The VPN advert on YouTube is not selling you privacy

Paid adverts promise strong encryption and no logs. They never tell you which government can lean on the company, who owns it, or what it holds when the police ask. Here is what nine popular VPNs really expose you to, scored by one set of rules.

Facts checked 28 September 2026

The Five, Nine and Fourteen Eyes as three rings Five Eyes at the centre, inside the Nine Eyes, inside the Fourteen Eyes. Fourteen Eyes Nine Eyes Five Eyes
A VPN company inside these rings answers to a state that shares intelligence with the others.

Read this first

If you want to watch a film that is not shown in your country, any of these will do and you can stop reading. Just do not count on Netflix, which checks for VPNs now.

If your aim is privacy, and especially privacy from a government, this page matters to you. An advert is a poor guide, and trusting one can end in a knock on the door, or worse. Read it carefully and be sure you understand what is at stake.

Disclosure

I use ExpressVPN. It is the tool I use myself, and it is scored here like the other eight, with its owner's links counted against it like anyone else's. This is not a paid advert. Nobody sponsored this page and there are no affiliate links on it.

I wrote it because I am tired of creators on YouTube and other platforms selling low quality, and sometimes dangerous, security products that are not fit for purpose. In my view many of them check nothing beyond what the sponsor pays for the slot.

What you are actually buying

At its simplest a VPN is a relay. Websites see the VPN company's address instead of yours, and your internet provider sees an encrypted connection to the VPN instead of the sites you visit. That is relocation. It moves where you appear to be, and it moves who can see your traffic, from your internet provider to the VPN company.

For watching something from another country's catalogue, that is all you need. It is not, on its own, protection of your identity. Whether the company that now sees your traffic can be made to hand it over, or to start recording it, depends on the five things scored below. It does not depend on the price or on the advert.

Five, Nine and Fourteen Eyes

The Five Eyes is an intelligence-sharing arrangement between five countries. Four more join to make the Nine Eyes, and five more make the Fourteen Eyes. Membership does not force a VPN company to log anything. It does mean the agencies share what they collect, and a company based in a member state answers to that state's law.

Five Eyes

  • United States
  • United Kingdom
  • Canada
  • Australia
  • New Zealand

Nine Eyes

The five above, plus:

  • Denmark
  • France
  • Netherlands
  • Norway

Fourteen Eyes

The nine above, plus:

  • Germany
  • Belgium
  • Italy
  • Spain
  • Sweden

So a VPN based in one of these countries is not automatically unsafe, but it can be ordered to act by a government that has partners. That is what the jurisdiction score measures.

Two kinds of government request

Requests about the past

A subpoena, a warrant, a raid or a formal request from a foreign police force asks for what a company already holds. The defence is engineering: nothing stored, so nothing to hand over.

RAM-only servers are the strongest form of it. Memory only holds live connections, and it is wiped when the server is powered off or rebooted. ExpressVPN says its servers wipe on every reboot, and one review reports they reboot every one to two weeks. Memory freed when a session ends is reused by new connections, so on a busy server old sessions get overwritten.

To get anything out of one, investigators would have to seize it while it is switched on, keep it running, capture the memory intact and preserve it as evidence. Even then it would show only the connections live at that moment, not anyone's history.

There is also time. A request from abroad has to go through a formal process in the provider's own country. For a British Virgin Islands operator, that means a written request to the islands' Attorney General. It takes time, and by the time it lands, past sessions have gone from memory.

Orders about the future

A different order asks a company to record from now on. RAM does not help, because the server can write down what happens next. Only the law of the country the company sits in decides whether that can be forced.

The United States has court orders that make a communications provider install and monitor a pen register for up to 60 days. A pen register collects metadata, not content, and the order can be sealed so the provider cannot tell the user. In the Netherlands, the intelligence services can order communication providers to help with live interception, and refusing is a criminal offence.

This is why jurisdiction gets its own scores. Engineering covers the past. Jurisdiction covers the future.

How the scores work

Every VPN here is marked on five things. Each has a fixed rule, so the same facts always give the same score. In every column, high is good and low is bad.

RAM-only servers, 3 points

It carries the most weight because it protects you against past requests whatever the law says. All servers RAM-only scores 3. Disks with full-disk encryption scores 1. Plain disks score 0.

Independent audits, 2 points

A named firm auditing the no-logs claim or the servers earns 1. A repeat audit adds 0.5, and so does a latest audit under 24 months old. An audit is a snapshot, which is why repeats and recent dates count. None published scores 0.

Seizure or court test, 1 point

A claim is worth more when it has been tested. A court case or subpoena on record where nothing usable was found earns 0.5. A seizure or raid confirmed by someone other than the company earns another 0.5. None found scores 0.

Operator's jurisdiction, 2 points

Where the company that runs the service sits. Outside the fourteen scores 2. Fourteen Eyes only scores 1. Nine Eyes scores 0.5. Five Eyes scores 0.

Intel protection, 2 points

Counts the links pulling a provider towards an intelligence-sharing state. A link is a parent or holding company in a Five, Nine or Fourteen Eyes state, or a move or pending law that pulls the company or its servers into one. It only counts if it adds a state beyond the operator's own. No links scores 2, and each link costs a point, so two or more scores 0.

Two worked examples

IVPN. All servers RAM-only (3). Audited repeatedly by a named firm (2). No public seizure or court test found (0). Operator in Gibraltar, outside the fourteen (2). No links (2). Total 9.0.

PIA. All servers RAM-only (3). Audited (2). Subpoenas that PIA says found nothing (0.5). Operator in the USA (0). One link, because Kape adds the UK (1). Total 6.5.

PIA has the stronger real-world test record, and still finishes 2.5 points behind. The gap comes from where the operator sits and who else has a hand on it.

The scores

Jurisdiction cells are shaded to match the rings at the top: teal is outside the alliances, sand is the Fourteen Eyes, orange is the Nine Eyes, and red is the Five Eyes.

Scoring rules
MetricPtsHigh (good)Low (bad)
RAM-only servers3All RAM-only: 3. Disks with full-disk encryption: 1Plain disks: 0
Independent audits2Named firm 1, repeat +0.5, latest under 24 months +0.5None: 0
Seizure or court test1Court case or subpoena, nothing found +0.5. Confirmed seizure or raid +0.5None found: 0
Operator's jurisdiction2Outside the fourteen: 2. Fourteen Eyes: 1. Nine Eyes: 0.5Five Eyes: 0
Intel protection2No links: 2. Each link costs a pointTwo or more links: 0
Scores
VPN RAM /3 Audit /2 Test /1 Jurisdiction /2 Intel /2 Total /10 Verdict
IVPN 3 2 0 2
Gibraltar
2 9.0 Strong
ExpressVPN 3 2 0.5 2
British Virgin Islands
1 8.5 Strong
Mullvad 3 2 0.5 1
Sweden
2 8.5 Strong
CyberGhost 3 2 0 2
Romania
1 8.0 Strong
Surfshark 3 1.5 0 0.5
Netherlands
2 7.0 Acceptable
NordVPN 3 2 0 0.5
Netherlands
(registered in Panama)
1 6.5 Acceptable
PIA 3 2 0.5 0
USA
1 6.5 Acceptable
Windscribe 3 1 0.5 0
Canada
2 6.5 Acceptable
ProtonVPN 1 2 0 2
Switzerland
1 6.0 Weak

How to read the scores: in every column, high is good and low is bad. The total is the five score columns added together. Verdicts: 8 to 10 strong, 6.5 to 7.9 acceptable, below 6.5 weak.

Jurisdiction: Gibraltar, the British Virgin Islands, Romania and Switzerland are outside the Five, Nine and Fourteen Eyes (2). Sweden is in the Fourteen Eyes only (1). The Netherlands is in the Nine Eyes (0.5). The USA and Canada are Five Eyes founders (0).

The links behind the intel scores

A link is a parent or holding company in a Five, Nine or Fourteen Eyes state, or a move or pending law that pulls the company or its servers into one. It only counts if it adds a state beyond the operator's own.

Provider by provider: what the exposure really is

IVPN, 9.0, Gibraltar

Top of the table. RAM-only, annual audits by Cure53, no email needed to sign up, and it takes cash and Monero. Gibraltar is a British Overseas Territory with its own legal system, and foreign requests go through its own process. It scores 0 on the seizure test only because no public case was found, which is a gap in the record, not a failing.

ExpressVPN, 8.5, British Virgin Islands

RAM-only, and audited by PwC, KPMG and Cure53. A server seized in Turkey in 2017 reportedly gave nothing usable. The exposure is Kape, which owns it and is listed with a London headquarters. UK orders can only be served on people in London, and it matters only if they can reach ExpressVPN's systems. No evidence was found that they can. Kape's owner is reported to live in Cyprus and holds it through an Isle of Man company.

