5 Eyes, 9 Eyes, and 14 Eyes: Does It Matter for Your VPN?
The 5 Eyes, 9 Eyes, and 14 Eyes are intelligence-sharing groups, not automatic VPN safety ratings. Learn what jurisdiction can prove and what evidence matters more.
The 5 Eyes, 9 Eyes, and 14 Eyes are intelligence-sharing groupings, not automatic verdicts on whether a VPN is safe. A provider’s jurisdiction can determine which laws and legal orders reach it. What matters more in practice is whether the provider retains useful activity or connection records, whether an independent reviewer has examined that claim, and what the audit actually covered.
Treat an Eyes-country location as one risk factor, not a blacklist. A well-evidenced no-logs VPN in the United States can present a stronger privacy case than an unaudited service incorporated outside every named alliance.
What the 5 Eyes, 9 Eyes, and 14 Eyes actually are
The official core is the Five Eyes. Its roots are in the BRUSA agreement signed by the United States and United Kingdom on March 5, 1946, later known as UKUSA. Canada, Australia, and New Zealand joined during the following decade. GCHQ marked UKUSA’s 80th anniversary in May 2026 and described it as an active intelligence-sharing partnership.
The wider labels require more care. Public reporting based on leaked intelligence documents describes several partner circles with different purposes and access levels. “Nine Eyes” and “Fourteen Eyes” are convenient privacy-industry names, but they are not evidence that every listed country has the Five Eyes’ depth of access or that all 14 operate under one public treaty.
Five Eyes countries
The Five Eyes members are:
- Australia
- Canada
- New Zealand
- United Kingdom
- United States
These national partners cooperate closely on signals intelligence: information derived from communications and other electronic signals. The partnership also extends to security and cyber work, but each country still has its own agencies, laws, courts, and oversight bodies.
Nine Eyes countries
In consumer privacy discussions, Nine Eyes means the Five Eyes plus:
- Denmark
- France
- Netherlands
- Norway
Public sources describe these 4 countries as third-party intelligence partners rather than full UKUSA members. No known public Nine Eyes treaty gives all 9 countries identical rights.
Fourteen Eyes countries
Fourteen Eyes means the Nine Eyes countries plus:
- Belgium
- Germany
- Italy
- Spain
- Sweden
The underlying group is commonly associated with SIGINT Seniors Europe. Documents reported by The Intercept show that this European intelligence circle began with 9 members in 1982 and had expanded to 14 by 2013. The NSA sometimes called it “14 Eyes,” but that does not turn it into a single borderless surveillance authority.
How intelligence sharing works in practice
Do not picture one global database that automatically receives every VPN account. The public record instead shows national intelligence services collecting under their own authorities, collaborating on shared targets, and exchanging selected intelligence, methods, or technical capabilities.
Oversight is national too. The Five Eyes Intelligence Oversight and Review Council brings together review bodies from the 5 countries to compare methods and discuss cooperation. Its existence is useful context: intelligence sharing crosses borders, while legal powers and review mechanisms remain rooted in each country.
For a VPN customer, jurisdiction matters at the point where a government can serve a valid demand on the company that controls the service or its data. The practical result depends on the local law, the request, and what records exist. An offshore registration cannot erase data already collected, while a genuine data-minimizing design can reduce the historical information available to disclose.
What alliance membership does not tell you

An Eyes label cannot answer the most important VPN questions by itself:
- It does not prove that a VPN logs activity. That requires evidence about the provider’s systems, policy, and operations.
- It does not make an outside country surveillance-free. Countries beyond the named groups have their own intelligence powers and can cooperate internationally.
- It does not cover every corporate layer. The VPN’s operating company, parent owner, staff, payment processors, and servers can sit in different countries.
- It does not make an audit permanent. An assurance report examines a defined scope and period. Surfshark’s 2025 Deloitte report, for example, explicitly says later system changes could change its conclusion.
- It does not make a VPN anonymous. A VPN moves trust from your local network and internet provider to the VPN operator. Websites can still recognize signed-in accounts, cookies, and other identifiers.
That last point is central. The Electronic Frontier Foundation notes that a VPN can hide metadata from an untrusted local network while making the same information visible to the VPN provider. Choose the operator as carefully as you choose the jurisdiction.
VPN jurisdictions and no-logs evidence in 2026

The provider information below was verified on July 16, 2026. “Outside” means outside the commonly cited Five, Nine, and Fourteen Eyes country lists; it does not mean beyond all government authority.
| VPN | Service jurisdiction | Eyes status | Public no-logs evidence | Important context |
|---|---|---|---|---|
| NordVPN | Panama | Outside | Deloitte examined its no-logs claim in a 2025 assurance engagement | NordVPN’s parent company, Nord Security, is based in the Netherlands and formed a group with Surfshark |
| ExpressVPN | British Virgin Islands | Outside | KPMG examined its privacy-policy controls and TrustedServer system in 2025 | Express Technologies Ltd. is the BVI operator; ultimate owner Kape Technologies is based in the UK |
| Surfshark | Netherlands | Nine Eyes and Fourteen Eyes | Deloitte issued a point-in-time no-logs assurance report dated June 10, 2025 | Surfshark and Nord Security belong to the same group but say they retain separate infrastructure and product plans |
| Private Internet Access | United States | Five Eyes, Nine Eyes, and Fourteen Eyes | Deloitte completed a third review of PIA’s no-logs controls in 2025 | PIA is owned by Kape Technologies, which also owns ExpressVPN |
| ProtonVPN | Switzerland | Outside | Securitum completed a fifth consecutive annual review of Proton VPN’s no-logs controls | Proton VPN is operated by Swiss company Proton AG |
This comparison shows why a country-only rule fails. PIA sits in a Five Eyes country but publishes recent assurance evidence. Surfshark sits in a Nine Eyes country, while its VPN infrastructure and no-logs controls have been reviewed. NordVPN, ExpressVPN, and ProtonVPN have outside-alliance service jurisdictions, yet their audits still matter because jurisdiction alone cannot verify implementation. Compare their privacy cases directly in our NordVPN vs Private Internet Access comparison.
How to choose a VPN without overrating the map
Use this order of importance:
- Read the exact logging policy. Look for clear treatment of browsing activity, DNS requests, source IP addresses, assigned VPN addresses, timestamps, and session duration. “No browsing logs” can still leave connection metadata unaddressed.
- Open the independent report. Check the auditor, date, systems examined, assurance standard, and limitations. A marketing sentence about an audit is not the same as the report.
- Check the legal entity and owner. A brand’s headquarters slogan may omit the company named in its terms or the parent group behind it.
- Look for repeat evidence. Updated audits and transparency reports are more useful than a single old assessment because infrastructure and policies change.
- Match the service to your threat model. Avoiding local Wi-Fi snooping, reducing ISP visibility, and resisting a targeted legal investigation are different problems.
No consumer VPN guarantees immunity from lawful investigation. VPN rules and permitted uses vary by country; check the law where you are.
Our pick for privacy-conscious VPN users
NordVPN is our practical pick because its Panama service jurisdiction is outside the named Eyes groups and Deloitte reviewed its no-logs claim again for 2025. That combination is stronger than jurisdiction marketing alone. It is not proof that no account or billing data exists, and the assurance remains limited to its stated scope, so read our full NordVPN review before subscribing. See our NordVPN vs ExpressVPN comparison for how it compares to another Eyes-outside rival.
If you prefer a Swiss operating company, see our full ProtonVPN review. For a BVI-based alternative, our full ExpressVPN review also covers the Kape ownership tradeoff.
FAQ
Is the United States part of the Five Eyes?
Yes. The United States is a founding Five Eyes partner alongside the United Kingdom. Australia, Canada, and New Zealand complete the group. The US also appears within the wider Nine Eyes and Fourteen Eyes lists because those circles include the original 5 countries.
Is the Netherlands in the 5 Eyes, 9 Eyes, or 14 Eyes?
The Netherlands is not a Five Eyes member. It is commonly listed in both Nine Eyes and Fourteen Eyes. That makes Surfshark’s Dutch jurisdiction relevant, but its 2025 Deloitte no-logs assurance is more direct evidence about what its reviewed systems retained.
Can a no-logs VPN ignore a court order?
No. A VPN must respond to valid legal process under the laws that apply to it. A no-logs policy changes what historical VPN activity data may exist; it does not cancel legal authority or prevent a provider from holding ordinary account and payment records.
Is Switzerland part of the 14 Eyes?
No. Switzerland is not on the commonly cited Five Eyes, Nine Eyes, or Fourteen Eyes lists. Proton VPN’s Swiss jurisdiction is a useful factor, but its published no-logs audits and actual data practices still deserve more weight than location alone.
