If you’ve spent any time researching VPNs, you’ve seen these terms: Five Eyes, Nine Eyes, 14 Eyes. Review sites use them constantly, usually as a reason to avoid VPNs based in certain countries. Most explanations stop at listing the member countries. This one goes further.
Here’s what these alliances actually are, what real cases show they can compel a VPN provider to do, and how much they should actually influence your VPN choice.
What is the Five Eyes alliance?
The Five Eyes (FVEY) is an intelligence-sharing agreement between five English-speaking countries: the United States, the United Kingdom, Canada, Australia, and New Zealand.
It grew out of the UKUSA Agreement, signed in 1946 after World War II. The original focus was signals intelligence (SIGINT): intercepting communications between foreign governments. Over the following decades it expanded into a comprehensive framework covering signals, human intelligence, and bulk data collection. There’s also a lesser-known oversight body, FIORC (Five Eyes Intelligence Oversight and Review Council), which brings together the inspectors-general and review agencies of the five member states. It exists mostly to compare notes on oversight, not to limit what the alliance collects.
What makes the Five Eyes significant for privacy is that its members agree to share surveillance data with each other. In practice, this means one country can ask another to collect data on its behalf, then receive that data, sidestepping domestic legal restrictions on spying on its own citizens.
The NSA’s PRISM program, revealed by Edward Snowden in 2013, showed the scale of what Five Eyes collection looks like in practice. The alliance isn’t a theoretical concern, and neither is the older ECHELON system, a global network of interception stations built to sweep up phone, fax, and satellite traffic. Washington has never officially confirmed ECHELON exists, but declassified documents and independent investigations have described it in detail for decades.
Five Eyes members: United States, United Kingdom, Canada, Australia, New Zealand
Nine Eyes adds four more countries
The Nine Eyes extends the Five Eyes framework to include Denmark, France, the Netherlands, and Norway. These four countries take part in intelligence sharing but with more limited access than the core five.
In privacy terms, the Nine Eyes matters because it widens the pool of countries that can request data on each other’s behalf. A French court order demanding data from a Dutch company, for example, carries more weight when both countries sit inside the same intelligence framework.
Nine Eyes adds: Denmark, France, Netherlands, Norway
14 Eyes extends further across Europe
The 14 Eyes adds Germany, Belgium, Italy, Spain, and Sweden to the Nine Eyes framework. Intelligence circles call this group SSEUR, SIGINT Seniors Europe, a body that has met annually in various forms since the early 1980s.
By this point, the alliance covers most of Western Europe plus the US, UK, Canada, Australia, and New Zealand. For VPN users, this means a provider incorporated in Germany sits technically inside a 14 Eyes country, even though Germany’s domestic privacy laws are among the strictest in Europe.
14 Eyes adds: Germany, Belgium, Italy, Spain, Sweden
There’s more than three alliances
Five, Nine, and 14 Eyes get all the attention, but they aren’t the only intelligence-sharing clubs worth knowing about.
SIGINT Seniors Pacific (SSPAC) is the Asia-Pacific counterpart to SSEUR, formed in 2005. Its members include the Five Eyes countries plus South Korea, Singapore, Thailand, France, and India.
Club de Berne is an older, informal network of European security and intelligence services (not limited to SIGINT) that has existed in some form since 1971. It’s rarely discussed in VPN marketing, but it’s part of the same broader picture of European agencies comparing notes with each other.
A possible “Six Eyes” has come up periodically since 2020, when Japan’s then defense minister floated closer intelligence cooperation with the Five Eyes in an interview with Nikkei. Nothing formal has come of it, and Japan isn’t a member of any of the three alliances covered here, but it’s a reminder that the list of five, nine, or fourteen countries isn’t set in stone.
None of this changes the core advice. It just means “outside the 14 Eyes” isn’t automatically the same thing as “outside every intelligence-sharing arrangement that exists.”
Does jurisdiction actually matter for VPN users?
Here’s the nuanced answer most reviews skip: jurisdiction matters, but it’s not the only thing that matters, and it’s often overweighted by people who haven’t thought through the actual threat model.
When jurisdiction matters a lot: If you’re a journalist, activist, or someone living under a government that might pressure a VPN provider through legal channels, jurisdiction is important. A US-based VPN can be served with a National Security Letter, a secret order that prohibits the recipient from disclosing it. A VPN in Panama cannot.
When jurisdiction matters less than people think: For the vast majority of VPN users (people who want to avoid ISP tracking, access geo-restricted content, or use public Wi-Fi safely), what matters more is whether the VPN actually keeps no logs. A no-logs VPN in a Five Eyes country, with that claim independently audited and court-tested, provides better practical protection than a VPN in a “safe” jurisdiction that keeps logs but hasn’t been verified.
The reason: if a VPN keeps no logs, there is nothing to hand over. Jurisdiction only becomes relevant if data exists.
NordVPN (Panama) and Mullvad (Sweden) illustrate this well. Panama sits outside Five Eyes, which is a privacy advantage. But Mullvad, incorporated in Sweden (a 14 Eyes country), has had its servers physically seized by police, and nothing was found, because it actually keeps no logs. Both are credible options for different reasons.
Real cases: what jurisdiction has actually forced VPNs to do
Theory is one thing. Here’s what’s happened in practice, in Five Eyes countries specifically:
- IPVanish (US, 2016) handed connection logs to the FBI as part of a criminal investigation, despite marketing itself as a no-logs VPN at the time. The company has since changed ownership and rebuilt its logging practices, but the case is the clearest example of a “no-logs” claim failing under US legal pressure.
