026. It will allow judicially issued or validated European Production and Preservation Orders to be addressed to designated establishments or legal representatives of covered service providers offering services in the Union. Preservation concerns data stored by or on behalf of the provider when the order arrives; it is not a general command to invent historical data. Notification, refusal, privilege and conflict rules remain relevant.
Sweden, Switzerland and Canada
Sweden: operator classification before slogan
PTS says operators with notifiable activities have law-enforcement retention duties and lists ten months for internet-access data. It also explains that temporary preservation can freeze data for up to 90 days, renewable once, but cannot require future data creation. That official position must be joined to whether a particular VPN is a covered operator and what its system generates. Mullvad's 2023 report that police left without customer data is strong real-world evidence for that event, not a perpetual exemption from Swedish law.
Switzerland: privacy law and surveillance law coexist
Swiss OFCOM guidance says the Surveillance of Postal and Telecommunications Traffic Act creates cooperation obligations for telecommunications providers and can also reach some services derived from telecommunications. Providers may have reduced obligations depending on classification. Official 2025 statistics record both real-time and retrospective surveillance measures. Proton's Swiss base is relevant; it is not the conclusion. Its VPN data design, legal entity, audit scope and request history complete the assessment.
Canada: preserve what exists, then use the right production order
Canada's Criminal Code distinguishes preservation from production. A preservation demand freezes specified computer data already in possession or control; it does not require a company to begin generating future traffic history. Subscriber, transmission and other records have separate production routes. TunnelBear therefore needs both a Canadian operator analysis and a US-parent control analysis.
Australia, India and offshore marketing jurisdictions
Australia's Assistance and Access Act created voluntary technical assistance requests, compulsory technical assistance notices and technical capability notices. The statute includes necessity, proportionality and systemic-weakness constraints. Those are serious powers, but "Australia can force every VPN to install a backdoor" is not a sufficiently precise legal conclusion.
India is the clearest provider-record rule in this comparison. CERT-In's 2022 direction requires covered VPN providers to retain validated subscriber identity, service period, allocated IP, onboarding IP and timestamp, purpose, address, contact and ownership-pattern information for five years or longer where law requires. It separately directs covered organisations to keep ICT-system logs for 180 days in India. Several major providers removed physical Indian servers rather than accept that model. That operational response is evidence of burden, not proof that every remote offering falls outside Indian reach.
British Virgin Islands and Panama addresses are often sold as privacy features. We treat them as one input. A marketed jurisdiction does not answer who operates the service, where processors and servers sit, whether a parent controls records, or which mutual-assistance and treaty routes are available. Offshore should mean "investigate further," not "immune."
What no-logs and RAM-only servers can actually prevent
A no-logs architecture can make a valid order return less. It cannot make the order invalid. RAM-only servers can reduce persistent data on an individual server and make redeployment more consistent. They do not automatically remove central authentication events, account identifiers, payment records, support tickets, abuse controls, crash analytics or data visible during a live session.
There are four separate proof questions. Does the provider normally retain the record? Can an existing record be preserved? Can the provider be ordered to collect a defined record prospectively? Can an authority or server host observe the connection outside the provider's claimed log store? A trustworthy audit names the systems, data categories, sampling window and limitations needed to test those questions.
Provider assessment: evidence, not flags
| Provider or group | Legal-reach assessment | Evidence burden |
|---|---|---|
| Kape / ExpressVPN / PIA / CyberGhost | UK parent, US-linked and EU/BVI product layers create several possible routes; no one flag resolves the group. | Entity-by-entity contracts, controller map, group access boundaries, post-acquisition audits and request statistics. |
| Nord Security / NordVPN / Surfshark | Dutch, Lithuanian and product-facing layers make current national process and the incoming EU e-evidence route relevant. | Regional contracting entities, designated representative, separation controls and product-specific audit scope. |
| Proton VPN | Swiss law applies to the Swiss operator; absence of a US or EU parent removes one corporate route but not Swiss process or cooperation. | Service-specific audit, classification, retained-data inventory and legal-request outcomes. |
| Mullvad / Mozilla VPN | Swedish operator law matters; Mozilla's separate customer and account relationship creates an additional data path. | Keep Mullvad and Mozilla controllers, account records and legal responses separate. |
| IPVanish / Ziff Davis | US ownership and operation make US production and preservation powers directly relevant to records held or controlled. | Current server-side audit, precise retention schedule and current transparency reporting. |
| TunnelBear / McAfee | Canadian operator history and US parentage require both domestic-process and parent-control tests. | Current entities, database control, processor map and jurisdiction-split request statistics. |
These are exposure assessments, not accusations that a secret order exists. The strongest opposing case is important: a large provider may have better legal teams, reproducible infrastructure and more frequent audits than a small offshore operator. The answer is not to reward independence automatically. It is to demand more proof wherever ownership, record control or legal reach becomes more complex.
What readers should do
- Find the operator and controller in the current terms and privacy policy.
- Use our ownership map to trace the parent, sister brands and review-site conflicts.
- Open the legal tracker, but treat its country colour as a research indicator rather than a provider verdict.
- List the records the VPN, payment processor, app store, support system and analytics stack actually create.
- Read the latest audit scope and transparency report. Do not accept an app test as proof of server-side non-retention.
- Match the remaining exposure to your threat model. A traveller on hotel Wi-Fi and a journalist facing a state investigation need different evidence.
Want a provider that publishes more of the evidence?
Our current evidence-led shortlist includes Proton VPN, NordVPN and Surfshark for different budgets and use cases. Compare their operator, audit and jurisdiction evidence before buying; none is immune from lawful process and none replaces Tor or specialist advice for a high-risk target.