Mullvad, 8.5, Sweden

RAM-only, with an account that is just a random number and no email, and cash accepted. In April 2023 Swedish police raided its Gothenburg office at the request of a German investigation and left with nothing. The exposure is simple: it is a Swedish company, Sweden is in the Fourteen Eyes, so Swedish orders can be served on it directly.

CyberGhost, 8.0, Romania

RAM-only, with three Deloitte Romania audits: 2022, 2024 and a third announced in February 2026. The operator is Romanian, outside the fourteen. The exposure is the same as ExpressVPN's: Kape has owned it since 2017, and its London headquarters adds the UK.

Surfshark, 7.0, Netherlands

RAM-only, with Deloitte audits reported for 2022 and 2023. It moved from the British Virgin Islands to the Netherlands in October 2021, and customers who signed up since then contract with Surfshark B.V. Dutch intelligence law lets the services order communication providers to help with live interception, and refusing is a criminal offence. Those orders can be served on it directly. It has shared a group with NordVPN since 2022.

NordVPN, 6.5, Netherlands (registered in Panama)

RAM-only, with Deloitte and PwC audits reported. The operating company, nordvpn S.A., is registered in Panama, and Nord says Panama has no mandatory data retention law. But the company is listed in a credit database with an establishment in Amsterdam, and the group holdings sit in the Netherlands and in a UK-registered company, Nordsec Ltd. The founders and Nordsec's director live in Lithuania. It is scored at the Dutch tier, and its one link is the UK holding company.

PIA, 6.5, USA

RAM-only according to its own transparency report, with Deloitte audits reported for 2022, 2024 and 2025. PIA says it was subpoenaed for logs in 2016 and 2017 and had none. The exposure is where it sits. It is a US company, and US law provides sealed monitoring orders that run forward. It is also owned by Kape.

Windscribe, 6.5, Canada

RAM-only, after it rebuilt its network following a 2021 incident. A Greek court dismissed charges against its founder in 2025. Windscribe says Dutch authorities seized a server and found only a stock install, but only the company has confirmed that, so it counts for half a point. Its infrastructure was audited by PacketLabs in 2024, but reviews report no published independent audit of its no-logs policy. It is a Canadian company, and Canada is in the Five Eyes.

ProtonVPN, 6.0, Switzerland

The best jurisdiction on paper: Switzerland is outside every alliance, and its law does not force VPN providers to log today. Four annual Securitum audits are reported for 2022 to 2025. But Proton says it uses hard disks with full-disk encryption instead of RAM-only servers, so it scores 1 of 3 there. And its jurisdiction is under threat, as the Swiss section below explains. Its total is the lowest here.

What they cost, and what the discounts really mean

Prices are US dollar list prices. The long-term offers are those advertised in mid September 2026, taken from PCWorld's deals page. The one-month and renewal prices come from a July 2026 price survey. UK prices differ and include VAT, and offers change week to week, so check the provider's own page before you pay.

Prices, in score order
VPN Score /10 One month Advertised long-term deal Renewal
IVPN 9.0 $6.00 $60 a year, about $5 a month. No free months. Same, $60 a year
ExpressVPN 8.5 $12.99 $2.99 a month for 24 months, plus 4 free months (Basic plan) $99.95 a year, about $8.33 a month
Mullvad 8.5 €5.00 None. Flat €5 a month, no discounts. Same, €5 a month
CyberGhost 8.0 $12.99 $1.99 a month for 24 months, plus 2 free months $56.94 a year, about $4.75 a month
Surfshark 7.0 $15.45 $2.49 a month for 24 months, plus 3 free months $99.95 a year, about $8.33 a month
NordVPN 6.5 $12.99 $3.49 a month for 24 months, plus 3 free months $139.08 a year, about $11.59 a month
PIA 6.5 $11.95 $2.03 a month for 36 months, plus 3 free months Higher. Sources give $56.94 to $79.00 a year
Windscribe 6.5 $9.00 $69 a year, about $5.75 a month. Free plan with 10GB a month. Same, $69 a year
ProtonVPN 6.0 $9.99 $2.99 a month for 24 months. Free plan, one device. $119.88 a year, about $9.99 a month

How a free month works

Free months come on top of the paid term, and the advertised monthly price is the total bill divided by every month, free ones included. CyberGhost's $56.94 works out at $2.19 a month over 26 months and $2.03 over 28. Same bill, smaller number. The multi-year prepayment is the sale, and the renewal is the price.

