VPNs and GDPR: What EU Privacy Law Does and Doesn't Cover
GDPR regulates how companies handle your data — it doesn't make a VPN provider trustworthy on its own. Here's the actual relationship between the two.
Quick answer
GDPR is a data-protection law that regulates how companies operating in or serving the EU collect, store, and use personal data — it does not certify a VPN as private, does not require "no-logs," and does not stop a government from compelling data disclosure through lawful legal process. A VPN based in the EU (or handling EU users' data) must comply with GDPR's rules on consent, data minimization, breach notification, and your right to access or delete your data, but compliance is a floor on how a company is allowed to behave, not a guarantee of what it actually logs. Judge a VPN's privacy by reading its actual privacy policy and jurisdiction, not by a "GDPR compliant" badge on its homepage.
What GDPR actually is, in plain terms
The General Data Protection Regulation is an EU law that came into force in 2018. It sets rules for how organizations collect, process, store, and share the personal data of people located in the EU — regardless of where the organization itself is based. If a company processes personal data belonging to someone in the EU, GDPR can apply to that processing even if the company's headquarters, servers, and staff are entirely outside the EU. That's the "extraterritorial" part of the law that often confuses people: a VPN provider incorporated in the British Virgin Islands or Panama can still be subject to GDPR obligations for the EU users it serves.
GDPR is built around a set of principles rather than a single checklist: personal data should be collected for specified, legitimate purposes; only the minimum data needed for that purpose should be collected ("data minimization"); people have rights to access, correct, and delete data held about them; and organizations must be able to demonstrate accountability for how they handle data, including reporting serious breaches within a set timeframe. None of those principles are specific to VPNs — they apply to any company handling personal data, from a supermarket loyalty app to a cloud storage provider to a VPN service.
What GDPR is not is a privacy seal of approval. It doesn't evaluate whether a company's core product is good at protecting your anonymity, and it doesn't audit technical claims like "no-logs." A company can be fully GDPR compliant in how it handles your billing address and support tickets while still logging connection metadata in ways that would surprise a privacy-focused user. Compliance and privacy-by-design are related but not identical.
Does GDPR apply to a VPN provider based outside the EU?
Often yes, at least partially. GDPR's territorial scope (Article 3) applies to processing personal data of people in the EU when that processing relates to offering goods or services to those people, even if the processor has no EU establishment. A VPN provider that markets to EU customers, accepts EU customers' payments, and processes their account data is generally within scope for that portion of its business, whatever its home jurisdiction. That said, enforcement against a company with no EU presence and no EU assets is a genuinely different practical matter than enforcement against a company headquartered in Germany or the Netherlands — a data protection authority's formal jurisdiction and its practical ability to compel compliance are not the same thing.
This is one reason "jurisdiction" comes up so often in VPN privacy discussions, and why it's worth treating as a separate question from "is this company GDPR compliant." A provider's jurisdiction determines which country's courts, intelligence-sharing agreements, and data-retention laws it operates under day to day. GDPR compliance tells you how the company says it handles the data subject to EU law; jurisdiction tells you what legal system actually governs the company and what it can be compelled to produce. Proton VPN, for example, is based in Switzerland — not an EU member state, but a country with its own strong data protection framework and a legal system often cited favorably in privacy discussions; see our Proton VPN review for more on how the company frames its jurisdiction. NordVPN is based in Panama, a jurisdiction outside both EU and typical intelligence-sharing frameworks; see our NordVPN review.
What GDPR requires a VPN provider to actually do
Setting aside marketing language, the concrete obligations GDPR places on a company handling EU users' data include a specific and fairly practical set of things:
A lawful basis for processing
The company needs a legitimate legal basis for each category of data it processes — consent, contractual necessity (you need an account to receive the service you paid for), or legitimate interest, among others. This is why VPN sign-up flows increasingly separate "data we need to provide the service" from "data we'd like for marketing," with the latter requiring an actual opt-in rather than being bundled into the terms of service by default.
Data minimization
The company should only collect what it actually needs for the stated purpose. In principle, this pushes providers toward collecting less connection and usage data than they might otherwise, since data collected for no clear purpose is itself a compliance liability under GDPR, not just a privacy nice-to-have. In practice, how strictly a given company applies this principle to its own logging is exactly the thing you have to verify by reading its privacy policy — GDPR sets the requirement, it doesn't audit each company's interpretation of "necessary."
