VPN Laws in the United States: Net Neutrality, the FCC, and What's Actually Regulated

There is no federal "VPN law" in the US — but net neutrality, which has flipped on and off multiple times in the past decade, is the regulatory question that actually touches how your VPN connection gets treated on the wire.

Quick answer

Yes, VPNs are legal in the United States — there is no federal or state law that bans VPN software, and the FCC does not license, approve, or directly regulate VPN services at all. What the FCC does regulate is net neutrality, and that status has changed several times: federal net neutrality rules were repealed in 2017, briefly restored by the FCC in 2024, and then struck down again by a federal appeals court in January 2025, so there is currently no federal rule barring an ISP from throttling or blocking traffic types — including VPN traffic — though a handful of states have their own net neutrality laws that still apply. None of this changes the fact that a VPN doesn't make an otherwise illegal act legal; it only affects the network layer, not what you do on top of it.

Are VPNs legal in the US?

Yes, unambiguously. There is no federal statute, FCC rule, or state law in the United States that prohibits an individual or a business from installing, running, or using VPN software. This puts the US in a very different category from the small number of countries that license, restrict, or ban VPN use outright — using a VPN to browse the internet, work remotely, protect a connection on public Wi-Fi, or access your own accounts while traveling is a completely ordinary and legal activity anywhere in the US, whether you're a citizen, a resident, or a visitor.

That said, "VPNs are legal" is a narrower statement than it sometimes gets treated as online. Legal, in this context, means the tool itself isn't restricted — it says nothing about whether a specific thing you do while connected to one is legal. Torrenting a copyrighted movie, breaking into an account you don't have authorization to access, or committing fraud are all still illegal whether or not a VPN is involved, and a VPN doesn't function as a legal shield for any of that. The rest of this guide separates those two questions carefully: what US law and regulation actually says about the VPN tool itself, and what it says about specific activities people sometimes associate with VPN use.

Does the FCC regulate VPNs?

No — and this is one of the most common points of confusion in this topic. The Federal Communications Commission regulates telecommunications carriers, broadcasters, and, depending on how broadband is classified at a given moment, internet service providers. It does not license VPN companies, does not approve or reject VPN apps, and has no rule on its books that mentions VPN services as a regulated category at all. A VPN provider operating in or serving customers in the US doesn't need FCC approval to exist, and nothing about the FCC's regulatory structure treats a VPN app the way it treats, say, a radio broadcaster's license or a phone carrier's spectrum allocation.

Where the FCC becomes relevant to the VPN conversation isn't VPNs directly — it's what the FCC does or doesn't require of the internet service providers whose networks your VPN traffic travels over before it ever reaches the VPN server. That's the net neutrality question, and it's genuinely the one piece of US regulation that has a real, if indirect, bearing on the VPN experience. The rest of this guide spends most of its length on that question specifically, because it's the one part of "VPN laws in the US" that's actually a live, contested, and frequently changing area of federal policy — unlike VPN legality itself, which has never seriously been in dispute.

What does the FCC's jurisdiction actually cover?

The FCC's authority comes from the Communications Act of 1934 as amended, most significantly by the Telecommunications Act of 1996, and it's organized around different "titles" of that law that carry different regulatory weight. Title II covers common carrier telecommunications services — historically, traditional telephone service — and gives the FCC fairly strong authority to regulate things like pricing, access, and nondiscrimination. Title I covers "information services," a lighter-touch category with much less FCC authority attached. Whether broadband internet access is classified under Title I or Title II has been the single biggest fight in US internet regulation for the past two decades, and it's the classification question that determines whether the FCC has the legal authority to impose net neutrality rules on ISPs at all. VPN services themselves have never been proposed for classification under either title by the FCC — they simply aren't the kind of service the agency's authority is built around.

What is net neutrality, and how does it relate to VPNs?

Net neutrality is the principle that an internet service provider should treat all lawful internet traffic roughly the same — it shouldn't block access to a competitor's service, slow down (throttle) specific types of traffic it doesn't like, or charge some companies extra for a "fast lane" to prioritize their content over everyone else's. As a regulatory matter, net neutrality in the US has specifically meant FCC rules that would prohibit ISPs from doing exactly those three things: blocking, throttling, and paid prioritization.

The connection to VPNs is straightforward once you see it: net neutrality rules, when they're in force, apply to all lawful internet traffic — and VPN traffic is lawful traffic. A rule against throttling means an ISP can't legally single out VPN traffic for slower speeds just because it's VPN traffic. Without that rule in place, an ISP is not legally barred from doing so, even though there's no widespread documented pattern of major US residential ISPs actually throttling VPN connections specifically. The practical risk to an individual VPN user has, in practice, stayed low regardless of which way the net neutrality rules have swung — but the legal backstop against that risk has genuinely gone on and off multiple times, and understanding why requires walking through the actual history rather than trusting a single headline from any one year.

What did the original 2015 net neutrality rules actually do?

In 2015, the FCC — then under Chairman Tom Wheeler — voted to reclassify broadband internet access as a Title II telecommunications service and, using that authority, adopted what's usually called the Open Internet Order. It established bright-line rules against blocking lawful content, throttling lawful traffic, and paid prioritization, plus a general conduct standard against practices that unreasonably interfered with users' or content providers' access to the open internet. This was, at the time, the strongest federal net neutrality protection the US had ever had, and a federal appeals court upheld the FCC's authority to adopt it the following year. For VPN users specifically, these rules meant an ISP throttling VPN traffic categorically would have been a clear violation, not just a hypothetical bad look.

What happened when those rules were repealed in 2017?

Under a new FCC majority — chaired by Ajit Pai — the agency voted at the end of 2017 to reverse course entirely. The Restoring Internet Freedom Order reclassified broadband back to a lightly regulated Title I information service and eliminated the 2015 conduct rules, taking effect in 2018. The FCC's stated rationale centered on encouraging broadband investment and rolling back what it characterized as unnecessary regulation; critics argued it removed a meaningful protection against ISPs favoring their own content or services. The order also attempted to preempt individual states from writing their own net neutrality laws to fill the gap — a piece of the order that didn't survive legal challenge intact, which is why the state-law landscape covered further down in this guide exists at all.

Did net neutrality rules come back in 2024?

Yes, briefly. After years without a working FCC majority to act on the issue, the agency — by then chaired by Jessica Rosenworcel, with a full complement of commissioners in place for the first time in years — voted in the spring of 2024 to restore federal net neutrality protections, again by reclassifying broadband under Title II. Commonly referred to as the Safeguarding and Securing the Open Internet Order, it reinstated the same basic no-blocking, no-throttling, no-paid-prioritization framework as the 2015 rules and took effect in mid-2024. For a period of several months in 2024 into early 2025, the US once again had enforceable federal net neutrality rules on the books.

What happened to the 2024 rules?

They were struck down. Broadband industry groups challenged the 2024 order in federal court almost immediately, and in January 2025 a federal appeals court vacated the FCC's reclassification, ruling that the agency lacked the statutory authority to classify broadband as a Title II telecommunications service. The decision leaned on the "major questions doctrine" — the idea that an agency needs unambiguous congressional authorization for decisions of major economic and political significance — and came in the wake of a separate Supreme Court decision that had recently narrowed how much deference courts give federal agencies when interpreting ambiguous statutes. The practical effect was to unwind the 2024 order and put broadband's classification back to Title I, the same lightly regulated status the 2017 repeal had established. As of this writing, that's where things stand: no enforceable federal net neutrality rule is currently in effect, following a fourth major swing on this exact question in about a decade. Net neutrality remains a live legislative and regulatory topic in Washington, and given how many times the classification question has already flipped, treat any specific status described here — including this guide's — as a snapshot rather than a permanent fact, and check current reporting if the answer matters for something time-sensitive you're doing.

Without federal net neutrality rules, can my ISP throttle or block VPN traffic?

In the current absence of federal net neutrality rules, there's no FCC-enforced prohibition specifically barring an ISP from throttling VPN traffic categorically, the way there was under the 2015 and 2024 rules. That's a real gap compared to when those rules were in force. It's worth separating that legal fact from the practical, observed reality, though: there isn't a documented pattern of major US residential or mobile ISPs broadly throttling or blocking general-purpose VPN traffic for ordinary customers, with or without net neutrality rules in place, because doing so would be a fairly aggressive and customer-hostile move that a major ISP has commercial reasons to avoid even absent a specific legal prohibition. The more commonly reported instances of VPN traffic being blocked or degraded in the US tend to involve narrower contexts — a specific hotel, airport, or public Wi-Fi network's captive portal blocking VPN ports as a matter of local network policy, or a workplace network doing the same — rather than a residential ISP blanket-throttling VPN traffic for its own subscribers.

It's also worth noting that even without Title II-based net neutrality rules, ISPs aren't entirely unregulated. The Federal Trade Commission retains general authority to act against unfair or deceptive business practices, and an ISP's own terms of service and any transparency disclosures it publishes about network management practices remain enforceable in that sense — an ISP that says it won't throttle certain traffic and then secretly does so could face a different kind of legal exposure than a straightforward net-neutrality violation, just under a different agency's authority. None of that adds up to the same bright-line protection the FCC's net neutrality rules provided when they were active, but it's not a total regulatory vacuum either.

Can my ISP see and sell my browsing activity, and does a VPN change that?

This is a separate regulatory thread from net neutrality, but it's closely related and comes up in the same conversations for good reason. In 2016, the same FCC that adopted the original net neutrality rules also adopted a separate broadband privacy rule that would have required ISPs to get opt-in customer consent before using or selling sensitive categories of browsing and app-usage data for advertising purposes. That rule never actually took effect: in early 2017, Congress used its authority under the Congressional Review Act to overturn it before it went into force, and — notably — a Congressional Review Act repeal also bars the agency from adopting a substantially similar rule again without new legislation, which is part of why this specific privacy gap has stayed a gap for years rather than being revisited administratively. The practical result is that there is no dedicated federal rule requiring your ISP to get your opt-in consent before using your browsing history commercially, in the way the 2016 rule would have required.

This is precisely the kind of regulatory gap a VPN is actually well-suited to address on a technical level, independent of whatever the law does or doesn't require: because a VPN encrypts your traffic between your device and the VPN server, your ISP can generally see that you're connected to a VPN server, but not the specific sites and services you're visiting through that tunnel — which meaningfully limits what browsing-pattern data your ISP has available to log, use, or sell in the first place, regardless of what the current regulatory rules around that data say. Some states have moved to fill part of this gap with their own consumer privacy laws that apply more broadly to businesses handling personal data, including, depending on the state's specific law, internet service providers — but coverage varies considerably by state and by the specifics of each law, so this isn't a uniform national protection either.

Do any US states have their own net neutrality laws?

Yes, and this is directly a consequence of how the 2017 repeal played out in court. The 2017 order tried to preempt states from adopting their own net neutrality rules, but that preemption attempt was substantially undercut by a federal appeals court ruling in 2019, which upheld the FCC's underlying repeal but rejected the blanket claim that states couldn't legislate in the space themselves. That opened the door for individual states to pass their own laws, and several did. California enacted one of the more comprehensive state-level net neutrality laws, closely mirroring the federal blocking/throttling/paid-prioritization framework; Washington state passed its own net neutrality statute around the same period; and a number of other states have adopted narrower approaches, commonly requiring that ISPs holding state government contracts comply with net neutrality principles as a condition of doing business with the state, rather than a blanket statewide mandate covering every ISP and every customer.

The upshot is that net neutrality protection in the US is currently patchier and more state-dependent than it was when the federal rules were in force, which is an unusual state of affairs for an issue that's fundamentally about how internet traffic crosses state and national lines. If you live in a state with its own net neutrality law, some of the protection that used to come from the FCC nationally may still apply to you locally — but that's a state-by-state legal question, not something a general guide like this one can answer for your specific state with certainty, and state laws in this area have also faced their own litigation over the years.

Is it illegal to use a VPN to access streaming content that isn't available in your region?

Using a VPN to make a streaming service think you're connecting from a different location is not, on its own, a criminal offense under US law. What it typically is, however, is a violation of that streaming service's terms of service — which is a contract matter between you and the service, not a matter of criminal or even most civil law. In practice, the consequence a streaming service can impose for this is usually limited to technical countermeasures (detecting and blocking known VPN server IP addresses) or, in a worst case, account suspension for a clear terms-of-service breach — not a lawsuit against an individual subscriber, which streaming platforms have not made a practice of pursuing over simple VPN-based region-shifting.

