VPN No-Logs Claims: Audits vs Court Cases

Explained

VPN No-Logs Claims: Why Audits and Court Cases Matter More Than Marketing

Nearly every VPN markets a no-logs policy. Independent privacy research cited across current industry analysis estimates roughly one-third of services claiming a zero-logs policy actually collect user data in some form regardless. The gap between the marketing page and the real policy only becomes visible through two specific kinds of evidence: an independent technical audit, or what happens when a government actually demands the data.

Key Takeaways

Key takeaways

  • Roughly a third of VPNs claiming no-logs policies collect some data anyway Independent privacy audits and research repeatedly find a gap between marketing claims and actual logging practice across the industry.
  • Court cases are stronger evidence than audits alone Private Internet Access was subpoenaed by the FBI in both 2016 and 2021, and in both cases had no user data to produce, a real-world test an audit can’t replicate.
  • Named providers have been caught providing logs despite no-log marketing PureVPN and HMA have both been documented providing user data to law enforcement despite advertising strict no-logs policies at the time.

Why a Privacy Policy Alone Isn't Proof

A genuine no-logs policy in 2026 means a provider stores no browsing activity, connection timestamps, IP addresses, or bandwidth usage tied to an individual user. The practical problem is that this is exactly the same language nearly every VPN uses on its marketing page, whether or not the underlying infrastructure actually supports the claim. Some providers technically avoid logging browsing history specifically while still retaining connection metadata, timestamps, and bandwidth figures, data that can still reveal a user's identity and activity pattern even without recording the literal websites visited.

The only way to actually distinguish a verified claim from a marketing one is independent evidence. Technical audits from firms like Deloitte, KPMG, Cure53, or Securitum examine a provider's server infrastructure directly to confirm what is and isn't being stored, and several major providers now undergo these repeatedly: ExpressVPN's no-logs policy has been audited three times including a June 2025 KPMG review, Private Internet Access has been independently audited three times by Deloitte, and ProtonVPN has undergone four separate Securitum reports plus a SOC 2 Type II audit, publishing its results openly.

A passed audit is a snapshot, not a permanent guarantee

An audit confirms logging practices at the time it was conducted. Ownership changes, jurisdiction shifts, or infrastructure changes afterward can alter what’s actually collected, which is why providers undergoing repeated, recent audits (not a single one from several years ago) offer a stronger ongoing signal than a one-time certification.

Why Court Cases Are Stronger Evidence Than Audits Alone

An audit is a cooperative, scheduled review. A legal demand for data is adversarial, and that distinction matters: a provider has every incentive to pass a scheduled audit, but a subpoena or court order tests the claim under genuine pressure, with real legal consequences for noncompliance. Private Internet Access was subpoenaed by the FBI twice, in 2016 and again in 2021, and in both cases confirmed it had no user data available to produce, a real-world result that carries more weight than any paperwork-only audit. OVPN has a similar documented case, with its zero-logs architecture tested and confirmed in an actual court proceeding rather than only through a hired auditor's review.

The opposite outcome has happened too, which is exactly why this distinction matters. PureVPN and HMA have both been documented providing user data to law enforcement despite marketing no-log policies, cases that surfaced specifically because of real legal action rather than a self-reported audit. Those cases are the clearest evidence available that a marketing claim and an actual, enforceable policy can diverge, and that the divergence isn't hypothetical.

What to Actually Check Before Trusting a No-Logs Claim

What to look for

A practical verification checklist

01
Recent, repeated, published third-party audits

A single old audit is weaker evidence than a pattern of recent, independently published reviews.

Look for
Audits within the last 12 to 18 months from a named, reputable firm, with the full report published, not just a summary badge
Avoid
A provider citing an audit with no date, no firm name, or no publicly accessible report
02
Real-world legal or enforcement history

This is the strongest available evidence, since it tests the claim under genuine adversarial pressure.

Look for
A documented case where the provider was legally compelled to produce data and had none to give
Avoid
Assuming a clean legal history means untested; it may simply mean the provider has never faced a serious legal demand
03
Jurisdiction and data retention law

Even a technically sound no-logs architecture offers less protection in a jurisdiction with mandatory data retention requirements.