The right to access, correct, and delete your data
Under GDPR you can request a copy of the personal data a company holds about you, ask for corrections, and request deletion (the "right to erasure," subject to some legal exceptions like retained billing records needed for tax law). A VPN provider subject to GDPR should have a defined process for these requests, typically described in its privacy policy, and should respond within statutory timeframes — usually one month, extendable in complex cases.
Breach notification
If a company subject to GDPR suffers a data breach likely to risk people's rights and freedoms, it's generally required to notify the relevant supervisory authority within 72 hours of becoming aware of it, and to notify affected individuals without undue delay if the risk is high. This is one of the more concrete, checkable obligations — a provider's track record on disclosing past incidents, where public, is a reasonable data point when comparing providers.
A named point of contact and, often, a Data Protection Officer
Companies processing data at scale are often required to designate a Data Protection Officer or at minimum a clear contact for privacy-related requests. Look for this in the privacy policy footer or a dedicated "privacy" or "data protection" contact — its presence and clarity is a small but real signal of how seriously a company treats the obligation versus treating it as boilerplate.
What GDPR does not do
This is the part that gets glossed over in a lot of VPN marketing copy, so it's worth being direct about it.
GDPR does not require "no-logs"
Nothing in GDPR says a VPN provider can't log connection data. GDPR regulates how personal data is handled once collected — consent, purpose limitation, security, retention limits, subject rights — not whether a VPN's core architecture logs traffic metadata in the first place. A provider can log connection timestamps and bandwidth usage, disclose that clearly in its privacy policy, retain it for a stated legitimate purpose like fraud prevention, delete it on a reasonable schedule, and be entirely GDPR compliant while doing so. "No-logs" is a separate, stronger claim about the product's architecture and policy — GDPR compliance and a no-logs claim are two different things that happen to often be discussed together.
GDPR does not stop lawful government data requests
GDPR governs how a company handles data in its ordinary commercial relationship with you. It does not exempt that company from responding to valid legal process — court orders, warrants, or other lawful requests from law enforcement or intelligence agencies, whether from an EU member state or, via mutual legal assistance treaties, from other countries. If a VPN provider has data to hand over — because it logs something, or because it can be compelled to start logging going forward for a specific target — GDPR doesn't block that disclosure; GDPR is a data-handling law, not a shield against lawful investigative authority. This is precisely why the actual content of a no-logs policy, and whether there's anything to hand over in the first place, matters more than the GDPR-compliance question when you're thinking about government access.
GDPR does not audit or certify VPN privacy claims
There is no GDPR "seal" that a company earns by passing an independent VPN-specific audit. Data protection authorities enforce the law reactively — through complaints, breach reports, and investigations — rather than proactively certifying that a given company's no-logs claim is technically accurate. A "GDPR compliant" badge on a VPN's homepage is a self-description, not third-party verification of the company's logging practices. That verification, where it exists at all, comes from independent security audits of the provider's infrastructure and source code — a different thing entirely, commissioned and paid for by the company itself, and scoped to whatever the audit actually covered.
GDPR does not make VPN use itself more legal or illegal
Whether using a VPN is legal in a given country is a matter of that country's own law, unrelated to GDPR. GDPR is about how companies handle personal data, not about regulating VPN technology or its use as a privacy tool.
Is a VPN provider a "controller" or a "processor" under GDPR, and why does it matter?
GDPR draws a distinction between a data controller — the entity that decides why and how personal data is processed — and a data processor — an entity that processes data on the controller's behalf, under instruction. For the ordinary consumer relationship (you sign up, pay, and use the app), a VPN provider is almost always acting as a controller of your account data: it decides what to collect at signup, how long to keep billing records, and how to handle support requests. That matters because a controller carries the heavier set of GDPR obligations — it's directly answerable to you and to regulators for how that data is used, rather than being able to point to someone else's instructions as the reason.
The picture gets more layered when a VPN provider is itself relying on sub-processors — a payment gateway, a customer-support ticketing platform, a cloud hosting company for its website and billing systems. Those sub-processors are usually processors acting on the VPN provider's instructions, and GDPR requires the controller (the VPN provider) to have a data processing agreement in place with each of them specifying what they're allowed to do with the data and requiring equivalent security commitments. This is invisible to you as a user in day-to-day use, but it's part of why a serious privacy policy will often name its major sub-processors or link to a sub-processor list, rather than staying silent on who else touches your data.
There's a separate, narrower case worth knowing about: if you use a VPN provided or mandated by your employer for work purposes, your employer is typically the controller of data related to that usage, and the VPN vendor is acting as the employer's processor. In that scenario, your GDPR rights (like a data access request) are generally exercised against your employer, not directly against the VPN vendor — a distinction worth knowing if you're trying to figure out who to actually contact.
Does GDPR restrict where a VPN provider can send your data?
Yes, in principle, and this is one of the more consequential parts of GDPR for a global service like a VPN. GDPR restricts transfers of EU personal data to countries outside the EU/EEA unless certain safeguards are in place. The main mechanisms are an "adequacy decision" — the European Commission formally recognizing that a country's data protection laws are essentially equivalent to the EU's own (Switzerland, the UK, and a handful of other countries currently have one) — or, absent that, contractual tools like Standard Contractual Clauses (SCCs) that bind the receiving party to GDPR-equivalent protections regardless of local law.
This became a live issue in 2020, when the EU's top court struck down the EU-US Privacy Shield framework in the Schrems II ruling, on the grounds that US surveillance law didn't offer EU citizens' data adequate protection once it reached US soil — companies transferring data to the US had to fall back on SCCs plus additional safeguards, or find another legal basis. The relevance for VPN users: if your VPN provider's billing systems, support desk, or infrastructure hosting run through US cloud services (a very common setup across the industry, VPN or otherwise), that data flow needs a valid transfer mechanism, and a privacy policy that's been updated to reflect current transfer rules is a small, checkable sign of a company staying on top of its actual compliance obligations rather than just publishing a policy once and leaving it untouched.
None of this changes what a VPN's core traffic-routing product does — your browsing traffic passing through a VPN server isn't what GDPR's international-transfer rules are primarily concerned with; they're concerned with the company's handling of your personal data as a customer. But it's a real, ongoing compliance obligation behind the scenes, and part of why "GDPR compliant" is an ongoing practice rather than a one-time checkbox a company ticks and forgets.
How does GDPR compare to how the US and UK regulate VPN data?
This comes up constantly because a lot of well-known VPN providers are based, or partly based, in the US, UK, or countries within their intelligence-sharing relationships. The US has no single comprehensive federal data-protection law equivalent to GDPR — protections are a patchwork of state laws (California's CCPA/CPRA being the most prominent), sector-specific rules, and Federal Trade Commission enforcement against unfair or deceptive practices, including false privacy claims. A US -based VPN making false statements about its logging practices could face FTC action for deceptive advertising, which is a real enforcement mechanism, just a different one from a GDPR complaint to a data protection authority.
The UK, post-Brexit, operates under UK GDPR — a near-identical framework retained from EU law and enforced by the UK's Information Commissioner's Office. A VPN based in the UK is subject to a GDPR-equivalent regime domestically, but the UK is also part of intelligence-sharing arrangements that get raised separately in jurisdiction discussions — again, a distinct question from data-protection compliance.
The practical upshot: a VPN's home country determines which data-protection regime applies to it as a baseline, but "GDPR applies" versus "GDPR doesn't apply" is a narrower and less decisive distinction than people often assume, because (a) GDPR can reach non-EU companies serving EU customers anyway, and (b) even where GDPR fully applies, it regulates data handling, not government access to that data through legal process.
What to actually check in a VPN's privacy policy, GDPR-aware
Given all of the above, here's a more useful way to read a VPN privacy policy than scanning for the phrase "GDPR compliant."
What categories of data are collected, specifically
Look for a policy that itemizes categories — account email, payment data, app crash reports, connection timestamps, aggregate bandwidth — rather than a single vague sentence like "we may collect data to improve our service." GDPR's transparency principle pushes toward this kind of itemization, and its presence (or absence) tells you something about how seriously the policy was written, independent of whether the company technically qualifies as GDPR-bound.
Retention periods
GDPR requires that data not be kept longer than necessary for its stated purpose. A well-written policy states actual retention periods — "aggregated diagnostic data is retained for 14 days," for example — rather than leaving retention open-ended. Vague or absent retention language is worth treating as a yellow flag regardless of whether the provider claims GDPR compliance.
Third parties and sub-processors
GDPR requires disclosure of data sharing with third parties, including sub-processors like payment processors, customer support platforms, or cloud infrastructure providers, and generally requires those third parties to be bound by equivalent data-protection commitments. A privacy policy that names its payment processor and analytics tools, and explains the legal basis for sharing data with them, is giving you more than a policy that just says "we may share data with trusted partners."
How to exercise your data rights in practice
Look for a concrete process — an email address, a web form, a stated response timeframe — for exercising access, correction, or deletion requests, rather than a generic statement that "EU residents have rights under GDPR" with no path to actually use them.
Whether the no-logs claim is specific
Separately from GDPR compliance, check whether the no-logs claim itself names what isn't logged — browsing activity, traffic content, DNS queries, connection timestamps, source IP, session duration — rather than using "no-logs" as an unscoped marketing word. A specific claim is falsifiable and therefore more meaningful than a vague one; it's also the kind of claim an independent audit can actually test.
Independent audits, and what they cover
Where a provider has commissioned an independent audit of its logging claims or app source code, check the audit's actual scope and date rather than treating "audited" as a permanent, blanket assurance. An audit is a snapshot of a specific system configuration at a specific time — it strengthens a specific claim, it doesn't validate the company's privacy posture forever.
Does a VPN with EU servers automatically mean better GDPR protection for me?
Not necessarily, and this is a common point of confusion. Where a VPN's server infrastructure is located is a separate question from where the company is legally based and which law governs its handling of your personal data. A VPN company based outside the EU can still operate servers physically located in EU countries, and a VPN company legally based in the EU can operate servers worldwide. Server location affects things like latency, local content access, and — depending on the host country's own laws around data centers — some technical exposure, but it doesn't by itself change which data-protection law governs the company's core handling of your account and connection data. That's determined by the company's legal jurisdiction and by GDPR's territorial-scope rules (whether it's serving EU customers), not by server geography.
Do free VPNs raise different GDPR concerns than paid ones?
The underlying legal obligations are the same regardless of price, but the business-model incentives around a free VPN are worth thinking through separately, because they shape how much data actually gets collected in the first place. A subscription VPN's revenue comes from what you pay it, which at least aligns its incentives toward not needing to monetize your data further. A free VPN has to fund its infrastructure somehow, and historically that's sometimes meant bundling third-party advertising SDKs into the app, selling aggregated or "anonymized" usage data, or upselling aggressively to a paid tier using data collected from free usage. None of that is automatically a GDPR violation — if it's disclosed, consented to where required, and handled under a valid legal basis, a free ad-supported VPN can still be technically compliant. But it does mean the privacy policy is doing more work, and it's worth reading a free VPN's policy specifically for what third-party SDKs or advertising partners are named, since that's where a free product's actual data-sharing usually lives, distinct from anything GDPR requires or forbids as a baseline.
A separate and more basic point applies to any VPN, free or paid: a browser extension or mobile app requesting broad permissions unrelated to routing traffic — access to your contacts, precise location when the VPN doesn't need it for functionality, or full browsing-history access outside of what's needed to apply a proxy — is worth more scrutiny than the GDPR-compliance question alone would suggest. Data minimization is a GDPR principle, but permission requests on your device are a platform-level (Google Play, Apple App Store) control you can check yourself before installing anything.
Common myths about VPNs and GDPR
A few misconceptions come up often enough to address directly.
Myth: "GDPR compliant" means audited and verified no-logs
Fact: it means the company states it follows GDPR's rules for handling personal data it does collect. It says nothing about whether a specific no-logs claim has been independently tested — that requires a separate, named security audit.
Myth: A VPN based in the EU is automatically more private than one based elsewhere
Fact: EU location determines the applicable data-protection regime, which is a real factor, but it doesn't by itself say anything about a specific provider's logging architecture, which is the thing that actually determines what could be disclosed if compelled. A well-run non-EU provider with a genuinely minimal logging architecture can be a stronger privacy choice than an EU-based one with a vague, permissive policy.
Myth: GDPR gives me a legal right to force a VPN to never log anything
Fact: GDPR gives you rights over data a company does hold about you — access, correction, deletion — not a right to dictate its architecture in advance. Whether a VPN logs connection metadata at all is a product and policy decision the company makes, disclosed (or not) in its privacy policy; it isn't something GDPR itself prevents.
Myth: If a VPN is GDPR compliant, using it makes me anonymous
Fact: GDPR compliance is about the VPN company's own data handling. It has no bearing on how much information websites, advertisers, or your own logged-in accounts can still gather about you once your traffic reaches its destination.
How do I file a data request or a complaint about a VPN provider?
If you want to see what personal data a VPN provider holds about you, most privacy policies describe a "subject access request" process — typically an email address or web form dedicated to privacy requests, distinct from general customer support. State clearly that you're making a GDPR access, correction, or deletion request, and note that a compliant company should respond within about a month. If a provider ignores the request, is non-responsive, or you believe it has mishandled your data in a way that breaches GDPR, you can file a complaint with your own country's data protection authority (in Ireland it's the Data Protection Commission, in Germany the relevant state authority, and so on — every EU member state has one, and most have a straightforward online complaint form). You don't need to know which authority has formal jurisdiction over the company; your own national authority can typically refer the complaint onward if another authority is the appropriate lead. This is a real, usable enforcement path, not a theoretical one — data protection authorities across the EU handle consumer complaints against companies of all kinds as a routine part of their work, and GDPR gives them the power to investigate and, where warranted, fine a company up to 4% of its global annual turnover or €20 million, whichever is higher, for serious violations.
Does GDPR cover cookies and trackers on a VPN provider's own website?
Partly, and it's worth separating this from the VPN app itself. Cookie consent on a company's marketing website — the banner asking you to accept or reject analytics and advertising cookies before you even sign up — is governed primarily by the ePrivacy Directive (sometimes called the "cookie law"), a companion piece of EU legislation that predates GDPR and specifically covers storing or accessing information on a user's device. GDPR and the ePrivacy Directive overlap and reinforce each other — where cookies collect personal data, GDPR's rules on consent and lawful basis apply on top of the ePrivacy requirement to ask first — but they're technically two different instruments, which is why you'll sometimes see privacy policies and cookie policies published as separate documents.
Practically, this means a VPN provider's marketing site can be tracking you with analytics and advertising cookies well before you've installed the actual VPN app or sent any traffic through its servers — a completely different data flow from the traffic-routing product itself, but still real data collection, and still something a cookie banner's "reject non-essential" option is meant to let you opt out of. If a site's cookie banner makes rejecting non-essential cookies meaningfully harder than accepting them — burying the reject option behind extra clicks, for instance — that's a recognized "dark pattern" regulators have specifically targeted in enforcement action, and it's a reasonable, checkable signal about how a company treats consent more broadly.
What should I actually do if a VPN provider notifies me of a data breach?
A breach notification under GDPR is required to describe, in plain terms, roughly what happened, what categories of data were involved, and what the company is doing about it. If you receive one from a VPN provider, the categories of data involved matter more than the fact of the breach itself: a breach limited to email addresses and hashed passwords is a different situation from one that exposed payment card data or, worse, connection logs the provider claimed not to keep. Change your password immediately (and anywhere else you reused it — a real risk if the breach exposed credentials), enable two-factor authentication on the account if the provider offers it, and watch for follow-up phishing attempts that reference the breach to look credible. A notification that's vague about what data was actually involved, or slow to arrive relative to when the incident is reported to have occurred, is itself worth factoring into whether you trust that provider going forward — GDPR sets a 72-hour clock for notifying the regulator, and "without undue delay" for notifying affected individuals when the risk is high, so a long, unexplained gap is a deviation from the standard, not just bad luck.
A ten-minute checklist for reading a VPN's privacy policy with GDPR in mind
Rather than looking for a "GDPR compliant" badge, work through this list against the provider's actual privacy policy:
- Does it name specific categories of data collected, rather than a single vague catch-all sentence?