- HideMyAss (UK, 2011) was ordered by a UK court to hand over user data connected to a hacking investigation. HMA didn’t disclose this to its users until after the case became public.
- Lavabit (US, 2013) was served a secret order demanding the encryption keys to its users’ email, as part of the investigation into Edward Snowden. Rather than comply, founder Ladar Levison shut the service down.
- Riseup (US), a privacy-focused email and VPN collective, was compelled to log specific user data under a gag order that also barred it from updating its warrant canary.
- TorGuard (US) was forced to block BitTorrent traffic on its US servers as part of a copyright settlement, showing that Five Eyes jurisdiction risk isn’t limited to government surveillance. Private litigation counts too.
None of these VPNs were in “bad” jurisdictions by accident. All of them were incorporated in Five Eyes countries where courts and agencies have real legal tools to compel cooperation, sometimes with a gag order attached so the company can’t even tell you it happened.
Countries outside all three alliances
If jurisdiction is a priority for you, these countries have no mandatory data retention laws and sit outside Five Eyes, Nine Eyes, and 14 Eyes:
- Panama (NordVPN’s home jurisdiction)
- Switzerland (ProtonVPN). Swiss law requires a criminal investigation before data can be compelled
- Iceland (strong privacy laws, outside EU mandatory retention directives)
- British Virgin Islands (ExpressVPN was incorporated here, though now owned by Kape Technologies, UK)
- Romania (CyberGhost parent company incorporated here)
- Malaysia (Hide.me)
Switzerland deserves special mention. Swiss law doesn’t just place it outside intelligence alliances. It actively requires a formal criminal investigation opened by Swiss authorities before any data can be compelled. Even then, the process is slow and transparent. This is why Proton (ProtonMail, ProtonVPN) chose Geneva as its base.
Beyond the alliances themselves, this is also part of a live regulatory picture in 2026. The EU’s “going dark” proposals and the ongoing chat control debate keep raising the question of what governments can force providers, VPNs included, to log or scan. Jurisdiction on paper doesn’t freeze in place; it moves with the law. Worth reading if you want the current state of play: what the EU chat control vote means for VPNs and the EU’s Going Dark proposal, explained.
How we score jurisdiction at VPN Picker
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Our Compare page includes jurisdiction as one of 18 scored criteria. VPNs in Panama, Switzerland, Iceland, and similar jurisdictions score highest. VPNs in the US, UK, and Australia score lower because of the legal tools available to those governments (NSLs, RIPA, and similar mechanisms). VPNs in Nine or 14 Eyes countries land in the middle.
Jurisdiction score is one input, not the only one. A VPN with a good jurisdiction score but no independent no-logs audit still scores poorly overall. You can see the full breakdown for any VPN on the Compare page.
The bottom line
The Five Eyes, Nine Eyes, and 14 Eyes alliances are real and relevant. They represent genuine legal risk for VPNs that collect data, and the IPVanish and HideMyAss cases above show what that risk looks like when it lands. But they’re not a simple checklist where “outside = safe.”
The honest framework: start with jurisdiction, it’s a meaningful filter, then verify the no-logs claim with independent audits or a court-tested track record, then check ownership. A “Panama VPN” owned by a UK holding company has less protection than the headline suggests. All three together give a clearer picture than any one factor alone.
For a full comparison of how 48 VPNs score across jurisdiction, no-logs audits, and 17 other criteria, see the Compare page.
Quick reference
Five Eyes: US, UK, Canada, Australia, New Zealand
Nine Eyes adds: Denmark, France, Netherlands, Norway
14 Eyes adds: Germany, Belgium, Italy, Spain, Sweden
Best jurisdictions for privacy: Panama, Switzerland, Iceland, BVI
Jurisdiction matters, but no-logs verification matters more for most users.
FAQ
Is a VPN in a Five Eyes country automatically unsafe?
No. A verified no-logs VPN in a Five Eyes country provides strong practical protection because there is no data to hand over. Jurisdiction becomes the deciding factor only when data exists and a government wants it.
Can Five Eyes governments force a VPN to install surveillance software?
In theory, yes. The US and UK have legal mechanisms to compel cooperation and impose gag orders. In practice, this is a risk for high-value targets, not typical VPN users. VPNs with open-source clients and regular audits are harder to compromise without detection.
Does the 14 Eyes apply to all EU countries?
No. Only Belgium, France, Germany, Italy, Netherlands, Spain, and Sweden are 14 Eyes members. Other EU countries, and Romania is a good example, sit outside all three alliances.
Are there intelligence alliances beyond the Five, Nine, and 14 Eyes?
Yes. SIGINT Seniors Pacific (SSPAC) links the Five Eyes with South Korea, Singapore, Thailand, France, and India. The Club de Berne is an older, informal European security network. Japan has floated closer ties with the Five Eyes since 2020 but hasn’t formally joined anything. None of these get the same attention as the 14 Eyes in VPN marketing, but they’re part of the same picture.
What about China, Russia, and other authoritarian countries?
The Five/Nine/14 Eyes alliances are separate from authoritarian surveillance states. A VPN incorporated in China operates under entirely different, and more direct, government control. Most serious privacy-focused VPNs are deliberately incorporated outside both Western intelligence alliances and authoritarian jurisdictions.
Keep reading: Best VPN Jurisdiction in 2026: Panama vs Switzerland vs Iceland and Who Really Owns Your VPN? The Consolidation Map in 2026.