Data privacy laws like the EU’s GDPR and California’s CCPA give you legal rights over your personal data: the right to know what’s collected, to request deletion, and in some cases to opt out of sale or targeted advertising. What they don’t do is stop the collection from happening in real time as you browse. Understanding the difference matters if you’re deciding whether these laws already cover you, or whether a VPN still has a job to do.
What GDPR actually covers
The EU’s General Data Protection Regulation applies to any company processing the personal data of people in the EU, regardless of where the company is based. It requires clear consent for data collection, gives you the right to access and delete your data, and mandates that companies report data breaches within a strict timeline. Enforcement includes some of the largest privacy fines in history.
What GDPR does not do is prevent a website from trying to fingerprint your browser, log your IP address at the moment you connect, or share data with advertising partners before you’ve had a chance to object, it regulates what happens to data after collection and requires consent mechanisms, but it doesn’t technically block collection at the network level. A VPN operates before any of that: it changes what IP address gets logged in the first place.
What CCPA (and its successor, CPRA) covers in the US
California’s Consumer Privacy Act, later expanded by the CPRA, gives California residents rights similar in spirit to GDPR: the right to know what data is collected, to request deletion, and to opt out of the sale or sharing of personal data. Several other US states have since passed comparable laws, though coverage and specifics vary significantly by state, and there’s still no single federal privacy law covering the whole country.
This state-by-state patchwork is one of the reasons US-based VPN users often see more value in a VPN than users in stricter, more uniform jurisdictions: the legal floor of protection varies a lot depending on which state you’re in, while a VPN’s protection doesn’t change based on your location.
Where these laws and a VPN do different jobs
Data privacy laws regulate companies: what they can collect, how long they can keep it, and what rights you have to challenge it. A VPN addresses the network layer: it hides your IP address from the sites you visit and encrypts your traffic so your ISP can’t see which sites you’re visiting in the first place. Neither replaces the other.
A useful way to think about it: GDPR and CCPA are about accountability after data exists. A VPN like ProtonVPN reduces how much identifying data gets created and logged in the first place, particularly IP-based data that a lot of tracking and profiling still relies on.
Why jurisdiction still matters for your VPN provider
Ironically, the same patchwork of privacy law that makes GDPR and CCPA matter to you also applies to the VPN provider you choose. A VPN based in a country with strong data protection law and no mandatory data retention requirements (Switzerland and Panama are common examples among audited providers) faces less legal pressure to log and hand over user data than one based in a country that can compel disclosure. See our breakdown of VPN jurisdiction and the Five Eyes/Nine Eyes/Fourteen Eyes alliances for how this plays out in practice.
Other regional laws worth knowing about
Brazil’s LGPD (Lei Geral de Proteção de Dados) closely mirrors GDPR’s structure and applies to any company processing the data of people in Brazil, regardless of where that company is headquartered. The UK maintains its own version of GDPR (UK GDPR) post-Brexit, functionally similar to the EU original but enforced separately by the UK’s Information Commissioner’s Office. Neither of these, like GDPR and CCPA, does anything to stop a VPN’s core function from being useful: masking your IP and encrypting your traffic remains relevant to users in Brazil and the UK just as much as it does in the EU or California, since the law and the network-level protection solve different parts of the same broader privacy problem.
What happens when these laws and government surveillance requests overlap
It’s worth being clear-eyed about a limitation these laws share: none of them override a government’s separate legal authority to compel data disclosure for law enforcement or national security purposes, through warrants, subpoenas, or, in some jurisdictions, more opaque legal processes. GDPR and CCPA govern commercial data practices; they are not a shield against lawful government access requests, which operate under entirely different legal frameworks in every country. This is precisely why a VPN provider’s jurisdiction and the actual existence (or non-existence) of logs to hand over matters independently of what privacy law otherwise applies to that provider.
What actually changed for VPN users because of these laws
VPN providers operating in the EU or serving EU customers are themselves subject to GDPR for any data they do collect, like billing information or support tickets. This is one reason audited no-logs claims matter: a provider can be fully GDPR-compliant on the data it does hold while still logging more connection data than its marketing suggests, unless that claim has been independently verified. Look for audited no-logs VPNs rather than relying on privacy-law compliance alone as proof of a strong privacy posture.
How to actually exercise your rights under these laws
If you want to see what a company has collected about you, most GDPR- and CCPA-covered businesses are legally required to provide a way to submit a data access or deletion request, typically through a privacy settings page or a dedicated email address listed in their privacy policy. Response timelines are set by law (30 days is common under GDPR, with some extensions permitted for complex requests), so a company ignoring a properly submitted request is itself a violation you can escalate to the relevant regulator, the Information Commissioner’s Office in the UK, national data protection authorities in the EU, or the California Privacy Protection Agency in the US.
Doing this periodically for the services you use most, streaming platforms, social media, and data broker sites in particular, is a more direct way to reduce your actual data footprint than most technical measures, since it removes data that already exists rather than just preventing new collection going forward.
The practical takeaway
If you live somewhere covered by GDPR, CCPA, or a similar law, you have real legal tools: request what a company has on you, ask for deletion, opt out of data sales where applicable. Use them. But don’t mistake having those rights for not needing a VPN. The laws govern what happens to data that already exists; a VPN reduces how much identifying data gets generated by your connection in the first place. They’re complementary tools, not substitutes for each other.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
GDPR, CCPA, and similar laws are real, useful legal protections, but they regulate what companies do with your data after it's collected, not whether tracking happens at the network level in the first place. A VPN with a verified no-logs policy and a privacy-friendly jurisdiction addresses the gap these laws leave open.
For the strongest combination of audited no-logs credentials and privacy-friendly jurisdiction, NordVPN and ProtonVPN remain our top-scoring picks in this category.
Keep reading: Five Eyes, Nine Eyes, and Fourteen Eyes Explained and Who Really Owns Your VPN? Ownership Transparency in 2026.