It's worth being precise about why this distinction matters: content licensing agreements are themselves genuinely complicated, and the geographic restrictions streaming platforms enforce usually exist because of licensing deals the platform has made with rights holders in different countries, not because of any US law requiring geographic content restriction. Circumventing that licensing structure with a VPN puts you at odds with the platform's contract terms with you, not with a criminal statute. That's a meaningfully different kind of risk than the sort covered later in this guide around copyright infringement, and conflating the two — "using a VPN to watch a show" versus "using a VPN while illegally downloading a show" — is one of the more common sources of confusion in this general topic area.

Does using a VPN protect you from liability for copyright infringement?

No, and this is worth being direct about. A VPN masks your IP address from the party on the other end of a connection, which in the context of torrenting means the other people in a torrent swarm — and by extension, the copyright holders or their monitoring firms who scan those swarms for infringing activity — typically see the VPN server's IP address rather than your home connection's IP address. That's a genuine practical effect: it makes the specific enforcement mechanism many copyright holders have relied on (identifying an infringing IP address, then subpoenaing the associated ISP for the subscriber's identity) much harder to execute against you directly. But that's a statement about detection difficulty, not about legality. Downloading or distributing copyrighted material without authorization remains a violation of US copyright law regardless of whether a VPN is involved, and the law doesn't carve out an exception for infringement that happens to be harder to trace.

It's also worth understanding that copyright infringement enforcement against individuals in the US has mostly played out as civil litigation — rights holders suing for damages — rather than as criminal prosecution, which is generally reserved for large-scale, commercial-grade infringement. A VPN reducing your odds of being identified for a civil lawsuit is a real practical effect people do factor into their decisions, but it's a description of risk exposure, not a legal opinion that the underlying activity is fine. If avoiding copyright liability is the actual goal, the durable way to do that is not infringing in the first place — a VPN is not a substitute for that, whatever role it plays in the surrounding risk calculation.

Can VPN use run afoul of the Computer Fraud and Abuse Act?

The Computer Fraud and Abuse Act (CFAA) is the main federal law criminalizing unauthorized access to computer systems, and it comes up in VPN discussions because of a specific, genuinely important Supreme Court decision from 2021. Before that ruling, there was real legal uncertainty about whether merely violating a website's terms of service — including, potentially, using a VPN to access content or pricing meant for another region, in violation of a site's terms — could be charged as "exceeding authorized access" under the CFAA, a federal crime. The Supreme Court's decision substantially narrowed that reading, holding that exceeding authorized access under the CFAA requires bypassing an actual technical access restriction — a specific file, folder, or database you weren't permitted into — rather than simply misusing access you otherwise validly have in a way that breaks a site's stated rules.

What that means practically for VPN use is reassuring, though not an absolute guarantee: using a VPN to access a publicly available website or service from a different apparent location, in a way that merely violates that service's terms of service, is not the kind of "unauthorized access" the CFAA was interpreted to criminalize after that ruling. The CFAA remains a serious statute for what it was actually designed for — genuinely breaking into systems, accounts, or data you have no legitimate access to at all, VPN or not — and using a VPN doesn't provide any special protection if that's what's actually happening. But the specific fear some people have — that using a VPN to get around a geographic restriction could itself be a federal computer crime — reflects an older and now largely superseded reading of the law, not the current one.

Are there restrictions on VPN use on government or work networks?

Yes, but these are policy restrictions set by individual employers and agencies, not restrictions created by any general law. It's common for federal, state, and local government agencies to restrict what software — including consumer VPN apps — can be installed on government-issued devices, and to filter or block certain VPN traffic on government networks, for information-security reasons specific to that agency's own risk posture. Private employers frequently do the same thing on company-owned devices and corporate networks, sometimes requiring the use of an approved corporate VPN instead of, or in addition to, blocking third-party consumer VPN apps entirely. None of this reflects a US law about VPNs generally; it reflects the same kind of acceptable-use policy that governs what other software you can or can't install on a work laptop, and violating it is an employment or contractual matter between you and that employer or agency, not a criminal one.

If you're a government employee, a federal contractor, or work somewhere with a security-conscious IT department, the actual rule that applies to you is whatever your organization's specific acceptable-use policy says — which can be considerably more restrictive than what general US law requires — and that policy is the one worth reading directly rather than inferring from a guide like this one.

