VPN No-Logs Claims: Why Audits and Court Cases Matter More Than Marketing
Nearly every VPN markets a no-logs policy. Independent privacy research cited across current industry analysis estimates roughly one-third of services claiming a zero-logs policy actually collect user data in some form regardless. The gap between the marketing page and the real policy only becomes visible through two specific kinds of evidence: an independent technical audit, or what happens when a government actually demands the data.
Key takeaways
- Roughly a third of VPNs claiming no-logs policies collect some data anyway Independent privacy audits and research repeatedly find a gap between marketing claims and actual logging practice across the industry.
- Court cases are stronger evidence than audits alone Private Internet Access was subpoenaed by the FBI in both 2016 and 2021, and in both cases had no user data to produce, a real-world test an audit can’t replicate.
- Named providers have been caught providing logs despite no-log marketing PureVPN and HMA have both been documented providing user data to law enforcement despite advertising strict no-logs policies at the time.
Why a Privacy Policy Alone Isn't Proof
A genuine no-logs policy in 2026 means a provider stores no browsing activity, connection timestamps, IP addresses, or bandwidth usage tied to an individual user. The practical problem is that this is exactly the same language nearly every VPN uses on its marketing page, whether or not the underlying infrastructure actually supports the claim. Some providers technically avoid logging browsing history specifically while still retaining connection metadata, timestamps, and bandwidth figures, data that can still reveal a user's identity and activity pattern even without recording the literal websites visited.
The only way to actually distinguish a verified claim from a marketing one is independent evidence. Technical audits from firms like Deloitte, KPMG, Cure53, or Securitum examine a provider's server infrastructure directly to confirm what is and isn't being stored, and several major providers now undergo these repeatedly: ExpressVPN's no-logs policy has been audited three times including a June 2025 KPMG review, Private Internet Access has been independently audited three times by Deloitte, and ProtonVPN has undergone four separate Securitum reports plus a SOC 2 Type II audit, publishing its results openly.
An audit confirms logging practices at the time it was conducted. Ownership changes, jurisdiction shifts, or infrastructure changes afterward can alter what’s actually collected, which is why providers undergoing repeated, recent audits (not a single one from several years ago) offer a stronger ongoing signal than a one-time certification.
Why Court Cases Are Stronger Evidence Than Audits Alone
An audit is a cooperative, scheduled review. A legal demand for data is adversarial, and that distinction matters: a provider has every incentive to pass a scheduled audit, but a subpoena or court order tests the claim under genuine pressure, with real legal consequences for noncompliance. Private Internet Access was subpoenaed by the FBI twice, in 2016 and again in 2021, and in both cases confirmed it had no user data available to produce, a real-world result that carries more weight than any paperwork-only audit. OVPN has a similar documented case, with its zero-logs architecture tested and confirmed in an actual court proceeding rather than only through a hired auditor's review.
The opposite outcome has happened too, which is exactly why this distinction matters. PureVPN and HMA have both been documented providing user data to law enforcement despite marketing no-log policies, cases that surfaced specifically because of real legal action rather than a self-reported audit. Those cases are the clearest evidence available that a marketing claim and an actual, enforceable policy can diverge, and that the divergence isn't hypothetical.
What to Actually Check Before Trusting a No-Logs Claim
A practical verification checklist
A single old audit is weaker evidence than a pattern of recent, independently published reviews.
This is the strongest available evidence, since it tests the claim under genuine adversarial pressure.
Even a technically sound no-logs architecture offers less protection in a jurisdiction with mandatory data retention requirements.
Some providers avoid activity logging while still retaining connection metadata or bandwidth data.
A provider’s privacy standards can shift after an acquisition or a move to a different jurisdiction.
Who Should Weight This Most Heavily
- Several major providers now undergo recent, repeated, publicly published audits
- Real court cases give genuinely strong, adversarially-tested evidence where they exist
- Checking jurisdiction and audit recency takes minutes and meaningfully narrows real options
- Roughly a third of no-logs claims don’t hold up under independent scrutiny, per current research
- Named providers have been documented providing data despite no-log marketing claims
- A clean legal history doesn’t necessarily mean a provider has actually been tested under pressure
Comparing VPNs and other security tools
See our full security software guide for VPNs, password managers and endpoint protection comparisons.
Our Sources
Where this comes from
The audit details and court case specifics here are drawn from multiple independent 2026 VPN privacy research sources, cross-checked for consistency on named providers, named audit firms, and named legal cases, given how directly these details matter for evaluating a provider’s actual privacy claims.
-
Specific audit details cited by provider and firm
ExpressVPN’s KPMG audit, Private Internet Access’s Deloitte audits, and ProtonVPN’s Securitum reports drawn from named, dated 2025-2026 sources.
-
Court cases cited by name
Private Internet Access’s FBI subpoenas and the PureVPN and HMA cases drawn from documented, independently reported legal and enforcement history.
-
No claims of our own technical VPN audit
This article explains published audit and legal evidence; it does not present our own original technical review of VPN server infrastructure.
Frequently Asked Questions
Frequently asked questions
How many VPNs that claim no-logs policies actually keep some data?
Independent privacy research cited across current industry analysis estimates roughly one-third of VPNs claiming a zero-logs policy collect some user data regardless, which is why independent verification matters more than the marketing claim alone.
What's the strongest evidence that a VPN's no-logs policy is real?
Real-world legal cases, where a provider was legally compelled to produce user data and had none to give, are generally stronger evidence than a scheduled, cooperative audit, since they test the claim under genuine adversarial pressure.
Which VPNs have been caught providing logs despite no-log marketing claims?
PureVPN and HMA have both been documented providing user data to law enforcement despite advertising no-logs policies at the time, cases that became public specifically through legal proceedings.
Does an independent audit guarantee a VPN's logging practices stay the same forever?
No. An audit confirms practices at the time it was conducted. Ownership changes or infrastructure shifts afterward can alter what’s collected, which is why recent, repeated audits are a stronger signal than a single older one.
Does a VPN make me completely anonymous online?
No. A VPN hides your IP address and encrypts your connection, but it doesn’t remove personal data already held by data brokers, and it doesn’t hide your activity from the websites you actually log into or interact with.
Final take
- Roughly a third of VPNs claiming no-logs policies collect some data anyway, per independent research
- Court cases, like PIA's two FBI subpoenas with nothing to produce, test claims under real pressure
- Named providers (PureVPN, HMA) have been documented providing data despite no-log claims
Almost every VPN claims a no-logs policy, and independent research suggests roughly a third of those claims don’t fully hold up once examined closely. The gap only becomes visible through specific, checkable evidence: recent, repeated third-party audits from named firms, and real-world legal history showing what actually happens when a government demands the data. Private Internet Access’s two FBI subpoenas with nothing to produce, against PureVPN and HMA’s documented cases of providing data despite similar marketing, show exactly why the policy page alone was never the real test.