Look for
A provider based outside mandatory data retention jurisdictions, with that location specifically named in its own policy
Avoid
Overlooking jurisdiction because the technical logging claim alone sounds reassuring
04
What specifically counts as a "log" in the provider's own policy

Some providers avoid activity logging while still retaining connection metadata or bandwidth data.

Look for
An explicit, itemized list of exactly what is and isn't collected, not just the phrase "no logs" alone
Avoid
Vague language that doesn't specifically address connection timestamps, bandwidth, or metadata
05
Ownership and infrastructure changes over time

A provider’s privacy standards can shift after an acquisition or a move to a different jurisdiction.

Look for
Confirmation that recent audits reflect the provider's current ownership and infrastructure, not a prior arrangement
Avoid
Relying on an audit that predates a known ownership change

Who Should Weight This Most Heavily

Best for
Anyone choosing a VPN specifically for privacy, not just for unblocking content or basic encryption Users currently relying on a provider's marketing claim alone with no audit or legal history checked
Not for
Users whose VPN use case is unrelated to privacy from the provider itself, such as basic geographic unblocking
Pros
  • Several major providers now undergo recent, repeated, publicly published audits
  • Real court cases give genuinely strong, adversarially-tested evidence where they exist
  • Checking jurisdiction and audit recency takes minutes and meaningfully narrows real options
Cons
  • Roughly a third of no-logs claims don’t hold up under independent scrutiny, per current research
  • Named providers have been documented providing data despite no-log marketing claims
  • A clean legal history doesn’t necessarily mean a provider has actually been tested under pressure

Comparing VPNs and other security tools

See our full security software guide for VPNs, password managers and endpoint protection comparisons.

Our Sources

Methodology

Where this comes from

The audit details and court case specifics here are drawn from multiple independent 2026 VPN privacy research sources, cross-checked for consistency on named providers, named audit firms, and named legal cases, given how directly these details matter for evaluating a provider’s actual privacy claims.

  • Specific audit details cited by provider and firm

    ExpressVPN’s KPMG audit, Private Internet Access’s Deloitte audits, and ProtonVPN’s Securitum reports drawn from named, dated 2025-2026 sources.

  • Court cases cited by name

    Private Internet Access’s FBI subpoenas and the PureVPN and HMA cases drawn from documented, independently reported legal and enforcement history.

  • No claims of our own technical VPN audit

    This article explains published audit and legal evidence; it does not present our own original technical review of VPN server infrastructure.

Frequently Asked Questions

Frequently Asked Questions

Frequently asked questions

How many VPNs that claim no-logs policies actually keep some data?

Independent privacy research cited across current industry analysis estimates roughly one-third of VPNs claiming a zero-logs policy collect some user data regardless, which is why independent verification matters more than the marketing claim alone.

What's the strongest evidence that a VPN's no-logs policy is real?

Real-world legal cases, where a provider was legally compelled to produce user data and had none to give, are generally stronger evidence than a scheduled, cooperative audit, since they test the claim under genuine adversarial pressure.

Which VPNs have been caught providing logs despite no-log marketing claims?

PureVPN and HMA have both been documented providing user data to law enforcement despite advertising no-logs policies at the time, cases that became public specifically through legal proceedings.

Does an independent audit guarantee a VPN's logging practices stay the same forever?

No. An audit confirms practices at the time it was conducted. Ownership changes or infrastructure shifts afterward can alter what’s collected, which is why recent, repeated audits are a stronger signal than a single older one.

Does a VPN make me completely anonymous online?

No. A VPN hides your IP address and encrypts your connection, but it doesn’t remove personal data already held by data brokers, and it doesn’t hide your activity from the websites you actually log into or interact with.

Conclusion

Final take

  • Roughly a third of VPNs claiming no-logs policies collect some data anyway, per independent research
  • Court cases, like PIA's two FBI subpoenas with nothing to produce, test claims under real pressure
  • Named providers (PureVPN, HMA) have been documented providing data despite no-log claims

Almost every VPN claims a no-logs policy, and independent research suggests roughly a third of those claims don’t fully hold up once examined closely. The gap only becomes visible through specific, checkable evidence: recent, repeated third-party audits from named firms, and real-world legal history showing what actually happens when a government demands the data. Private Internet Access’s two FBI subpoenas with nothing to produce, against PureVPN and HMA’s documented cases of providing data despite similar marketing, show exactly why the policy page alone was never the real test.

Urivio
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart