Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


5 Eyes 9 Eyes 14 Eyes are often used in VPN marketing to create fear, but what they really describe is a set of intelligence cooperation and information-sharing relationships between countries. They do not prove that every VPN in a listed country is unsafe. Public records show that Five Eyes grew out of UK-U.S. intelligence cooperation and the UKUSA Agreement, with the United States, United Kingdom, Canada, Australia, and New Zealand as members.[1]
For VPN users, the better questions are not just “is this country on the list?” They are: where is the VPN company incorporated, does it keep identifiable logs, has it been independently audited, does it use diskless or log-minimized servers, and what happens when it receives a legal request? If you want the basics first, start with our complete VPN guide.
Key Takeaways
- 5 Eyes is an intelligence-sharing alliance between the U.S., U.K., Canada, Australia, and New Zealand.[1]
- 9 Eyes and 14 Eyes are common extensions in wider intelligence and VPN privacy discussions, but their public boundaries are less clear than Five Eyes.
- VPN privacy cannot be judged by company location alone. Logging policy, technical architecture, audits, and transparency matter.
- Server location and company jurisdiction are different. Connecting to a server in a country does not mean the VPN company is incorporated there.
- A VPN that keeps no identifiable logs is more meaningful than a slogan about being “offshore.”
Five Eyes usually refers to intelligence-sharing cooperation between the United States, United Kingdom, Canada, Australia, and New Zealand.
The U.S. National Security Agency has released historical material on the UKUSA Agreement, showing that the relationship grew out of post-World War II U.K.-U.S. signals intelligence cooperation and later expanded to other members.[1]
Five Eyes was not invented by the VPN industry, and it is not a single law. It is better understood as a long-running intelligence cooperation framework.
VPN articles commonly describe the groups this way:
| Name | Commonly listed members |
|---|---|
| 5 Eyes | United States, United Kingdom, Canada, Australia, New Zealand |
| 9 Eyes | 5 Eyes plus Denmark, France, the Netherlands, Norway |
| 14 Eyes | 9 Eyes plus Germany, Belgium, Italy, Spain, Sweden |
Be careful with this list. Five Eyes has clearer public historical material. 9 Eyes and 14 Eyes appear more often in broader intelligence cooperation, SIGINT Seniors Europe, and VPN privacy discussions, but they do not have the same public-facing clarity as Five Eyes.
So do not treat “14 Eyes country” as an absolute legal label. It can remind you to think about cross-border intelligence sharing, but it cannot replace evaluating a specific VPN provider.
The connection matters in three main ways:
Official U.K. and European Parliament reports show why these issues cannot be reduced to a map: national legal frameworks govern intelligence powers, while cross-border surveillance can affect people and data protections outside the collecting country.[2][3]
The key question is whether the provider has anything identifiable to hand over.
If a VPN stores your real IP address, connection times, visited sites, DNS queries, and account identity links, jurisdiction becomes more sensitive. If a VPN does not technically record identifiable activity and backs that claim with audits and transparency reports, the risk profile changes.
These three ideas are often confused:
| Concept | What it means | Why it matters |
|---|---|---|
| Company jurisdiction | Where the VPN company is incorporated and operated | Shapes the main legal request path |
| Server location | The country of the VPN exit node you connect to | Affects IP region, speed, and local data center rules |
| User location | Where you physically are | Affects your own legal duties and network environment |
Connecting to a U.S. server does not mean the VPN company is a U.S. company. Using an overseas VPN company does not mean you can ignore the laws where you are.
No.
A VPN registered outside the commonly listed 14 Eyes countries may still be a poor privacy choice if it:
The opposite can also be true. A provider in a stricter jurisdiction may be more trustworthy if it does not retain activity logs, undergoes regular audits, and publicly explains its legal request process.
If you want to understand what a VPN can and cannot do, read whether a VPN makes you fully anonymous.
Start with these eight items:
Be cautious when you see promises like “absolute anonymity” or “impossible to trace.”
Yes. Server location mainly affects your exit IP, speed, and access to region-specific content.
For example, if you only want to access a regional website, lower latency, or test availability, connecting to a server in a commonly listed 14 Eyes country does not automatically mean “privacy failure.”
A more practical approach is:
If you use VPNs or cross-border network tools in mainland China, consider local law, network conditions, and account security in addition to the provider’s privacy policy.
In practice, many privacy risks do not come from 5 Eyes. They come from:
Do not put all privacy anxiety on the alliance list. It is one dimension, not the whole risk model.
It usually refers to the United States, United Kingdom, Canada, Australia, and New Zealand.[1]
No. You need to check whether the provider stores identifiable logs, has audits, and handles legal requests transparently.
For legal requests, company jurisdiction is usually more important. For speed and exit IP location, server location matters more.
Not always. Many services still keep payment, account, crash, or temporary diagnostic data. Read the policy details and audit scope.
Not automatically. The server is only the exit node. The provider’s architecture and logging policy matter more.
Ordinary users should not read them as real-time watchlists. They are intelligence-sharing frameworks; actual risk depends on legal requests, targeting, provider logs, and user behavior.
You can use jurisdiction as one signal, but do not stop there. No-logs design, audits, transparency reports, and technical implementation are stronger indicators.
Disclaimer
This article is for digital privacy and VPN selection education only. It does not constitute legal, intelligence, compliance, or cross-border network use advice. Rules on data requests, VPN use, and communications monitoring vary by country and region. Follow the laws that apply to you.
For the VPN workflow in “5 Eyes 9 Eyes 14 Eyes: 2026 Guide”, AethoVPN is one option; verify current official app availability before relying on a particular device or location.
Sources
Sources checked 8 May 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.