ExpressVPN's $2.99 a month renews at about $8.33. NordVPN's $3.49 renews at about $11.59. Mullvad, IVPN and Windscribe charge the same price on renewal, and Mullvad does not discount at all.

Cheap is not the tell

It would be neat to say the cheapest are the weakest. The scores say otherwise. CyberGhost has the lowest advertised price in the table and scores Strong. ExpressVPN advertises the most free months, four, and also scores Strong. Windscribe has the highest advertised monthly price and scores Acceptable. Across these nine, the advertised price and the score are barely related, so a big discount is not a warning sign and a high price is not a guarantee.

What the price can tell you is different. Two of the three top scorers, IVPN and Mullvad, sell at one price with no free months and no multi-year promotion. And one review site's price index says it plainly: price reflects marketing and promotions as much as quality.

Where cheap does get dangerous

Free and lifetime offers. One review site's summary of the market says most free VPNs cap your data, inject adverts or collect and sell your browsing data to pay for themselves, and that lifetime deals often compromise on security. When the product is free, the company is paid somewhere else.

What the low price is paying for

On a good provider, a low price pays for scale and a long lock-in. On a bad one it pays for nothing you can see. The advert cannot tell you which, because the five things that matter are not on the price page. The headline is the number that sells, and the renewal sits in the terms. Ask what year three costs, then ask the five questions.

EU GDPR: what it does and what it does not

GDPR is the EU's data protection law and has applied since 25 May 2018. It covers how companies handle the personal data of people in the EU. It reaches beyond the EU: a company anywhere that offers services to people in the EU, or monitors their behaviour, has to follow it and must appoint a representative in the EU. Fines can reach 20 million euros or 4 percent of annual worldwide turnover, whichever is higher.

For a VPN user that means rights over your own data, such as access and erasure, and a duty on the company to collect no more than it needs. Sweden, the Netherlands and Romania are EU states, so it applies directly to Mullvad, Surfshark and CyberGhost. It also reaches providers outside the EU that sell to people in it.

What it does not do is stop a government. Processing for national security sits outside EU law, and police use of personal data is covered by a separate law, the Law Enforcement Directive. GDPR governs how a company treats you. It does not switch off an intelligence agency's own powers, and it does not stop the Dutch interception orders described above.

The UK left the EU and now has its own version, the UK GDPR, built on the same rules.

What Switzerland is doing

Switzerland is outside the EU and all the eyes, and for years that made it the default answer for privacy. Its current law does not force VPN providers to log. That is now under threat.

The Swiss government has proposed rewriting the ordinance on surveillance of post and telecoms traffic, known by its German initials VÜPF. The draft would apply to VPN, email and messaging providers with as few as 5,000 users. They would have to identify customers with a government document, keep IP addresses and connection data for six months, and be able to decrypt what they have encrypted. It is an ordinance issued by the government, not a law passed by parliament.

The first consultation closed on 6 May 2025 with a near-uniformly hostile response. In February 2026 the justice department said it had commissioned an external risk impact assessment and would prepare a second consultation. As of June 2026 there was no binding timetable, and the Federal Council had not said the project was dead. A paused law is not a buried one.

Proton, the best known Swiss provider, froze new Swiss data-centre spending and put the servers for its new AI assistant in Germany, with facilities also being built in Norway. It says its headquarters, legal entity and core Mail and VPN infrastructure stay in Geneva. Its chief executive has said the company would leave if the amendment passes.

That leaves ProtonVPN exposed either way. If the rule passes and Proton stays, it has to log. If it leaves, the places it is already building servers, Germany and Norway, are inside the alliances, and the company and its data would still sit under alliance-state law. That is why it scores 1 point on intel protection, and why having no RAM-only servers matters.

What to do with this

Read the advert as what it is: a paid script. Then ask the same five questions of any VPN, the ones in the table. Does it run RAM-only servers? Has a named firm audited it, recently and more than once? Has its no-logs claim been tested by a seizure or a court? Which country is the operator in? Who else, in which country, owns it or can pull it?

Then look at what it costs in year three, not year one. The deal in the advert is the introductory price.

No provider scores 10. The top score is 9.0, and it loses its point only because no public seizure or court test was found. Nobody here is out of reach of every possible order, so pick on evidence, not on the advert.

About these ratings: the method is this site's own. It is based on public sources and company statements, checked on 28 September 2026. Companies change owners, servers and laws, so check current details before you rely on any of this. This page is information, not legal advice.

Sources