Do VPN providers have to keep logs or hand over user data to US authorities?

There's no general US law that requires a VPN provider — whether based in the US or elsewhere — to retain logs of user activity by default. What does exist is the standard legal-process apparatus that applies to companies more broadly: US courts can issue subpoenas, warrants, or other legal orders compelling a company subject to US jurisdiction to produce data it actually possesses. The operative phrase there is "data it actually possesses" — a provider that genuinely doesn't log connection activity or browsing data in the first place has nothing to hand over in response to that kind of order, regardless of where it's headquartered, which is the core logic behind why a provider's actual logging practices matter more than almost anything else when you're evaluating it for privacy. This site's individual provider reviews link out to each provider's own privacy policy for exactly this reason — read the actual policy rather than relying on marketing language, including ours.

A provider's jurisdiction affects which country's legal process it's subject to and what those legal mechanisms look like procedurally, but jurisdiction is a secondary factor compared to whether the provider has data to produce in the first place. A strong no-logs practice, ideally backed by an independent audit with a specific, dated scope you can actually read, matters more than jurisdiction alone in most realistic scenarios — jurisdiction and logging policy work together, not as substitutes for each other.

What about national security-related legal process specifically?

US law does include mechanisms — national security letters and certain classified court orders among them — that can come with restrictions on disclosing that the order was even received, sometimes called gag provisions. These are a real feature of the US legal landscape and are one of the reasons some privacy-focused users weight jurisdiction as a meaningful factor, preferring providers based outside the US specifically to avoid this category of legal process altogether. Whether that consideration matters for you depends on your own threat model — for the overwhelming majority of ordinary VPN use cases, this kind of national security legal process isn't a realistic concern — but it's a legitimate reason some people specifically look at where a provider is legally headquartered rather than treating it as a minor detail.

Is VPN encryption itself restricted or regulated in the US?

No, not domestically. There was a period, mostly through the 1990s, when strong encryption was treated under US export law as a controlled munition, requiring a government license to export outside the country — a policy that produced significant legal and political fights, including litigation on First Amendment grounds over restricting the publication of cryptographic source code. Those export controls were substantially relaxed starting in the late 1990s and further loosened in the years after, and today, using strong encryption domestically — which is what a VPN's encrypted tunnel fundamentally is — carries no special legal restriction for ordinary civilian use in the US. There have been recurring policy debates in Washington over whether companies should be required to build law-enforcement backdoors into encrypted products and services, but those debates have targeted company-level product design requirements, not individual consumers' right to use encryption tools like a VPN, and none of those proposals has become a law banning or restricting individual VPN or encryption use in the US.

Does using a VPN attract law enforcement attention by itself?

No. VPN use is common, mainstream, and legal, and law enforcement in the US does not treat the mere fact of VPN use as suspicious on its own — millions of Americans use one daily for entirely ordinary reasons: securing a connection on public Wi-Fi, working remotely, or simply not wanting an ISP logging every site they visit. What draws law enforcement attention is underlying illegal activity, not the presence of a VPN wrapped around it; using a VPN while doing something illegal doesn't make the activity more suspicious than it already was, and using one while doing something entirely legal doesn't create suspicion out of nothing. If anything, VPN use is common enough in the US at this point — for remote work alone, given how many employers require one to reach internal systems — that treating it as inherently notable would be a misunderstanding of how ordinary the tool has become.

What should a business know about VPN use and US regulatory compliance?

For a business, the more relevant regulatory questions usually aren't about VPN legality at all — that's settled — but about how VPN use interacts with industry-specific compliance obligations the business already has. A healthcare organization subject to HIPAA, a financial services firm subject to relevant financial-privacy regulations, or any company handling regulated categories of data needs to evaluate a VPN as one part of its broader security and compliance posture, not as a standalone legal question. That typically means looking at things like whether the VPN vendor will sign a business associate agreement where one is required, how the vendor's own data-handling practices align with the business's compliance obligations, and whether a business-grade product with centralized administration and audit logging is a better fit than consumer VPN apps installed ad hoc by individual employees.

None of this stems from any VPN-specific law — it's the general principle that regulated industries need to evaluate any third-party tool that touches their data through the lens of their existing compliance framework, and a VPN is no exception to that. A business with genuine regulatory exposure in this area should work through it with its own compliance and legal counsel rather than inferring requirements from a consumer-facing guide like this one.

