VPN Jurisdiction and No-Logs Audits: What the Fine Print Means
Why Panama, Switzerland and the BVI matter, what 5/9/14-Eyes means in practice, and how to read an audit report.
Every VPN says it keeps no logs. The two things that make that claim worth anything are where the company can be compelled to log, and whether an outside firm has checked.
Jurisdiction
Panama (NordVPN), the British Virgin Islands (ExpressVPN) and Switzerland (Proton) have no mandatory data-retention laws for VPNs and are outside the 5/9/14-Eyes intelligence-sharing agreements. The Netherlands (Surfshark) and the United States (PIA) are inside them. Romania (CyberGhost) and Sweden (Mullvad) are EU members; Sweden is in 14-Eyes but Mullvad has designed its service so there is nothing to hand over.
Audits
A no-logs audit is a firm such as Deloitte, KPMG or Cure53 inspecting servers and configuration and confirming nothing is stored. Look for the date (NordVPN 2024, PIA 2024, Proton 2024, Surfshark 2023, ExpressVPN and CyberGhost 2022) and whether the report is public. Mullvad and Proton also publish app source code.
Court records
PIA has twice been unable to produce logs in US cases; ExpressVPN's Turkish server seizure in 2017 yielded nothing. That history counts for as much as a policy page.
» See the full rankings: Best VPN for Privacy in 2026, Best VPN for Torrenting in 2026 .