Five Eyes Jurisdictions and VPN Privacy

Five Eyes membership is not a VPN verdict. It tells you that a provider may operate inside a country with mature intelligence powers and close foreign partners. It does not tell you what that provider logs, which legal entity runs it, or what a specific order could obtain.

What Five Eyes means

The alliance includes Australia, Canada, New Zealand, the United Kingdom, and the United States. The UK government describes it as a long-standing intelligence alliance. Its public response to Parliament's 2023 report on international intelligence partnerships also confirms intelligence sharing, shared analysis, and joint cooperation with foreign partners.

That cooperation does not merge five legal systems into one. A UK order uses UK law. An Australian notice uses Australian law. Overseas requests and intelligence sharing can move information between countries, but the authority, conditions, review process, and available safeguards depend on the route used. Claims that every Five Eyes agency can directly order every provider in all five countries go beyond the public record.

The law can reach providers in different ways

The UK's Investigatory Powers Act covers interception warrants, communications-data retention, equipment interference, duties on operators, and requests from overseas authorities. It also sets approval and oversight rules. The existence of those powers does not prove that a named VPN has received an order or that every provision applies to it.

Australia's Assistance and Access Act created technical assistance requests, technical assistance notices, and technical capability notices for designated communications providers. The statute defines who may issue them and for what purposes. Whether a VPN company falls within a provision requires the statute, the company structure, and the facts of the request. A country label cannot answer that question alone.

Review the company, not an alliance chart

Start with the operating entity and parent company. Check where each is incorporated, where staff and payment systems sit, and which entity signs the terms. Server location matters too, but a rented server in another country does not move the whole company there.

Then read the logging policy line by line. "No activity logs" may still leave account records, payment records, support messages, website logs, and temporary authentication data. Mullvad's published policy is useful because it lists those categories separately. It says the VPN service does not retain traffic, DNS requests, connection timestamps, source IP addresses, or bandwidth tied to an account. It also explains which payment and support records remain. That level of detail is more useful than a no-logs badge.

An audit can test whether selected systems matched the provider's claims during a defined period. It cannot guarantee future conduct, cover systems outside its scope, or prevent a later legal demand. Read the report, its dates, and its exclusions.

Jurisdiction is one control, not the whole threat model

A VPN shifts trust from the internet provider to the VPN provider. The VPN handles your connection and can see your source IP while you connect. HTTPS still protects the content between your browser and the destination, but the VPN does not hide logins, cookies, browser fingerprints, or information you give a site.

For ordinary protection on public Wi-Fi or from ISP browsing records, a well-run VPN may be enough. For separation from a persistent state adversary, one commercial VPN is a weak boundary regardless of its country. Use separate identities and do not attach identifying payments and accounts to them.

A practical VPN review

  • Identify the operating company, parent company, and controlling owners.
  • Read the current privacy policy, terms, and logging policy.
  • List retained account, payment, support, website, and session data.
  • Read the full audit report and note its date, scope, and exclusions.
  • Check the provider's transparency reports and documented responses to legal demands.
  • Decide whether a VPN is enough for the threat you face.

Do not choose a VPN from a coloured map of intelligence alliances. Choose it from evidence about the company, its systems, and the law that can reach them.

Sources

Frequently Asked Questions

What are the Five Eyes?

The Five Eyes are Australia, Canada, New Zealand, the United Kingdom, and the United States. Their intelligence agencies cooperate and share intelligence, but each country still acts under its own law.

Does a Five Eyes address make a VPN unsafe?

No. Country of incorporation is one part of the review. The provider's logging, payment records, ownership, infrastructure, audit scope, and response to legal demands also matter.

Does a no-logs policy remove legal risk?

No. It can reduce the historical data available to disclose, but the exact policy matters. Read what the provider stores for accounts, payments, support, websites, and live sessions. Also check whether an independent audit tested the relevant systems.