How does the US approach compare to countries that actually restrict VPNs?

It's worth putting the US situation in context, because "VPN laws" as a search topic often gets discussed as if every country handles it similarly, when the range is actually wide. Some countries maintain explicit licensing regimes for VPN services or outright restrict personal VPN use through specific legal provisions — our guide to VPN laws in China covers one heavily documented example, and our guides on VPN legality in the UAE and India cover others with their own distinct legal frameworks. The US sits at the opposite end of that spectrum: no VPN-specific statute exists at all, at the federal or state level, and the closest thing to an actual regulatory fight in this space — net neutrality — is about how ISPs are allowed to treat internet traffic generally, not about VPNs as a named, regulated category. If you're comparing VPN legality across countries for travel or relocation purposes, treat each country as its own question with its own current legal framework, rather than assuming a country's rules mirror what you're used to — the US's essentially unrestricted approach is common among Western democracies but is far from universal.

Practical takeaway: what does all this mean for you?

If you're in the US and wondering whether it's legal to use a VPN, the answer is a straightforward yes, with no meaningful asterisk attached to the tool itself — no license, registration, or approval is required, and no federal or state law restricts ordinary VPN use. The genuinely unsettled part of "VPN laws in the US" isn't about VPNs directly; it's net neutrality, which determines whether your ISP is under a legal obligation not to throttle or block traffic types including VPN traffic, and that status has changed four times in a decade and currently sits, following the January 2025 court ruling, without an enforceable federal rule in place — though a handful of states have their own laws that may still apply where you live. Beyond that, the specific activities that carry real legal risk — copyright infringement, unauthorized access to systems you're not entitled to, fraud — carry that same risk with or without a VPN in the picture; a VPN changes what's visible on the network, not what's legal to do on top of it. For most people, the practical questions worth spending time on are less about legality and more about which provider's actual privacy practices and jurisdiction you're comfortable trusting, since that — not any US law — is what determines how meaningfully a VPN protects you in practice.

Frequently asked questions

Are VPNs legal in the US?

Yes. There is no federal or state law in the United States that bans or restricts VPN software, and the FCC does not license or directly regulate VPN services. Using a VPN for privacy, security, remote work, or general browsing is completely legal for individuals and businesses alike.

Does the FCC regulate VPN companies?

No. The FCC regulates telecommunications carriers and, depending on current classification, broadband internet service providers — it has no rule that treats VPN services as a licensed or regulated category. The FCC-related issue that actually affects VPN users indirectly is net neutrality, which governs how ISPs are allowed to treat internet traffic generally, VPN traffic included.

Is net neutrality currently in effect in the US?

Not at the federal level, as of this writing. Federal net neutrality rules were repealed in 2017, briefly restored by the FCC in 2024, and then struck down by a federal appeals court in January 2025, which found the FCC lacked authority to reclassify broadband as a Title II service. Some states have their own net neutrality laws that may still apply locally. This is an actively litigated area, so treat the current status as a snapshot rather than a permanent fact.

Can my internet provider throttle or block VPN traffic in the US?

Without an enforceable federal net neutrality rule currently in place, there's no FCC prohibition specifically barring an ISP from throttling VPN traffic categorically. In practice, there's no documented pattern of major US residential ISPs broadly throttling general VPN use, and other legal mechanisms — like FTC authority over unfair or deceptive practices — still apply in a more limited way.

Does a VPN make torrenting or copyright infringement legal?

No. A VPN masks your IP address from other parties in a torrent swarm, which makes a common enforcement mechanism harder to use against you, but it doesn't change the underlying legality. Downloading or distributing copyrighted material without authorization remains a violation of US copyright law with or without a VPN.

Can using a VPN to bypass a website's region restriction get you charged under the CFAA?

Generally, no, under the current legal standard. A 2021 Supreme Court decision narrowed the Computer Fraud and Abuse Act's "exceeds authorized access" language to require bypassing an actual technical restriction, not merely violating a site's terms of service. Using a VPN to access a publicly available service from a different location, in violation of its terms, is a contract issue with that service, not the kind of unauthorized access the CFAA was interpreted to criminalize.