VPN Jurisdictions Ranked: Where Your Provider Answers Subpoenas

A tier-by-tier ranking of our tracked VPNs by legal jurisdiction, and a plain-English guide to what Eyes-alliances and data-retention laws actually do to your provider.

Tomas
July 9, 2026
6 min read

A VPN's marketing usually leads with server counts and encryption ciphers. Those matter, but the question that decides what happens when a court comes knocking is quieter: which country's laws can legally compel your provider to hand over data. That is what "vpn jurisdiction" means, and it is not the same as where a server sits.

Data verified from official vendor pages, updated August 28, 2026.

Below I rank the providers we track by jurisdiction tier, then explain the frameworks behind the tiers so you can judge compulsion risk yourself rather than trust a badge. If you want the deeper legal background, our jurisdiction primer unpacks the treaties in detail.

Jurisdiction is about compulsion, not geography

Server locations are an engineering choice. Jurisdiction is a legal one. A provider headquartered in a country with strong privacy statutes and no blanket data-retention mandate is harder to compel than one based in a Five-Eyes founding member, regardless of where its servers physically live.

The shorthand you will see everywhere is the Eyes-alliances: the Five Eyes (intelligence-sharing among founding English-speaking states), expanded to Nine and then Fourteen with additional partners. Membership does not mean a VPN logs you. It means the legal machinery for intelligence sharing and cross-border requests is already built, so a request in one member state can travel farther than it otherwise would.

The second factor is data-retention law. Some jurisdictions require certain communications providers to hold connection metadata for a fixed period. If a country mandates retention, a no-logs promise has to be read against the possibility of local legal pressure. If a country has strong privacy law and no such mandate, the promise stands on firmer ground.

A no-logs claim is only as strong as two things behind it: the jurisdiction that would enforce a compulsion order, and an independent audit confirming there is nothing to hand over. Jurisdiction is the half most buyers skip.

The tiers, defined

Here is how we group the tiers, from strongest privacy footing to weakest:

  • Tier 1 — strong privacy law and no blanket retention mandate. Examples in our set sit in Switzerland, Panama, the British Virgin Islands and Iceland.
  • Tier 2 — good protections; EU or EU-adjacent states outside the core Eyes-alliances.
  • Tier 3 — Fourteen-Eyes membership or credible state-access concerns.
  • Tier 4 — Five-Eyes founding members, where the compulsion and sharing machinery is most developed.

These tiers describe legal exposure, not a verdict on any single provider's honesty. A Tier 1 base with no audit is not automatically safer than a lower-tier provider with a clean, repeated audit. Jurisdiction is one input; treat it that way.

Tracked providers ranked by jurisdiction tier

TierProviderBase jurisdictionWhat the tier signals
Tier 1ExpressVPNBritish Virgin IslandsNo blanket retention; outside Eyes-alliances
Tier 1NordVPNPanamaStrong privacy footing, non-Eyes
Tier 1ProtonVPNSwitzerlandStrong privacy law, non-Eyes
Tier 1PrivadoVPNIcelandStrong privacy footing, non-Eyes
Tier 2CyberGhostRomaniaEU, non-Eyes; good protections
Tier 2Bitdefender Premium VPNRomaniaEU, non-Eyes; good protections
Tier 2Avast SecureLine VPNCzech RepublicEU, non-Eyes; good protections
Tier 2F-Secure VPNFinlandEU; good protections
Tier 3SurfsharkNetherlandsFourteen-Eyes concerns
Tier 3Kaspersky VPN Secure ConnectionRussiaState-access concerns
Tier 3iTop VPNHong KongState-access concerns
Tier 4Norton VPNUnited StatesFive-Eyes founding member
Tier 4HMA (HideMyAss!)United KingdomFive-Eyes founding member

You can cross-reference any of these on the full providers list or line two up side by side with our comparison tool.

Tier 1: the strongest legal footing

ExpressVPN (British Virgin Islands), NordVPN (Panama), ProtonVPN (Switzerland) and PrivadoVPN (Iceland) all base themselves outside the Eyes-alliances in jurisdictions without blanket retention mandates. This is the position that lets a no-logs policy carry the most weight, because there is less local legal machinery to compel disclosure in the first place.

A caveat I will repeat until it sticks: a favorable jurisdiction is necessary but not sufficient. It reduces the surface for compulsion; it does not by itself prove the servers hold nothing. That proof comes from independent audits, and their scope and recency should be checked per provider rather than assumed.

Tier 2: solid EU and EU-adjacent bases

CyberGhost and Bitdefender Premium VPN are based in Romania, Avast SecureLine VPN in the Czech Republic, and F-Secure VPN in Finland. These are good-protection jurisdictions inside or adjacent to the EU and outside the core Eyes-alliances. The EU's data-protection regime is a genuine strength here. Read each provider's policy on its own terms; you can start with CyberGhost's profile.

Tier 3: Fourteen-Eyes or state-access concerns

Surfshark is based in the Netherlands, a Fourteen-Eyes member, which places it in a higher-exposure tier on jurisdiction alone. Kaspersky VPN Secure Connection (Russia) and iTop VPN (Hong Kong) sit here for state-access concerns tied to their home jurisdictions. None of this describes their logging behavior; it describes the legal environment that behavior operates within.

Tier 4: Five-Eyes founding members

Norton VPN (United States) and HMA (United Kingdom) are headquartered in Five-Eyes founding members, where the compulsion and intelligence-sharing frameworks are most developed. That does not make them dishonest or unusable. It does mean the jurisdictional starting point is the weakest of the four tiers, and their no-logs assurances lean harder on audit evidence to compensate.

How to weigh jurisdiction against everything else

Jurisdiction is a filter, not a scoreboard. My suggested order of operations:

  1. Start with the tier. If your threat model includes legal compulsion, favor Tier 1 or Tier 2 and treat Tier 4 as needing extra justification.
  2. Demand an audit. A no-logs claim without independent verification is unverified, full stop. Check who ran it, when, and what scope it covered.
  3. Match the use case. For casual streaming, jurisdiction matters far less than for high-risk work. Our best-for guides sort by need.
  4. Ignore the fear-marketing. "Military-grade encryption" is a slogan, not a spec, and it tells you nothing about compulsion risk.

If you want the reasoning behind our scoring, the learn hub lays out how documented evidence — policies, audits, court records — feeds the tiers rather than vibes.

FAQ

Does a Five-Eyes base mean my VPN logs me?

No. Jurisdiction describes the legal machinery that could compel disclosure, not whether a provider records anything. A Tier 4 provider with a clean, recent independent audit may hold nothing to hand over. The point is that its promise carries more legal risk to lean on, so the audit evidence has to do more work.

Is jurisdiction more important than encryption?

They answer different questions. Encryption protects data in transit against interception; jurisdiction determines what a provider can be legally forced to reveal about you. Both matter. If your concern is subpoenas and cross-border requests, jurisdiction is the factor most buyers underweight.

Where can I see the evidence behind these tiers?

Each provider's profile links its official policy and any published audit, and our comparison tool puts jurisdictions side by side. Where a provider lacks an independent audit, we mark that gap as unverified rather than assume the best.

Tomas, Scout VPN Team

Ready to Choose a VPN?

Check out our reviews and find the perfect VPN for your needs.

View All VPNs