VPN Jurisdictions Ranked: Where Your Provider Answers Subpoenas

A jurisdiction-first ranking of our tracked VPNs. What Eyes-alliance membership and data-retention law actually mean for who can compel your provider, and which tiers we place each name in.

Tomas
July 9, 2026
6 min read

The country a VPN answers to is not a marketing footnote. It decides which courts can issue orders, which intelligence-sharing pacts apply, and whether a data-retention statute forces a provider to keep records it would otherwise discard. That is what a vpn jurisdiction analysis is really about: legal compulsion power, not the flags on a server map.

Below I group every provider we track into four jurisdiction tiers and explain the frameworks behind them. This is a living snapshot built from documented facts about where each company is incorporated, not from speed runs or lab benchmarks.

Data verified from official vendor pages, updated July 9, 2026.

What jurisdiction actually controls

Two separate things get conflated constantly, so let me separate them.

Server location is where a machine physically sits. It matters for latency and for local content, but a server can be wiped, run diskless, or seized without touching the company's core records.

Corporate jurisdiction is the legal home of the entity that owns your account, holds your billing data, and receives court orders. That is the pressure point. If you want the deeper mechanics, our jurisdiction primer walks through how compulsion works step by step.

The two levers that define compulsion risk:

  • Eyes alliances. The Five Eyes (US, UK, Canada, Australia, New Zealand), the Nine Eyes, and the Fourteen Eyes are intelligence-sharing arrangements. Membership signals a legal environment where cross-border data requests are routine.
  • Data-retention law. Some jurisdictions oblige communications providers to store connection metadata for a fixed period. A no-logs promise is far stronger when no statute forces the provider to log in the first place.

A no-logs policy only helps if it is technically real and legally survivable. In a low-compulsion jurisdiction with no retention mandate, "we have nothing to hand over" is a defensible position. In a Five-Eyes founding member, that same claim faces heavier legal weather.

The tiers, at a glance

TierWhat it meansProviders we track
Tier 1Strong privacy law, no mandated retentionExpressVPN (VG), NordVPN (PA), ProtonVPN (CH), PrivadoVPN (IS)
Tier 2Good protections, EU non-Eyes footingCyberGhost (RO), Bitdefender Premium VPN (RO), Avast SecureLine VPN (CZ), F-Secure VPN (FI)
Tier 314-Eyes or state-access concernsSurfshark (NL), Kaspersky VPN Secure Connection (RU), iTop VPN (HK)
Tier 4Five-Eyes founding membersNorton VPN (US), HMA (GB)

Higher tier is not automatically "better VPN." It is a lower-compulsion legal base. A Tier 4 provider with a clean audited no-logs record can still be a reasonable pick for many people; the tier just tells you the legal ceiling it operates under.

Tier 1: low-compulsion homes

These four sit in jurisdictions known for privacy-friendly law and no blanket data-retention mandate.

  • ExpressVPN is based in the British Virgin Islands, a jurisdiction with no data-retention requirement and legal distance from Eyes frameworks.
  • NordVPN operates from Panama, outside the major intelligence-sharing pacts.
  • ProtonVPN answers to Switzerland, which has strong constitutional privacy protections.
  • PrivadoVPN is based in Iceland.

Jurisdiction is a starting condition, not proof of behavior. What raises confidence is independent verification of the no-logs claim. When you compare these names on their profile pages (ExpressVPN, NordVPN, ProtonVPN), read the audit sections closely: the point is whether a third party confirmed the architecture, not whether the marketing says "private."

Tier 2: solid EU footing, outside the core Eyes

  • CyberGhost and Bitdefender Premium VPN are Romania-based. Romania is inside the EU but is not a Five/Nine/Fourteen Eyes member, and it famously pushed back against blanket EU data-retention rules in the past.
  • Avast SecureLine VPN operates from the Czech Republic.
  • F-Secure VPN is Finland-based.

These jurisdictions carry good baseline protections. The caveat with EU homes is that European legal instruments can create cross-border cooperation channels, so "non-Eyes" is not the same as "unreachable." Still, none of these are founding intelligence-sharing members. You can see how CyberGhost lines up against Tier 1 options on our comparison tool.

Tier 3: fourteen-Eyes reach or state-access questions

This tier is where nuance matters most.

  • Surfshark is based in the Netherlands, a Fourteen Eyes member. That places it inside a broad intelligence-sharing arrangement, which is why it sits below the Tier 1 cluster on jurisdiction alone. Its documented audit history is still worth reviewing on the Surfshark profile before you judge it.
  • Kaspersky VPN Secure Connection answers to Russia, a jurisdiction with significant state-access and data-localization concerns.
  • iTop VPN is associated with Hong Kong, where the legal environment for data requests has shifted meaningfully in recent years.

For the Russia and Hong Kong cases specifically, the concern is not just Eyes membership but the breadth of state power to compel or access data. I would treat those as elevated-risk on jurisdiction grounds for anyone whose threat model includes state actors.

Tier 4: Five-Eyes founding members

  • Norton VPN is US-based.
  • HMA (HideMyAss!) is UK-based.

The United States and United Kingdom are founding members of the Five Eyes and operate legal regimes with strong compulsion tools, including mechanisms that can attach confidentiality obligations to orders. That is the highest compulsion ceiling among the providers we track.

This does not mean these services log everything or hand over your history on a whim. It means the legal environment is the least favorable of the four tiers, so the burden of proof on a no-logs claim is heaviest here. HMA, notably, has a documented history tied to a case where account data assisted an investigation years ago, which is exactly the kind of court-record evidence that outweighs any slogan.

How to use these tiers

Jurisdiction is one input, not the whole score. Weigh it alongside:

  1. Independent audits. Has a named third party verified the no-logs architecture? An unaudited claim in a Tier 1 country is weaker than an audited one, though the combination of both is strongest.
  2. Ownership transparency. Who ultimately owns the entity, and where does that parent sit?
  3. Your threat model. Casual privacy from advertisers is a very different bar than protection against a determined state adversary.

If your priority is the lowest legal compulsion ceiling, start with the Tier 1 group and verify their audit records. If you are optimizing for something else, like streaming, jurisdiction may weigh less in your decision. Browse the full lineup on our providers page, or read more background in our learn hub.

Where a jurisdiction claim rests on documents I could not confirm, I have said so rather than guessed. Anything in this article beyond the incorporation tiers, such as internal logging behavior, should be checked against each provider's current audit status, which is unverified here unless the individual profile says otherwise.

FAQ

Does a Five-Eyes jurisdiction mean my VPN logs me?

No. It means the legal environment has stronger compulsion tools, so a no-logs claim faces a tougher legal test. Whether a specific provider actually logs depends on its policy and, ideally, an independent audit, not on the country alone.

Is server location the same as jurisdiction?

No. Servers can sit anywhere, but the company that receives court orders and holds your account data is governed by its corporate jurisdiction. That corporate home is what this ranking is about.

Why is Surfshark in Tier 3 when it is a well-known service?

Because the Netherlands is a Fourteen Eyes member, which sets its jurisdiction tier. Tier placement reflects legal compulsion reach, not overall quality. Its audit history is a separate factor you should weigh on its profile.

Tomas, Scout VPN Team

Ready to Choose a VPN?

Check out our reviews and find the perfect VPN for your needs.

View All VPNs