Skip to content
VPNmine
PRIVACY AND LAW

Five, Nine and Fourteen Eyes: what they actually change

The Eyes alliances are intelligence-sharing arrangements between states, and they are frequently used to argue that a VPN in a member country is unsafe. Jurisdiction matters for what a provider can be compelled to do, but it matters far less than what the provider actually retains.

4 min read

Illustration of a globe and an eye, joined by a dashed tunnel line on a dark grid.

The Five Eyes is a signals intelligence arrangement between Australia, Canada, New Zealand, the United Kingdom and the United States, originating in the UKUSA Agreement after the Second World War. Nine Eyes adds Denmark, France, the Netherlands and Norway. Fourteen Eyes adds Belgium, Germany, Italy, Spain and Sweden.

All of that is real and documented. The question is what it means for someone choosing a VPN, and the honest answer is: less than the marketing suggests.

What jurisdiction genuinely determines

What a provider can be compelled to produce. A court in the country where a company is established can order it to hand over what it holds.

Whether it can be compelled to start collecting. Some jurisdictions permit orders requiring a provider to begin retaining data it does not currently keep. This is a more significant power than the first one and it varies widely.

Whether it can be gagged. Whether an order can prohibit telling anyone.

Which data protection law applies. An EU establishment brings GDPR obligations, which are meaningful and enforceable.

Why the alliance framing is weak

It is not a list of the only countries that cooperate. Intelligence sharing and mutual legal assistance exist far beyond these groupings. Choosing a provider in a non-member country does not put it outside international cooperation; it puts it outside one named arrangement.

Signals intelligence is not the same as compelling a company. The alliances are about sharing intercepted communications between states. That is a different mechanism from serving a court order on a business, and the two are frequently conflated in provider marketing.

Some "privacy-friendly" jurisdictions are worse. A country with no data protection law, weak judicial oversight and a government that can lean on a local company informally is not obviously safer than a country with GDPR and functioning courts. It is merely less legible.

Server location and company location are different. A provider established in one country running servers in fourteen is subject to its home jurisdiction for the company and to local law for each server.

What matters more, in order

  1. What the provider retains. A provider with no browsing history cannot produce browsing history in any jurisdiction.
  2. Whether that has been verified. A published policy, ideally an audit.
  3. Who operates the servers. Rented hardware means a hosting company with its own records, wherever it sits.
  4. What the provider does with account and payment data. Often the most identifying information it holds.
  5. Then jurisdiction, which shapes what any of the above can be turned into.

Putting jurisdiction fifth is not dismissing it. It is observing that the first four determine whether there is anything for jurisdiction to act on.

Server location and what it changes for you

Picking a server country changes three things, none of which is about the Eyes alliances: how far your packets travel, which country's law governs traffic leaving that server, and what the local network environment does — filtering, blocking, retention requirements on local operators.

Those are practical considerations with real effects, and the server list covers them per country. A German exit is subject to German law; that is a fact about your traffic, not about a treaty.

Where VPNmine sits

VPNmine operates servers in dozens of countries, several of them in Fourteen Eyes member states, because that is where the network capacity and the users are. The argument for that being acceptable is not that the alliances are harmless — it is that the privacy policy states what is recorded, which is which server a session used and when, and that a jurisdiction can only compel production of what exists.

Anyone who considers jurisdiction the deciding factor should weigh that differently, and should say so. It is a legitimate position; it is just not the only one, and the industry's habit of treating a country list as a security rating obscures more than it explains.

A reasonable way to think about it

Jurisdiction is a modifier on a risk, not the risk itself. Start with what is retained, then ask what the law where the provider sits could do about it. In that order the question becomes tractable. In the reverse order it becomes a map with countries coloured in, which looks informative and decides very little.

Sources

  1. UKUSA Agreement — declassified documents, NSA
  2. EU Court of Justice — Schrems II judgment
  3. GDPR Chapter V — transfers to third countries

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine