European Data Retention Laws and Why They Matter for VPN Users

There is no single EU data retention law anymore — there's a shifting patchwork of national rules, four major court rulings, and a lot of confusion about who those rules actually bind. Here's what a data retention law and VPN use really have to do with each other.

Quick answer

The EU no longer has a single, unified data retention law — its 2006 Data Retention Directive was struck down by the EU's top court in 2014, and follow-up rulings in 2016, 2020, and 2022 narrowed things further, so today each member state runs its own version, and some have very little enforceable general retention left at all. Those laws, where they exist, are aimed at telecom and internet access providers — the companies that connect you to the internet in the first place — not at VPN apps layered on top of that connection, though the line isn't drawn identically in every country. A VPN doesn't make data retention law stop applying to your internet connection; it changes what your ISP can see and log, shifting the more meaningful visibility to the VPN provider itself, which is why that provider's own logging policy and jurisdiction matter at least as much as which EU country you're sitting in.

What does "data retention law" actually mean?

"Data retention" has a specific, narrower meaning in EU law than the phrase suggests at first read. A data retention law does not require anyone to intercept or store the content of your calls, messages, or browsing — that would run into a much larger set of legal protections around the confidentiality of communications. Instead, it requires specific categories of providers, historically telecom operators and internet service providers, to retain metadata: records of who communicated with whom, when, for how long, from what location or IP address, and using which device — without necessarily recording what was actually said or which web pages were viewed.

That distinction matters because metadata is often more revealing in aggregate than a single piece of content. A retained log showing that a particular IP address connected to a specific server at a specific time, repeated across months, can reconstruct a detailed picture of someone's associations, movements, and habits even without a single word of actual communication being stored. That's precisely the concern that has driven a decade of litigation over whether, and how, a data retention law can be squared with the EU's own fundamental rights framework.

It's also worth being clear up front that "data retention law" and "data protection law" pull in opposite directions, even though they sound similar and are frequently confused. Data protection law, chiefly the GDPR, generally pushes organizations toward collecting and keeping less personal data, for a shorter time, for a clearly defined purpose. A data retention law does the opposite: it compels a defined set of providers to keep specific data for a mandated minimum period, for law-enforcement and national-security purposes, whether or not the provider would otherwise want or need to keep it. Understanding that tension is the key to understanding why this area of EU law has been fought over in court so persistently.

Did the EU used to have one single data retention law for every member state?

Yes, briefly. The Data Retention Directive (2006/24/EC), adopted in 2006 in the aftermath of the Madrid and London terrorist attacks, required telecom operators and internet service providers across the EU to retain traffic and location data — records of calls, emails, and internet access, though not the content of those communications — for a period set by each member state within a range of six months to two years. The stated purpose was to make that data available to law enforcement for the investigation, detection, and prosecution of serious crime.

Because it was a Directive rather than a Regulation, it didn't apply automatically and uniformly the way EU Regulations do — each member state had to transpose it into its own national law, which is part of why the retention periods, the exact categories of data covered, and the safeguards attached to accessing that data varied somewhat from one country to the next even while the Directive was in force. That national-transposition structure turned out to matter a great deal once the Directive itself was struck down, because plenty of national laws implementing it didn't automatically disappear along with it.

What happened to that directive — is it still in force?

No. The Data Retention Directive was invalidated by the Court of Justice of the European Union (CJEU) in April 2014, in the joined cases known as Digital Rights Ireland. The Court found that requiring the blanket, indiscriminate retention of traffic and location data for the entire population — regardless of whether any individual was even remotely suspected of involvement in serious crime — interfered disproportionately with the rights to respect for private life and to the protection of personal data guaranteed under the EU Charter of Fundamental Rights. The ruling didn't say that no data retention could ever be lawful; it said that this particular, undifferentiated, EU-wide approach went further than necessary and lacked adequate safeguards around access to the retained data.

What the ruling did not do, and this is where a lot of the confusion around "is data retention law dead in the EU" comes from, is automatically repeal every national law that had been enacted to implement the now-invalid Directive. Those national laws remained on the books in a number of member states, some of them continued to be enforced, and it took a further series of court cases — at both the EU and national level — to work out what, if anything, could replace the old EU-wide approach.

Did member states just stop retaining data after 2014?

Not uniformly, and this is the part of the story that keeps this area of law genuinely unsettled more than a decade later. Digital Rights Ireland struck down the EU Directive, but a number of member states kept their own national retention laws in force, arguing that national law derives its own authority from national legislatures even if the EU-level instrument that originally prompted it is gone. That set up a second round of litigation, this time challenging individual national laws directly rather than the EU framework as a whole, and the CJEU has been asked to weigh in repeatedly since.

The result has been less a single clean answer and more an ongoing back-and-forth between national legislatures trying to keep some form of retention regime in place and the CJEU repeatedly narrowing how far they're allowed to go. That back-and-forth is still active as of this writing, and it's exactly why anyone asking "does my country have a data retention law" needs a country-specific, current answer rather than a general EU-wide one — the legal status genuinely differs by member state and can change with the next ruling.

What did the later rulings — Tele2/Watson and La Quadrature du Net — actually decide?

Two further landmark rulings shaped the current legal landscape considerably. In December 2016, in the joined Tele2 Sverige and Watson cases, the CJEU held that EU law precludes national legislation that provides for the general and indiscriminate retention of all traffic and location data as a blanket rule. Crucially, though, the Court left room for something narrower: targeted retention — limited by category of person, geographic area, or communication method, and tied to the objective of fighting serious crime, with a retention period no longer than strictly necessary — could still be compatible with EU law, subject to proper judicial or independent oversight of access to the data.

Then, in October 2020, the CJEU's ruling in La Quadrature du Net and Others refined the picture further, in a case brought against French and Belgian retention laws. The Court reaffirmed that general and indiscriminate retention of traffic and content-adjacent data is, as a rule, incompatible with EU law, but it carved out a couple of narrower exceptions: general and indiscriminate retention of IP addresses specifically could be justified in the fight against serious crime, and a member state facing a genuine, present, or foreseeable serious threat to national security could order general and indiscriminate retention for a limited period, subject to effective review by a court or independent body.

A follow-up ruling in September 2022, in the joined SpaceNet and Telekom Deutschland cases, applied that framework directly to Germany's own general telecom data retention law and found it incompatible with EU law, since Germany hadn't established the kind of serious, concrete national-security threat the earlier rulings said would be required to justify blanket retention. That's a useful data point because it shows the CJEU has continued applying the same reasoning consistently to individual national laws as they've been challenged, rather than the 2016 and 2020 rulings being one-off exceptions.

So is there one clear, current answer to "what does data retention law require" in the EU?

Honestly, no — and any source telling you there's a single tidy EU-wide answer right now is oversimplifying a genuinely unsettled area of law. What exists today is a patchwork: some member states have replaced general retention with narrower, targeted regimes that attempt to track the CJEU's guidance; some still have broader laws on the books that remain legally vulnerable to challenge and haven't yet been tested in court; and in countries where a national law has been struck down by a domestic constitutional or supreme court following this EU case law, there can be periods where enforceable general retention is minimal or effectively paused pending new legislation.

Because the details — which categories of data, for how long, under what access safeguards — genuinely vary by country and continue to shift as litigation plays out, this guide isn't going to publish a fixed country-by-country table and present it as current fact, since it would likely be out of date by the time you read it. If the specific rules in a specific member state matter for your situation, that's worth checking against that country's current implementing legislation directly, or with a source that tracks it live, rather than any general guide, including this one.

Does this apply to the UK too, or is it different post-Brexit?

The UK is a useful comparison precisely because its trajectory shows how a country can diverge once it's no longer bound by CJEU rulings. The UK's domestic framework, the Investigatory Powers Act 2016, allows the government to issue retention notices compelling telecom and internet providers to retain specified communications data for up to twelve months. While the UK was still an EU member and subject to CJEU jurisdiction, that framework was challenged in a case brought by the civil liberties organization Liberty, and a UK court found parts of it incompatible with the same line of EU case law discussed above — general and indiscriminate retention without sufficiently targeted safeguards — leading to amendments in 2018 that narrowed access to retained data and added independent authorization requirements for many types of request.

Since Brexit, the UK is no longer bound by new CJEU rulings, and its data retention framework now develops independently of the EU line of cases described in this guide, rather than being required to track it going forward. That matters for anyone assuming "UK data retention law" and "EU data retention law" are now the same thing by default — they started from a shared legal ancestry, but they're legally separate systems today, capable of diverging further as each develops on its own track. If a UK-specific answer matters to you, it's worth treating it as its own question rather than assuming whatever applies in an EU member state automatically applies in the UK, or vice versa.

Is a data retention law the same thing as the GDPR?

No, and conflating the two is one of the more common mix-ups in this area. The GDPR (Regulation (EU) 2016/679) is a data protection law: it constrains how organizations that process personal data may collect, use, and store it, and its core principles — data minimization and storage limitation among them — generally push toward collecting less data and keeping it for less time. A data retention law does the structural opposite: it compels certain providers to keep specific categories of data for a mandated minimum period, for law-enforcement and national-security purposes, regardless of what the provider's own data-minimization instincts might otherwise dictate.

The instrument that actually creates room for a national data retention law to exist alongside general EU privacy protections is the separate ePrivacy Directive (2002/58/EC), specifically its Article 15(1), which allows member states to restrict the otherwise-default confidentiality of electronic communications through national legislation, under defined conditions, for purposes including national security, defense, and the prevention, investigation, and prosecution of criminal offenses. It's this specific derogation provision that every one of the CJEU rulings discussed above has been interpreting and narrowing — the case law isn't about the GDPR at all, it's about how far Article 15(1) lets a member state go. If you want the fuller picture of how the GDPR itself applies to VPN providers and users — a related but genuinely separate question — our guide to VPNs and GDPR covers that ground in more depth than this article will.

Do EU data retention laws actually apply to VPN providers?

This is the question most people asking about "data retention law and VPN" actually want answered, and the honest response is: it depends on the country, and it's genuinely not a settled, uniform answer across the EU. The national retention obligations built on Article 15(1) of the ePrivacy Directive were historically aimed at providers of publicly available electronic communications services and public communications networks — in plain terms, telecom carriers and the internet service providers that physically connect a home or business to the internet. A commercial VPN service is a different kind of provider, layered on top of that underlying connection rather than providing it.

Whether a given member state's implementing legislation defines its covered "electronic communications service" broadly enough to sweep in a VPN provider is a matter of that country's own statutory language, and it isn't consistent from one member state to the next. In most EU countries, the retention obligation is squarely aimed at internet access and telecom providers rather than the specific applications or services running on top of an internet connection, which would include a VPN app. But because definitions and their interpretation genuinely differ by country and can change with new legislation, this guide won't claim a single blanket answer applies to a VPN provider incorporated anywhere in the EU — that's a question worth checking against the specific national law of the country a given VPN provider is legally based in, if it matters to you.

What is more consistently true is this: even in member states where a data retention law doesn't reach VPN providers directly, it very likely does reach your internet service provider — the company whose network you're connecting through in the first place, VPN or no VPN. That's the layer where a data retention law and VPN use most reliably intersect, and it's covered in the next section.

Is "data retention" the same thing as police being able to request my data?

No, and this is a distinction worth keeping straight because the two get talked about as if they're interchangeable. A data retention law is about standing, ongoing storage — a provider is required to keep certain records for everyone, by default, for a set period, whether or not any specific investigation exists yet. That's different from a targeted preservation or production order, where law enforcement, usually with judicial authorization, asks a specific provider to hand over or preserve data tied to a specific account or investigation that's already underway. The Council of Europe's Budapest Convention on Cybercrime, which a number of countries beyond the EU have also signed onto, builds its own cross-border evidence-sharing framework around this kind of targeted "expedited preservation" request rather than mandating blanket retention itself.

Why the distinction matters here: a VPN provider that keeps no logs at all has nothing to hand over in response to either kind of request, retention-law-driven or targeted-order-driven — an empty log is an empty log regardless of which legal mechanism is used to ask for it. But a provider that does keep some connection records, whether because a data retention law requires it or simply because its own systems generate them for operational reasons, can still be compelled to produce whatever it does hold through an individual, targeted legal request even in a country with no general retention mandate at all. "My VPN's jurisdiction has no data retention law" and "my VPN can never be compelled to disclose anything" are not the same claim — the second one depends entirely on what the provider actually logs, not on whether a standing retention law happens to exist where it's based.

Does using a VPN protect me from data retention laws if my ISP is in the EU?

Partially, and it's worth being precise about which part. When you connect to a VPN, your internet service provider can still see that your device established an encrypted connection to a particular server — including the server's IP address, the times you connected and disconnected, and roughly how much data passed through — because that connection itself isn't hidden from the ISP, only its contents are. If your ISP operates under a national data retention law that requires logging connection metadata, that metadata about your VPN connection is exactly the kind of record such a law is built to capture, regardless of what you're doing once the encrypted tunnel is established.

What the VPN does change is what's inside that picture. Your ISP can no longer see which specific websites, services, or servers you're reaching beyond the VPN server itself, because that traffic is encrypted between your device and the VPN provider. So a data retention law that compels your ISP to log connection metadata still produces a record showing "this account connected to a VPN server for this many hours on this date" — it just doesn't produce a record of your actual browsing or destination traffic, because the ISP genuinely can't see that anymore. That's a real, meaningful privacy improvement, but it's a narrower one than "a VPN makes data retention law not apply to me," which overstates what's actually happening.

The flip side of that shift is that the VPN provider itself now occupies the position your ISP used to be in with respect to your destination traffic — which is exactly why the provider's own logging practices, and whatever legal obligations apply to it in its jurisdiction, become the more meaningful question once you're using one. A VPN doesn't remove the question of who can see your traffic; it relocates it.

Does the VPN provider's own jurisdiction actually matter here?

Yes, though it's one factor among several rather than the whole story on its own. A VPN provider legally based outside the EU generally sits outside the reach of EU member states' national data retention laws entirely — those laws bind entities within the legislating country's jurisdiction, and a provider incorporated and operating from elsewhere isn't compelled by them, whatever its own home country's separate legal framework happens to require instead. NordVPN, for instance, is based in Panama, a jurisdiction with no EU-style mandatory data retention regime for VPN providers; you can read more about how that fits into its broader positioning in our NordVPN review.

Proton VPN is based in Switzerland, which is not an EU member state and isn't bound by EU directives or the CJEU rulings discussed in this guide, though Switzerland has its own separate domestic legal framework governing telecommunications surveillance that operates on its own terms rather than simply being "no rules at all." Being outside the EU's specific data retention framework isn't the same claim as being outside every legal framework anywhere, and it's worth not overstating jurisdiction as a single silver-bullet answer. Our Proton VPN review and our broader guide to evaluating a VPN for privacy go into more depth on how jurisdiction fits alongside logging policy and independent audits rather than substituting for them.

The larger point is that jurisdiction tells you which government could theoretically compel a provider to hand over data or start logging — it doesn't, by itself, tell you whether the provider is actually logging anything to begin with. A provider in a retention-friendly jurisdiction that genuinely keeps no logs of your activity has nothing meaningful to hand over even if compelled; a provider in a privacy-friendly jurisdiction that quietly logs more than it advertises is a weaker choice than the jurisdiction alone would suggest. Jurisdiction and logging policy need to be evaluated together, not as substitutes for each other.

What should I actually look for in a VPN, given this legal backdrop?

A few practical, honest priorities follow directly from everything above, rather than a simple "pick a provider in country X" rule:

  • Read what the provider's no-logs policy specifically covers — "no-logs" is a claim about what the provider chooses not to record, which is a separate question from what any data retention law in its home jurisdiction might otherwise require of it. Our breakdown of what "no logs" actually means walks through how to read a logging policy critically rather than taking the headline claim at face value.
  • Check whether the provider's jurisdiction has a data retention law that could apply to it directly, understanding that this varies by country and by how broadly that country's law defines a covered provider, as covered earlier in this guide.
  • Look for independent verification — an audit of a no-logs claim, where one exists and can be pointed to directly, is a stronger signal than an unverified policy statement, though it's a snapshot in time rather than a permanent guarantee.
  • Remember that your ISP is part of this picture too, not just your VPN provider — if your own ISP operates under a national data retention law, it will very likely still log the fact that you connected to a VPN server, even though it can no longer see what you did once connected.
  • Don't treat jurisdiction as a complete answer on its own — pair it with the provider's actual stated logging practices rather than assuming a privacy-friendly country automatically means a privacy-friendly provider.

Providers differ in how they position themselves around exactly these points. Proton VPN's marketing leans heavily on Swiss jurisdiction combined with privacy-first engineering; NordVPN's leans on Panama jurisdiction combined with a broad server network and app ecosystem. Our PureVPN review and FastestVPN review lay out how those two providers position their own jurisdiction and logging claims as well, so you can compare across all four rather than taking any single provider's framing as the full picture.

Does this mean a VPN is pointless if my country has a data retention law?

No — that would be overstating the case in the other direction. Even accepting that your ISP can still log the fact of a VPN connection under a national data retention law, that's a meaningfully narrower record than an ISP being able to log every individual site, service, and destination you reach without a VPN in place. A data retention law that captures "connected to VPN server X for Y hours" is a real reduction in what's recorded compared to a full destination-level browsing log, even though it isn't total invisibility.

What using a VPN under a data retention regime does mean is that you're making a choice about where the more detailed visibility sits — shifting it from an ISP that's subject to your own country's retention law, to a VPN provider that may or may not be subject to any retention law at all, depending on where it's based and what it actually logs. Whether that trade is worth it, and which provider makes the most sense for your specific situation, depends on what you're actually trying to protect against — a question our guide to VPNs and privacy walks through in more general terms beyond the data retention question specifically.

Does a business or corporate VPN work differently under data retention law?

The core legal analysis in this guide is written around consumer-facing VPN services, but it's worth flagging that a company running its own VPN — say, to let staff connect securely into an internal network — sits in a somewhat different position than someone subscribing to a commercial VPN app. A business operating its own VPN infrastructure is generally not itself a "provider of a publicly available electronic communications service" in the sense the ePrivacy Directive and national retention laws are built around, since the service isn't being offered to the public — it's an internal tool for that company's own staff and systems. That distinction is one reason enterprise VPN and consumer VPN questions often get separate legal treatment even within the same country.

What doesn't change for a business running its own VPN is the underlying internet connection each employee or office uses to reach it in the first place — the ISP layer described earlier in this guide is just as present for a corporate VPN user as for a consumer one, and any data retention law binding that ISP applies the same way regardless of whether the VPN on the other end is a commercial service or an internal company system. Employers with specific compliance obligations around this — financial services, healthcare, and other regulated sectors in particular — typically have sector-specific legal guidance that goes well beyond what a general consumer-facing guide like this one is written to cover, and that's worth consulting directly rather than extrapolating from a piece written primarily for individual VPN users.

The bottom line

There is no single, current EU data retention law anymore. The 2006 Data Retention Directive was struck down by the CJEU in 2014, and a series of further rulings in 2016, 2020, and 2022 narrowed how far individual member states can go with their own national retention regimes, leaving a genuine, ongoing patchwork rather than one clean answer. Those national laws, where they exist, are generally aimed at telecom and internet access providers rather than VPN services specifically, though the exact reach differs by country and hasn't been tested uniformly. Using a VPN doesn't make data retention law disappear from your internet connection — your ISP can typically still log the fact and duration of your VPN connection under a retention law that applies to it — but it does meaningfully narrow what gets logged, while shifting the more detailed visibility to your VPN provider. That's why, when weighing a data retention law and VPN use together, the provider's own jurisdiction and its actual, specific logging practices deserve at least as much attention as the general legal status of data retention in your own country.

Frequently asked questions

Does the EU still have a mandatory data retention law?

Not a single, EU-wide one. The original 2006 Data Retention Directive was struck down by the CJEU in 2014, and later rulings in 2016, 2020, and 2022 further narrowed what individual member states can require. Today, retention rules exist as a patchwork of national laws rather than one uniform EU-wide regime, and the details vary by country and continue to shift with ongoing litigation.

Is a data retention law the same thing as the GDPR?

No. The GDPR is a data protection law that generally pushes organizations toward collecting and retaining less personal data. A data retention law does the opposite: it compels specific providers, historically telecoms and ISPs, to keep certain connection metadata for a mandated period, under a separate legal basis found in the ePrivacy Directive rather than the GDPR itself.

Do data retention laws in the EU apply to VPN providers?

It depends on the country, and it isn't a settled, uniform answer. National retention obligations have historically targeted providers of internet access and telecom services rather than VPN apps layered on top of that connection, but exactly which providers count is defined by each member state's own law and isn't identical everywhere.

If I use a VPN, can my ISP still see that I connected to it?

Yes. A VPN encrypts and hides the contents and destination of your traffic, but your ISP can typically still see that your device connected to a VPN server, along with the connection times and approximate data volume. If your ISP operates under a national data retention law, that connection metadata is the kind of record such a law is built to capture.

Does a VPN provider's jurisdiction matter for data retention purposes?

Yes, though it isn't the whole picture on its own. A provider based outside the EU, such as one in Panama or Switzerland, generally sits outside the reach of EU member states' national data retention laws, though it may still be subject to its own home country's separate legal framework. Jurisdiction should be weighed alongside the provider's actual, specific logging practices rather than treated as a complete answer by itself.

Which EU countries currently enforce a data retention law?

This genuinely varies and continues to change as national laws are challenged and revised following the CJEU's rulings, so this guide isn't going to publish a fixed list and present it as current — it would likely be out of date quickly. If a specific country's current rules matter for your situation, check that country's current implementing legislation directly rather than relying on any general guide, including this one.