Democratic lawmakers in the House and Senate sent a letter in March 2026 to Director of National Intelligence Tulsi Gabbard, raising a question most VPN users have never thought about: does routing your traffic through a commercial VPN change your legal protections against US government surveillance? The letter landed ahead of Congress’s April 20, 2026 deadline to renew FISA Section 702, and it puts VPN use itself under a legal microscope for the first time.
Nothing about your VPN changed today. No law passed, no VPN got banned, no court ruled on anything. But the letter signals that lawmakers are now scrutinizing a question that has sat unresolved for years. Here’s what FISA 702 actually does, what the letter asked, and why it matters even if you’ve never given US surveillance law a second thought.
What is FISA Section 702?
FISA stands for the Foreign Intelligence Surveillance Act. Section 702, added in 2008, lets US intelligence agencies like the NSA collect the communications of non-US persons located outside the country, without an individual warrant for each target. It’s the legal basis for programs like PRISM, the NSA collection program revealed by Edward Snowden in 2013.
The catch, and the reason 702 gets renewed with controversy every few years, is that it doesn’t just collect foreigners’ communications. When a foreign target talks to an American, or an American’s data happens to pass through the collection net, that data gets swept up too. This is called “incidental collection,” and it’s been the center of a fifteen-year fight between civil liberties advocates and intelligence agencies. Americans caught up this way don’t get the same warrant protections they’d have under ordinary domestic surveillance law.
Section 702 needs periodic reauthorization from Congress. That’s what’s driving the April 20, 2026 deadline, and it’s why lawmakers are asking pointed questions about the law’s scope right now rather than at some random point in the year.
What the letter to Gabbard actually asked
The letter, sent by Democratic members of the House and Senate to DNI Tulsi Gabbard, asked her office to clarify how commercial VPN use interacts with FISA protections. You can read the letter directly on Senator Wyden’s site: wyden.senate.gov.
The core concern isn’t that VPNs are dangerous or illegal. It’s narrower and more technical: when you route your internet traffic through a VPN, especially one based outside the US, or one that could itself be compelled to cooperate with intelligence requests, does that change how your communications get classified under FISA? Does it complicate whether you count as a “US person” with Fourth Amendment protections for a given piece of data, or does it push your traffic into a gray zone where those protections are murkier?
Nobody has a clean answer to that. It’s not that the government has ruled against VPN users. It’s that the question has apparently never been squarely litigated or clarified in public, and the lawmakers behind the letter want DNI Gabbard’s office to say, on the record, how her agencies treat VPN-routed traffic under 702.
Why VPN jurisdiction and routing matter here
This is a different question from the one people usually ask about VPN jurisdiction. Most privacy guides (including ours on Five Eyes, Nine Eyes, and 14 Eyes intelligence alliances) focus on where a VPN company is legally based and whether that country can compel it to hand over logs. That’s about protecting your data from your VPN provider being served a legal order.
The FISA question is different. It’s about how using a VPN, any VPN, might affect the government’s own classification of your communications when it’s collecting data in bulk under 702, independent of whether your specific VPN provider gets served anything. Encrypting your traffic and routing it through servers in another country could, in theory, change how a piece of communication gets flagged, whether it looks “foreign” or “domestic” to a collection system, and which legal standard applies to it. Legal scholars have flagged this kind of ambiguity for years without a definitive answer, and the letter to Gabbard is effectively asking the intelligence community to state its position clearly.
A US-based VPN provider is also more directly reachable by a National Security Letter or a FISA order than one incorporated in Switzerland or Panama, which is why jurisdiction still matters as a separate, additional factor. ProtonVPN’s Swiss base and ProtonVPN’s requirement of a Swiss criminal investigation before data can be compelled, or Mullvad’s Swedish anonymous-account model at mullvad.net, are relevant precisely because they sit outside direct US legal reach. But the letter raises a question that exists regardless of which VPN you use or where it’s based: what does 702 do with VPN-encrypted traffic in the first place.
What this means practically, today
Nothing changes for you right now. No VPN has been restricted, no new rule requires VPN providers to do anything differently, and using a VPN remains completely legal in the US. The letter is a request for clarification sent to one government official ahead of a legislative deadline. It’s a sign that a question is being asked in an official capacity, not a policy outcome.
What it does tell you is that VPN use is now explicitly part of the FISA 702 conversation in Congress, which wasn’t really the case in previous reauthorization cycles. If lawmakers get a response from DNI Gabbard’s office, or if VPN-related language ends up in whatever renewal or reform package moves through Congress before the April 20 deadline, that’s worth watching. Privacy advocates have pushed for stronger FISA reforms in past cycles and mostly lost those fights, so there’s no guarantee this letter changes anything concrete. But it’s the first time VPN use specifically, as opposed to VPN provider jurisdiction, has shown up this directly in the surveillance-law debate.
If you’re weighing which VPN to trust with your traffic in the meantime, jurisdiction, audited no-logs policies, and transparency reporting are still the practical levers you control. Our warrant canary explainer covers how VPNs signal secret government requests, which is the closest existing tool for tracking this kind of pressure on a specific provider.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
What to watch before April 20
A few things worth tracking as the reauthorization deadline approaches:
Whether DNI Gabbard’s office actually responds to the letter, and what it says about VPN traffic classification under 702.
Whether the House or Senate reauthorization bill includes any language specific to VPN use, encrypted traffic routing, or commercial privacy tools, none of which has happened yet.
Whether privacy organizations like EFF or ACLU pick up this specific VPN angle in their own 702 reform pushes, since they’ve historically focused more on warrant requirements for incidental collection generally.
None of this means you should stop using a VPN, and nothing here suggests VPN use itself creates legal risk for ordinary users. The question raised is about how the law treats your data, not whether you’re allowed to use the tool.
This is a letter asking a question, not a ruling or a new law. Nothing about VPN use has changed today, and no VPN provider has been implicated in any wrongdoing. What matters is that lawmakers are now scrutinizing how FISA 702 treats VPN-encrypted traffic ahead of the April 20, 2026 renewal deadline, an angle that hasn't gotten this much attention in past reauthorization fights. Keep using a reputable, audited, no-logs VPN in a favorable jurisdiction. That protects you from your provider being compelled to hand over data, which remains the more concrete and immediate risk. The FISA classification question is one to watch, not one to panic about.