Proton published an updated transparency report and warrant canary on July 14, 2026, and the headline number is the kind of thing a privacy-focused VPN wants to publish: 458 legal requests for information about who was connected to a specific Proton VPN server at a given time, all routed through the Swiss legal system, and none of them fulfilled. Proton says it had no connection logs to hand over, because it doesn’t keep them.
What the report actually says
According to Proton’s own blog post, the report covers requests seeking to identify a user connected to a specific VPN server at a specific time, the kind of request that would matter most if Proton did retain connection logs. All 458 requests came through Swiss legal channels, and Proton states it could not comply with any of them, since its no-logs architecture means the underlying data being requested was never recorded in the first place.
Proton has published a transparency report in some form since 2017, updating it periodically rather than on a strict schedule, typically when there’s a meaningful new legal request or policy shift worth disclosing. This July update is a routine continuation of that practice rather than a reaction to any single incident.
Why the warrant canary framing gets complicated in Switzerland
A warrant canary is normally a statement a company updates regularly to signal it hasn’t received a secret government order; its disappearance is meant to be the warning sign, since gag orders typically forbid disclosing the request directly. Our explainer on warrant canaries covers how that mechanism is supposed to work.
Proton’s own reporting notes something that complicates the usual warrant canary logic specifically for Switzerland: Swiss law generally requires that the target of a surveillance or data request eventually be notified, giving them the opportunity to contest it. That legal structure makes a silent, permanently secret gag order less likely under Swiss jurisdiction than in countries with more expansive national security letter regimes, which is part of why Proton and other Swiss-based or Swiss-law-governed services lean on jurisdiction as a selling point in the first place.
Why this matters even if you don’t use Proton
A transparency report is only meaningful in the context of a verifiable no-logs architecture, not the other way around. Proton’s claim has previously been tested through its independently audited no-logs policy, reviewed by KPMG, and the transparency report is the operational, ongoing evidence that the audited architecture is actually holding up when real legal requests come in, rather than just a one-time certification.
This is the distinction worth keeping in mind whenever a VPN provider markets a “no-logs” policy: an audit checks the system’s design at one point in time, while a transparency report shows what happens when that design is tested against actual government requests, on an ongoing basis. Providers that publish neither ask you to take the claim entirely on faith. Providers that publish both, and where the two are consistent over multiple years, have the strongest case.
It’s also worth noting what this report doesn’t cover. It says nothing about metadata Proton might collect for account administration, billing, or abuse prevention, which is a separate question from connection logs tied to VPN server activity. A thorough reading of any transparency report means checking exactly what category of data it addresses, not just accepting the reassuring headline number.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
What these 458 requests probably were
Proton’s report doesn’t name individuals or specific investigations, but the request type it describes, identifying who connected to a given server at a given time, is the standard shape of a criminal investigation request: police or prosecutors in some jurisdiction believe a crime was committed from a specific IP address at a specific timestamp, and they want to know which Proton customer was behind it. This is different from a broad surveillance request asking for ongoing monitoring of a user going forward.
That distinction matters because it shows the system working as designed on both sides. Legitimate law enforcement requests are still being filed and still going through Swiss courts, which is exactly the process Proton’s jurisdiction is meant to route them through, rather than something being suppressed. What changes is the outcome: the request is valid, but the data it’s asking for was never collected, so there’s nothing to disclose regardless of how legitimate the underlying investigation is.
The regulatory backdrop makes this report more than routine
This transparency report lands at a genuinely relevant moment. The European Union has been preparing an expanded data retention framework that would require VPN providers, messaging apps, and other online services to retain user connection metadata, IP addresses, timestamps, and login records, for at least a year. Our EU data retention coverage covers the proposal in more depth, but the short version is that it would make a genuinely no-logs VPN difficult to operate legally within EU territory if it becomes binding law.
Proton VPN operates under Swiss law, not EU law, which is one reason the company has consistently positioned Switzerland’s data protection framework as a structural advantage rather than just a marketing point. A report like this one, showing the no-logs policy holding up against real requests right as EU-wide retention mandates are being debated, functions as a practical argument for why jurisdiction outside the EU (and outside Five Eyes and Nine Eyes alliances) still matters for VPN users concerned about future-proofing their privacy against exactly this kind of legislative shift.
How Proton compares to peers on this specific practice
Not every VPN publishes a comparably detailed transparency report, and fewer still publish one broken down by request type and jurisdiction the way Proton does. Mullvad and a handful of other privacy-focused providers publish similar reports; many mainstream consumer VPNs publish more general marketing pages about their no-logs policy without the same level of request-by-request accounting.
This doesn’t mean providers without a public transparency report are hiding something, but it does mean Proton’s practice here is closer to the standard privacy advocates actually ask for, rather than the industry norm. If jurisdiction and verifiable process matter to you as much as raw features, it’s worth weighing alongside speed and streaming scores when comparing VPNs. Our ProtonVPN review covers the rest of the product beyond this specific practice.
Proton's July 14, 2026 transparency report is a solid, unglamorous confirmation of something that matters more than most VPN marketing claims: when 458 real legal requests came in through Swiss courts, there were no logs to hand over. That's the practical payoff of a genuinely audited no-logs architecture. It doesn't make Proton the right VPN for everyone, since jurisdiction and audits are only one part of the picture, but it's a meaningful data point if privacy and verifiable process are near the top of your list.
For more on how jurisdiction and legal requests intersect with VPN privacy claims, see best VPN jurisdiction in 2026.