Skip to content
VPNmine
PRIVACY AND LAW

GDPR and VPN logging

Under GDPR an IP address is personal data, so a VPN that stores connection records is processing it and needs a lawful basis, a stated purpose and a retention period. Users get rights of access, erasure and portability over whatever the provider actually holds.

4 min read

Illustration of a set of scales and a text document, joined by a dashed tunnel line on a dark grid.

The starting point is a 2016 Court of Justice decision, Breyer v Germany, which held that a dynamic IP address is personal data for a website operator where the operator has a legal route to identifying the subscriber behind it.

That settles the question for VPNs. A provider storing connection records is processing personal data, and GDPR applies to how it does so.

What GDPR requires of a provider

A lawful basis. Usually legitimate interests for abuse handling and network security, or contractual necessity for delivering the service. Consent is a poor fit, because a service cannot function if the user withdraws consent to the processing it depends on.

Purpose limitation. Data collected for abuse handling cannot be repurposed for advertising. This is the provision that makes selling browsing data unlawful, not merely distasteful, for anyone within scope.

Data minimisation. Only what is necessary for the stated purpose. A provider that keeps the source address for a year needs to explain why abuse handling required a year.

Storage limitation. A defined retention period, actually enforced. "As long as necessary" is not a period.

Security. Article 32 requires appropriate technical measures, which is where encryption at rest and access control live.

Transparency. The privacy notice must state what is collected, why, for how long, on what basis and who receives it — in plain language.

Your rights over what is held

Access (Article 15). You can ask what is held about you and receive a copy. For a VPN, that should reveal exactly what the retention policy claims. It is the most direct way to test a no-logs claim available to an ordinary user.

Erasure (Article 17). You can ask for deletion, subject to exceptions where the provider has an overriding legal obligation.

Portability (Article 20). Your data in a machine-readable format.

Objection (Article 21). You can object to processing based on legitimate interests, and the provider must weigh your objection against its interest.

Making a subject access request is worth doing once with any provider you rely on. The response, and how it compares with the published policy, tells you more than any amount of marketing.

Who is actually in scope

GDPR applies to providers established in the EU, and to providers outside it that offer services to people in the EU. That second limb is broad and catches most international consumer VPNs.

Whether a given regulator would pursue an operator with no European presence is a different question, and enforcement against small offshore providers is limited in practice. The obligation exists regardless of whether it is enforced.

Where GDPR and no-logs actually meet

GDPR does not require a provider to keep nothing, and it does not prohibit retaining connection metadata for a stated, proportionate purpose. What it does is make vagueness a compliance problem.

A provider claiming to keep nothing, whose privacy notice reserves broad rights to process data for unspecified purposes, has a contradiction on its own site. A provider stating precisely what is kept and for how long is both more useful to users and more defensible.

That is why specificity is the signal worth looking for. VPNmine's privacy policy lists what is recorded — which server a session used and when — and what is never collected, and the terms name the operator, which is what makes any of the rights above exercisable against someone.

The retention laws that pull the other way

Some jurisdictions require providers to retain data that data protection law would otherwise limit. India's 2022 CERT-In direction is the prominent recent example, requiring five years of subscriber records.

Where those obligations bind, they override a provider's preference. The usual industry response has been to withdraw physical infrastructure from the jurisdiction rather than comply, which is a legitimate answer and one worth noticing when a provider claims coverage in a country where it operates no hardware.

What to do with this

Read the privacy notice for a retention period and a purpose. If either is missing, that is a GDPR deficiency and a practical warning at the same time. Then, if it matters, make a subject access request and compare what comes back with what was promised.

Sources

  1. GDPR Article 5 — principles relating to processing
  2. GDPR Article 6 — lawfulness of processing
  3. GDPR Article 15 — right of access
  4. EU Court of Justice — Breyer v Germany (C-582/14)

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine