VPN Jurisdiction, Five Eyes, and What You Can Actually Check
VPN jurisdiction is shorthand for the legal system a provider operates under, and it is used in marketing as though it were a rating on a spec sheet. The more accurate picture is that jurisdiction is a property of legal entities, and any VPN service involves several entities established in several places at once. This page explains which those are and what you can establish for yourself. It does not state what any country’s law requires or what any intelligence-sharing arrangement can do — those are questions for official sources, not a blog.
A service is several entities, not one location
The brand on the app icon is not a legal person. Behind it there is normally a company you contract with, named in the terms of service, and often a different company named as responsible for your account data. Above both there may be a parent or holding company somewhere else. Alongside them sit suppliers: the businesses that own the physical machines the exit servers run on, the payment processor that handles your card, and sometimes a separate operator running the resolvers your lookups go to.
Each of those is established somewhere, and each is subject to the rules of the place it is established. “Based in” on a homepage refers to one of them and usually the most flattering one. It is not wrong, exactly, but it answers a narrower question than the reader thinks.
This matters most for people who chose a provider specifically on the strength of its stated home. If the entity in the terms of service differs from the one in the marketing, the one in the terms is the one you have a relationship with.
Where the servers sit is a separate fact
A provider incorporated in one country can serve traffic from machines in dozens of others, and those machines are ordinarily rented rather than owned. The company that owns the hardware and the rack has its own obligations in its own location, plus its own records about which customer had which address.
There is a genuinely useful consequence here, and it is one you can observe. Every address on the internet belongs to a registered network with a name and an operator attached, and the exit address you are given is no exception — what an ASN and reverse DNS reveal about your connection covers how to look this up. Doing it tells you which network actually carries your traffic, which is frequently a hosting company rather than the VPN brand. That is not a scandal; it is how nearly all of these services are built. But it does mean “our jurisdiction” describes the office, not the wire.
Why the alliance names are a weak signal
A large amount of writing in this category sorts countries by membership in named intelligence-sharing arrangements between states, and providers advertise sitting outside the ones with the most familiar names.
Treat that as weak evidence, for reasons that do not require knowing anything about the arrangements themselves.
It is a claim about states, not about a company. The arrangements concern cooperation between governments. A company’s exposure to legal process comes from where it is established, where its suppliers are, and where its data sits — a chain that a country-level label does not describe.
It is used as a substitute for the specific question. What a reader actually wants to know is: what could compel this company to produce a record about me, and does the record exist? A three-word label answers neither.
It travels well and ages badly. Lists of countries get copied between articles for years. Arrangements between states change, are described inconsistently, and are not published as a tidy roster for consumers to check.
And it can distract from a much simpler point: a company holding no attributable record is in a materially different position from a company holding one, and that is true regardless of the flag on its registration.
What this site will not do is tell you which states participate in which arrangement, or what powers any of them holds. That is exactly the kind of assertion that is stale, oversimplified, or wrong in every article that makes it.
What jurisdiction does decide, in general terms
Stated as categories rather than as anyone’s specific law, the legal system where an entity is established tends to determine three things.
Which authority can address a demand to that company, and what process is required before it does. Whether any rules require records to be created or kept in the first place, which can constrain what a company is able to promise. And what obligations attach in the other direction: data-protection duties, disclosure requirements, and whether you would have any practical remedy if the company broke its own commitments.
That last one gets almost no attention and is the most relevant to an ordinary customer. A promise you could never enforce anywhere is a different product from a promise made by a company inside a regime that supervises such promises.
The checks that are actually available to you
None of these require reading law, and all of them are current, which nothing written about a provider will be.
Read to the bottom of the terms of service and the privacy notice and write down every company name you find, along with where each is stated to be established. Look for a legal or company-information page, which in many places is required to publish a registration number and address. Note whether the same entity appears in the terms, the notice, and on your card statement — a different name on the payment line is a normal finding and a useful one. Check whether the provider publishes anything about how it handles official requests, and when it last did so. Then look up the network that owns your exit address, as above.
If a provider will not tell you plainly which entity you are contracting with, that reticence is itself the answer to a different question.
How this interacts with retention
Jurisdiction and record-keeping are usually discussed separately and they are really one topic. A demand can only produce what exists. So the question of where a company sits is downstream of the question of what it holds, which is why reading the retention language carefully — see which words do the work in a VPN logging policy — does more for you than comparing countries. The structural reason the operator sees both ends of your connection in the first place, and what that limits any promise to, is in what a no-logs VPN claim covers.
How much weight it deserves
Some, and less than it is given. Establish which entity you are dealing with, because that is a fact with consequences. Note where it says it is established, and note that its suppliers are elsewhere. Then spend your remaining attention on what the company records and on what an outside examination actually looked at, which is where a decision can be made on evidence rather than on a label — what gets examined when a VPN says it was audited sets out how to read that part.