A VPN’s home country decides who can legally compel it to hand over your data, and what it is required to keep in the first place. A provider with excellent encryption is still bound by the laws where it is registered, and those laws vary enormously.
That is why VPN jurisdiction belongs on your checklist alongside protocols and price. Two providers with identical technical specifications can offer very different real-world protection purely because of where their company sits.
Here is how jurisdiction actually works, which countries sit inside the intelligence-sharing alliances, and where the major providers are based.
Jurisdiction Decides Who Can Compel Your Provider
The legal address of a VPN company determines which government can make demands of it, and what it must comply with. That plays out in a few specific ways.
- Court orders and subpoenas. Local authorities can compel a company registered in their country to produce whatever data it holds.
- Data retention mandates. Some countries legally require communications providers to log and store user activity for a set period.
- Gag orders. In certain jurisdictions a provider can be barred from disclosing that it received a data request at all.
- Cross-border cooperation. Mutual legal assistance treaties let one country’s authorities request data through another’s courts.
The critical point is that encryption does not exempt a company from law. If a provider holds records and a court with authority over it demands them, they get handed over. Jurisdiction decides who holds that authority.
The Eyes Alliances, Explained Plainly
The intelligence-sharing alliances come up constantly in VPN discussions, usually with more alarm than explanation. Here is what they actually are.
Five Eyes is the core arrangement: the United States, United Kingdom, Canada, Australia and New Zealand share signals intelligence extensively. Nine Eyes adds Denmark, France, the Netherlands and Norway. 14 Eyes countries extend it further with Germany, Belgium, Italy, Spain and Sweden.
Membership means these governments cooperate on intelligence gathering and can, in practice, request information collected by partners. For a privacy tool, that widens the number of agencies with a potential route to your data.
The honest caveat is that membership alone does not make a provider unsafe. What matters is whether the company has anything to hand over, which brings us to the more important factor.
Retention Law Matters More Than Alliance Membership
Here is the nuance most jurisdiction guides skip. An alliance member with no mandatory logging can protect you better than a non-member country that legally requires providers to keep records.
VPN data retention laws are the sharper test. If a country compels providers to log connection times, IP addresses and session data, then a no-logs promise is legally impossible to keep there. If a country has no such requirement, a provider can genuinely hold nothing.
So the question worth asking is not only which alliance a country belongs to. It is whether that country forces providers to retain data, and whether its courts have shown any appetite for limiting surveillance. Those two things tell you more than a flag on a map.
Where the Major VPNs Are Based
This is where the theory meets the market, and the results surprise people. Several of the most privacy-respected names sit inside the alliances.
| Provider | Country | Alliance membership |
| GnuVPN | Portugal | None |
| Proton VPN | Switzerland | None |
| NordVPN | Panama | None |
| ExpressVPN | British Virgin Islands | None |
| Mullvad | Sweden | 14 Eyes |
| Surfshark | Netherlands | 9 Eyes |
| Private Internet Access | United States | 5 Eyes |
Read that carefully. Mullvad, widely treated as the privacy gold standard, is registered in Sweden, a 14 Eyes member. Surfshark sits in the Netherlands, inside the Nine. Private Internet Access is based in the United States, the centre of the Five.
None of that makes those providers bad, and each compensates with strong no-logs practice. But it shows that a reputation for privacy and a clean jurisdiction are separate things, and privacy-friendly VPN countries are not always where you assume.
Portugal’s Courts Keep Striking Retention Down
GnuVPN‘s jurisdiction is Portugal, which sits outside the Five, Nine and 14 Eyes arrangements entirely. That alone puts it in a smaller group than several better-known providers.
The more substantial point is what Portuguese courts have actually done. The Constitutional Court has struck down blanket data retention three separate times:
- April 2022, when it declared Law 32/2008, which mandated one year of traffic and location data retention, unconstitutional for being indiscriminate
- December 2023, when Parliament’s replacement law was struck down for the same defect
- A narrower third framework, Lei 18/2024, which regulates metadata access specifically for criminal investigations instead of requiring blanket collection
Portugal’s privacy protections are written into a constitution drafted in reaction to four decades of secret-police surveillance, and the courts have enforced them repeatedly against the legislature’s own attempts at mass retention.
Combined with GDPR, that produces a no-data-retention VPN environment backed by case law, not just by an absence of legislation.
For a provider, that means there is no legal mandate compelling it to log what its users do. A no-logs policy in Portugal is a promise the law permits it to keep.
No-Logs and Audits Complete the Picture
A good address is necessary and not sufficient, so it belongs in a set with two other things.
- A no-logs policy, because jurisdiction only matters in relation to what a provider actually holds
- Independent verification, whether an audit of the no-logs claim or an assessment of the apps themselves
- Infrastructure choices like RAM-only servers, which discard data on reboot
Providers in difficult jurisdictions have to lean hard on these to compensate, which is exactly what PIA does from the United States. Providers in clean jurisdictions get to stack them on top of a legal environment that is already working in their favour.
GnuVPN sits in the second group. It operates a no-logs policy from a country with no surviving blanket retention mandate, so the legal environment supports the promise instead of undercutting it.
GnuVPN’s Android app has also passed an independent security assessment under Google’s App Defense Alliance programme at assurance level 2. The best VPN jurisdiction is one where the law, the policy and the verification all point the same direction, which is the combination GnuVPN has.
FAQ
Does VPN jurisdiction matter?
Yes, though not in isolation. Does VPN jurisdiction matter comes down to what the law requires of your provider: a country with mandatory data retention makes a genuine no-logs policy legally impossible, while a country without one lets a provider hold nothing. Jurisdiction sets the legal ceiling on how private a service can be.
Is a Five Eyes VPN automatically unsafe?
No. A Five Eyes VPN faces broader intelligence cooperation, but if the provider retains no data there is nothing to compel. Private Internet Access is US-based and has had its no-logs claim tested in court. The alliance matters less than whether records exist at all.
Where is GnuVPN based?
Portugal. Where is GnuVPN based has a straightforward answer: its operating company is registered there, which places it outside the Five, Nine and 14 Eyes alliances and inside the GDPR framework. Portugal’s Constitutional Court has also struck down blanket data retention three times.
Which countries are the best for a VPN?
Countries without mandatory data retention and outside the intelligence alliances, which include Portugal, Switzerland, Panama and the British Virgin Islands. Among 14 Eyes countries, you can still find strong providers, since a no-logs policy plus audits can offset the jurisdiction. Court-tested constitutional privacy protection is the strongest signal.
Can a VPN be forced to log my activity?
In some countries, yes. Where data retention is legally mandated, providers must keep records regardless of their marketing. Where retention has been struck down or never existed, a provider can genuinely operate without logs. That is the practical difference jurisdiction makes.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.