- Does the no-logs claim (if there is one) specify what isn't logged — traffic content, DNS queries, connection timestamps, source IP — rather than just saying "no logs"?
- Are retention periods stated for the data that is collected, rather than left open-ended?
- Are third parties and sub-processors (payment processors, analytics, hosting) named, with the legal basis for sharing data with them?
- Is there a clear, reachable process — an email address or form — for exercising access, correction, and deletion requests, with a stated response time?
- Does the policy explain international data transfers if the company uses infrastructure outside the EU/EEA?
- Is there a named contact for privacy or data-protection questions, separate from general support?
- If the company claims an independent audit of its no-logs architecture, can you find the actual audit report, and does its date and scope match what's being claimed?
- Does the cookie banner on the company's own website make rejecting non-essential cookies as easy as accepting them?
None of these questions requires legal training to check, and none of them depends on taking the company's "GDPR compliant" self-description at face value. A policy that answers most of these clearly is doing meaningfully more than the legal minimum to earn your trust; one that answers none of them is leaning entirely on the phrase "GDPR compliant" to do work it isn't actually built to do.
Practical takeaway
GDPR is a genuinely useful baseline: it requires clear disclosure, gives you enforceable rights over your account data, and creates real consequences — including fines and regulatory investigation — for a company that mishandles personal data or lies about how it processes it. What it doesn't do is certify a VPN's core privacy promise, mandate a no-logs architecture, or block a provider from complying with lawful government data requests. Treat "GDPR compliant" as a floor, not a ceiling: a reasonable expectation for how any company handling your data should behave, not proof that a given VPN is more private than one that doesn't emphasize the phrase. The more informative questions are the ones GDPR doesn't answer for you — what specifically is logged, where the company is actually headquartered and what law governs it there, and whether any no-logs claim has been independently tested. Our individual provider reviews link out to each provider's own privacy policy and, where one exists, its audit report, so you can check these things yourself rather than taking any single source's word for it — including this one.
Frequently asked questions
Does GDPR mean a VPN can't log any of my data?
No. GDPR regulates how personal data is handled once a company decides to collect it — consent, purpose, retention limits, and your rights over it — but it doesn't prohibit a VPN from logging categories of data like connection timestamps or bandwidth usage, as long as that's disclosed and handled in line with GDPR's principles. "No-logs" is a separate, stronger claim about a provider's own architecture and policy, not something GDPR requires or guarantees.
Is a VPN based outside the EU still subject to GDPR?
Often, yes, for the portion of its business serving EU customers. GDPR's territorial scope can apply to any company processing the personal data of people in the EU when it's offering goods or services to them, regardless of where the company itself is headquartered. That said, a company's legal jurisdiction still separately determines what courts and laws actually govern it day to day, which is why jurisdiction and GDPR compliance are usually discussed as related but distinct questions.
Can GDPR stop a government from requesting my VPN data?
No. GDPR governs how a company handles personal data in its ordinary operations; it does not exempt a company from responding to valid legal process such as a court order or warrant. If a VPN provider has data that could be handed over, GDPR itself doesn't block a lawful request for it — what matters more in that scenario is what the provider actually logs in the first place.
Does "GDPR compliant" on a VPN's website mean its no-logs claim has been verified?
No. "GDPR compliant" is typically a self-description about how a company handles personal data under EU law, not a third-party audit of its no-logs claims. Verification of a specific no-logs or architecture claim, where it exists, comes from independent security audits the company commissions separately — check the audit's actual scope and date rather than treating either "GDPR compliant" or "audited" as a blanket guarantee.
What rights does GDPR actually give me over the data a VPN provider holds?
Broadly, the right to know what personal data a company holds about you, to request a copy of it, to request corrections, and to request deletion (subject to exceptions like data a company must legally retain, such as billing records). A GDPR-compliant VPN provider should have a clear, reachable process for these requests described in its privacy policy, with a stated response timeframe.
Does using EU-based VPN servers give me stronger GDPR protection?
Not by itself. Server location affects things like latency and local content access, but the law governing how a VPN company handles your personal data is determined by the company's own legal jurisdiction and by whether it's serving EU customers under GDPR's territorial-scope rules — not by where its servers are physically located.