Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.
A Five Eyes VPN question usually means: does it matter if my VPN is based in a country that shares intelligence? The Five Eyes are the US, UK, Canada, Australia and New Zealand. The Nine Eyes add Denmark, France, the Netherlands and Norway, and the Fourteen Eyes add Germany, Belgium, Italy, Spain and Sweden. Jurisdiction matters, but our evidence shows logs matter more. PIA, based in the US, saw three federal subpoenas produce no user data. Mullvad, in Sweden, had police leave with nothing.
This guide explains the alliances, where major providers sit and what actually protects you.
What the Five Eyes Are
The Five Eyes is an intelligence-sharing arrangement between the US, UK, Canada, Australia and New Zealand. The Nine and Fourteen Eyes are wider groups of countries that share some intelligence with them. For a VPN user, the worry is that a court could compel a provider in one of these countries to hand over data. Partners could then share it.

Where Major Providers Are Based
Our tables record NordVPN in Panama, ExpressVPN and PureVPN in the British Virgin Islands, Proton VPN in Switzerland, CyberGhost in Romania and hide.me in Malaysia, all outside the alliances. Surfshark is in the Netherlands, a Nine Eyes member. Mullvad in Sweden and AirVPN in Italy sit in the Fourteen Eyes. PIA, StrongVPN, VyprVPN, TorGuard and Norton operate from the US, and TunnelBear and Windscribe from Canada. Our VPN ownership guide covers the owners.

Why Logs Matter More
A provider can only hand over what it keeps. Three federal subpoenas to PIA produced no user data, and officers with a warrant left Mullvad empty-handed, our reviews record. Both companies sit inside the alliances. Our VPN audit tracker shows which providers had their no-logs claims checked independently.

Where Jurisdiction Does Matter
Local law can force logging. India’s 2022 CERT-In rules required VPNs with servers there to keep logs for 180 days, so providers such as Surfshark moved to virtual Indian servers hosted abroad. Our Surfshark India guide explains the move.
A Five Eyes VPN Is Not Automatically Unsafe
A US provider with audited no-logs claims and a court record can be safer than an offshore one with neither. Weigh evidence first: audits, court records, RAM-only servers and transparency, then jurisdiction.
Five Eyes VPN Choices by Need
Journalists and activists facing state adversaries may prefer a provider outside the alliances with strong audits. Everyday users protecting public Wi-Fi gain little from jurisdiction alone. Streamers care about servers more than base. Our guide to VPN for Journalists covers evidence, obfuscation and the limits.
RAM-Only Servers
RAM-only servers store nothing on disk, so seized hardware holds no stored data. Surfshark runs its network this way, Wikipedia notes. That reduces what any jurisdiction can collect from a server.
Transparency Reports
Some providers publish the legal requests they receive and how they answered. Read them alongside audits; a report with no data handed over supports a no-logs claim.
Your Own Country Matters Too
Your local law applies to you wherever your provider sits. Our VPN legality guide covers where VPN use is restricted.
Quick Check
For any provider, look up its base, its parent company, its audits and any court or raid record. Our Surfshark safety guide shows how we weigh those for one provider.
Data Requests in Practice
A request can only reach what exists. Providers with RAM-only servers and audited no-logs policies have little to hand over, whatever the country. That is why court records and audits weigh more in our reviews than an address on a map.
Is a Swiss or Panamanian Base Better?
Both sit outside the alliances. Proton is Swiss and NordVPN Panamanian; both also publish audits. The base adds a layer, not a guarantee. Our Proton VPN vs PrivateVPN comparison sets the two side by side.
Five Eyes VPN Myths
A base outside the alliances does not make a provider trustworthy on its own, and a base inside does not make it unsafe. Evidence decides: audits, court records and server design.
Quick Rule
Audited and tested under pressure: good in any country. Unaudited and offshore: unproven, not safe by default.
Server Locations vs Company Base
A provider’s servers sit in many countries, each under local law. That is why RAM-only design and virtual locations matter alongside the company’s own base.
Quick Check
Look up a provider’s base, parent, audits and legal record before trusting it with sensitive work.
Streaming and Jurisdiction
For streaming, a provider’s base matters little; server locations in the right countries matter more. Our Netflix VPN guide covers that side.
Keeping Track
Ownership and bases change through sales, as VyprVPN’s 2023 sale to Certida shows. Recheck a provider every year or two.
Ownership Can Cross Borders
A company elsewhere can own a provider registered offshore. NordVPN and Surfshark share an owner, Nord Security; ExpressVPN, CyberGhost and PIA belong to Kape. Check both the registration and the parent.
How We Research
This page draws on our audit, ownership and jurisdiction tables, our PIA and Mullvad reviews and Surfshark’s CERT-In announcement. We cross-checked these sources against each other, and where they conflict or something can’t be verified, we say so in the text rather than guessing. We checked time-sensitive figures, including prices in US dollars, on 8 October 2026. The main source we relied on is Surfshark’s CERT-In announcement. Our full approach lives on the About Us page.
Five Eyes VPN FAQ
The US, UK, Canada, Australia and New Zealand.
Not automatically; audited no-logs evidence matters more.
NordVPN, ExpressVPN, Proton VPN, CyberGhost, PureVPN and hide.me, among others.
PIA’s, through three federal subpoenas that produced no user data.
Yes, for servers inside it, as India’s CERT-In rules showed.
The Verdict
A Five Eyes VPN base is one factor, not the deciding one. Choose audited no-logs providers with a record under pressure, then prefer jurisdictions outside the alliances where all else is equal.