Affiliate disclosure: Those three links may earn The VPN Matrix a commission at no extra cost to you. Commission does not change the Matrix score, legal assessment or inclusion. Mullvad and IVPN are also discussed in our evidence set, and we currently earn no commission from their direct links. Read our full disclosure and editorial policy.
Frequently asked questions
Can the CLOUD Act force every VPN to hand over data?
No. The relevant US rule reaches a covered provider subject to US process for records in its possession, custody or control, even when those records are stored abroad. It does not put every foreign VPN under US law merely because it has US customers or rents a US server, and it does not require a provider to create a permanent browsing log that does not exist.
Does Five Eyes membership mean one country's warrant works in every member country?
No. Intelligence sharing is not a substitute for legal authority over the provider. Cross-border requests still need a lawful route, such as domestic process against an entity with control, mutual legal assistance, a qualifying direct-access agreement or another implemented evidence mechanism.
Can a no-logs VPN ignore a valid court order?
No. A provider must respond according to the law that applies. A defensible no-logs design changes the response because it reduces the records available to produce. It does not cancel legal process, protect payment or support records automatically, or prove that prospective collection cannot be ordered.
Is Switzerland automatically safer than the United States or United Kingdom?
No. Switzerland has its own surveillance statute and cooperation duties, and official guidance says telecommunications and some derived communications services may have to cooperate. The useful question is whether the particular VPN is covered, what data it creates, and what the order can lawfully require.
Does the EU ban communications-data retention?
No. EU case law rejects general and indiscriminate traffic or location retention for ordinary crime, but permits defined forms of targeted, expedited, IP-address or civil-identity retention under safeguards. National law and service classification still matter. The EU e-Evidence Regulation will add cross-border production and preservation orders from 18 August 2026.
What is the best evidence that a VPN cannot identify a user?
A current server-side audit, a precise retention schedule, transparent account and payment data flows, public legal-request reporting, and real cases in which authorities obtained no useful customer record are stronger than a country badge or a broad no-logs slogan.
Sources
Sources are ordered by authority: statutes and official government or regulator guidance first, then the provider's own incident account. Provider statements are evidence of what the provider reported, not independent proof of every system state.
References
- [1]Australian Parliament (2018) 'Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018', Federal Register of Legislation. Available at: https://www.legislation.gov.au/C2018A00148/latest/text (Accessed: 26 July 2026).
- [2]Council of Europe (2022) 'Second Additional Protocol to the Convention on Cybercrime', Cybercrime Convention Committee. Available at: https://www.coe.int/en/web/cybercrime/second-additional-protocol (Accessed: 26 July 2026).
- [3]Court of Justice of the European Union (2024) 'Case C-470/21, La Quadrature du Net and others', EUR-Lex. Available at: https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:62021CJ0470 (Accessed: 26 July 2026).
- [4]European Parliament and Council (2023) 'Regulation (EU) 2023/1543 on European Production and Preservation Orders', EUR-Lex. Available at: https://eur-lex.europa.eu/eli/reg/2023/1543/oj/eng (Accessed: 26 July 2026).
- [5]Government of Canada (2026) 'Criminal Code, preservation demands and production orders', Justice Laws Website. Available at: https://laws-lois.justice.gc.ca/eng/acts/c-46/ (Accessed: 26 July 2026).
- [6]Indian Computer Emergency Response Team (2022) 'Directions under section 70B of the Information Technology Act', CERT-In. Available at: https://cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (Accessed: 26 July 2026).
- [7]Mullvad VPN (2023) 'Mullvad VPN was subject to a search warrant: customer data not compromised', Mullvad Blog. Available at: https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised/ (Accessed: 26 July 2026).
- [8]Swedish Post and Telecom Authority (2026) 'Data retention for law-enforcement purposes', PTS. Available at: https://pts.se/internet-och-telefoni/sakerhet-och-skydd-av-uppgifter/datalagring/ (Accessed: 26 July 2026).
- [9]Swiss Federal Department of Justice and Police (2026) 'Telecommunications surveillance statistics for 2025', FDJP. Available at: https://www.ejpd.admin.ch/de/newnsb/In7wcvFLifhBDFtjfsjMq (Accessed: 26 July 2026).
- [10]Swiss Federal Office of Communications (2024) 'Registration and publication as a telecommunications service provider', OFCOM. Available at: https://www.bakom.admin.ch/en/registration-and-publication-as-a-tsp (Accessed: 26 July 2026).
- [11]UK Parliament (2016) 'Investigatory Powers Act 2016', legislation.gov.uk. Available at: https://www.legislation.gov.uk/ukpga/2016/25/contents (Accessed: 26 July 2026).
- [12]UK Parliament (2024) 'Investigatory Powers (Amendment) Act 2024: Explanatory Notes, Part 4', legislation.gov.uk. Available at: https://www.legislation.gov.uk/ukpga/2024/9/notes/division/7/index.htm (Accessed: 26 July 2026).
- [13]United States Department of Justice (2022) 'CLOUD Act Agreement between the United States and the United Kingdom', Office of International Affairs. Available at: https://www.justice.gov/criminal/criminal-oia/cloud-act-agreement-between-governments-us-united-kingdom-great-britain-and-northern (Accessed: 26 July 2026).
- [14]United States House of Representatives (2024) '18 U.S.C. 2713: Required preservation and disclosure of communications and records', United States Code. Available at: https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section2713 (Accessed: 26 July 2026).
- [15]United States House of Representatives (2024) '18 U.S.C. 2703: Required disclosure of customer communications or records', United States Code. Available at: https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section2703 (Accessed: 26 July 2026).
