What Happens When a Government Subpoenas a VPN Company?
Every VPN claims a "no-logs" policy. What actually happens when that claim gets tested by a real legal demand is a much more useful data point than the marketing copy itself — and several VPN providers now have genuine, documented real-world cases to point to, not just written policies.
How the Process Works
When law enforcement or a government agency wants data from a VPN provider, the specific mechanism depends on jurisdiction — a subpoena, a court order, or in some countries, a more sweeping and sometimes secret legal instrument. In the US and most Western jurisdictions, this typically means a court-authorized order compelling the company to produce whatever data it holds. Critically: a company can only hand over what it actually retains. If a VPN provider's architecture genuinely doesn't log connection timestamps, browsing activity, or IP-to-account mappings, a valid legal order doesn't create data that doesn't exist — it just confirms there's nothing to produce.
Real Cases, Not Just Policies
Private Internet Access (PIA): Tested twice in real US legal proceedings — a 2016 FBI subpoena tied to a bomb-threat investigation, and a separate 2018 case involving a hacking investigation. In both instances, the company had no data mapping IP addresses to individual accounts to produce.
ExpressVPN: In 2017, Turkish authorities physically seized one of the company's servers during an investigation. No data was found that could identify a user, thanks to the company's RAM-only TrustedServer architecture, which by design retains nothing persistent.
Mullvad: In April 2023, Swedish police entered the company's Gothenburg office with a search warrant seeking customer data. Officers left empty-handed, since Mullvad's anonymous account-number system meant there was no identifying information to seize in the first place.
Windscribe: In 2021, Ukrainian authorities seized two of the company's servers during an investigation and recovered nothing, consistent with its no-logs, RAM-only design.
The counterexample worth knowing: IPVanish, in 2016 under prior ownership (Highwinds/Mudhook Media), reportedly did share user connection logs with the FBI despite advertising a "zero-log" policy at the time — a genuine breach of trust that the company has spent years and two independent audits (2022, 2025) trying to move past under its current ownership. PureVPN, similarly, cooperated with the FBI in a 2017 cyberstalking case using logs it held at the time, despite its own no-logs marketing — the company has since moved jurisdiction and adopted a KPMG "Always-On Audit" arrangement in response.
Why Jurisdiction Still Matters, Even With Real No-Logs Cases
A verified no-logs architecture is the most important factor, but jurisdiction shapes what legal tools are even available to compel a company in the first place. Providers based outside the Five/Nine/Fourteen Eyes intelligence-sharing alliances (Sweden's Mullvad, Switzerland's ProtonVPN, Panama's NordVPN operating entity, Romania's CyberGhost) generally face fewer mandatory data-retention obligations than those based inside the US or UK. That doesn't make US-based providers like PIA untrustworthy — PIA's own real-world court test record is genuinely strong — but it does mean the legal environment they operate under is inherently less favorable on paper, even when the technical architecture holds up in practice.
What This Means for You
When evaluating a VPN's privacy claims, a real-world legal test (a court case, a server seizure, a police raid) is meaningfully stronger evidence than a privacy policy alone, and stronger than most independent audits too, since an audit examines a system's configuration at one point in time, while a legal test examines what actually happens under real pressure. The providers with genuine, documented real-world tests — PIA, ExpressVPN, Mullvad, Windscribe — have all passed them. The providers with a documented failure — IPVanish and PureVPN, both under different ownership or policy than today — are worth knowing about specifically because they show what happens when a no-logs claim doesn't hold up, not just when it does.
What a "No Data to Produce" Response Actually Looks Like
It's worth understanding what happens procedurally when a company genuinely has nothing to hand over. Rather than refusing to cooperate, a company with a real no-logs architecture typically responds to a valid legal request by confirming it received the request and explaining, often in a published transparency report, that it does not retain the type of data being sought. PIA's quarterly transparency reports follow exactly this pattern: disclosing the number of requests received each quarter and confirming that none resulted in data disclosure, specifically because none was retained in the first place. This is meaningfully different from a company simply ignoring a legal order, which would carry real legal consequences — the point is that compliance and having nothing to disclose aren't in tension when the underlying architecture is built correctly from the start.
Why Real-World Tests Carry More Weight Than Audits Alone
An independent audit is a snapshot: auditors examine a system's configuration, server setup, and code at one specific point in time and confirm it matches the provider's stated policy at that moment. A real legal test is different in kind, not just degree — it's what happens when an outside party with actual legal authority demands the data under real conditions, with real consequences for the company if it can't comply or if it's later found to have misrepresented its capabilities. Both forms of evidence matter, but when they're available, real-world cases like the ones documented here are the single most convincing category of proof a no-logs claim can offer.
Keep in mind that new cases continue to emerge as VPN usage grows and law enforcement interest in the industry increases correspondingly; the list of real-world tests documented in this piece reflects the public record as of mid-2026, and readers should treat any provider's claimed no-logs status as an ongoing question worth periodically revisiting rather than a fact established once and settled permanently.
Frequently Asked Questions
Can a VPN company be forced to hand over my data?
Yes, via a valid legal order in whatever jurisdiction the company operates. However, a company can only hand over data it actually retains — a genuinely no-logs architecture means there's nothing usable to produce even under a valid order.
Has any VPN actually been tested by a real subpoena or raid?
Yes. PIA (2016, 2018 US legal cases), ExpressVPN (2017 Turkish server seizure), Mullvad (2023 Swedish police raid), and Windscribe (2021 Ukrainian server seizure) all had no usable data to produce in real legal or law-enforcement tests.
Which VPNs have failed a real-world logging test?
IPVanish, under prior ownership in 2016, reportedly shared connection logs with the FBI despite advertising a zero-log policy. PureVPN cooperated with the FBI in a 2017 case using logs it held at the time. Both companies have since changed ownership or policy and added independent audits.
Does jurisdiction matter if a VPN has passed a real legal test?
It still matters for the legal tools available to compel a company in the first place, even if the technical no-logs architecture has held up. Jurisdiction and verified architecture are both relevant, not substitutes for each other.