On this page

The 14 Eyes countries are the Five Eyes (the United States, the United Kingdom, Canada, Australia and New Zealand), plus Denmark, France, the Netherlands and Norway, which make the Nine Eyes, plus Belgium, Germany, Italy, Spain and Sweden. For a server, membership concerns how spy agencies share intercepted communications, not who can legally obtain its data.
Of our seven locations, only the Netherlands is on these lists; Iceland, Switzerland, Moldova, Romania, Bulgaria and Malaysia are in none. This guide separates what is official from what was leaked, explains what the alliances can and cannot do to a hosted server, and shows when the question should shape your choice of an offshore VPS location among our seven jurisdictions.
Who are the 14 Eyes countries?
The groups are nested: each contains the smaller ones, and sharing is closest at the core.
| Group | Countries | Evidence |
|---|---|---|
| Five Eyes | United States, United Kingdom, Canada, Australia, New Zealand | UKUSA agreement, officially acknowledged in 2010 |
| Nine Eyes | The Five Eyes plus Denmark, France, the Netherlands, Norway | Leaked NSA documents (2013) |
| 14 Eyes | The Nine Eyes plus Belgium, Germany, Italy, Spain, Sweden | Leaked NSA documents (2013, 2018) |
Five Eyes countries and the UKUSA agreement
The Five Eyes began as a signals intelligence pact between Britain and the United States, signed on
Nine Eyes and 14 Eyes: SIGINT Seniors Europe
The wider groups are known from leaks, not from a published treaty. In
In 2018 the Intercept published NSA newsletters from the same files that name the
The labels are shorthand
Three lists do not capture every relationship. The Guardian also mentioned a "
Our seven locations and the 14 Eyes countries
Only one of our locations is on any list. The legal notes come from our location pages.
| Location | 5 / 9 / 14 Eyes | EU member | Legal note |
|---|---|---|---|
| Iceland (Reykjavík) | None | No (EEA member) | Telecom undertakings keep minimal traffic records for six months |
| Switzerland (Zürich) | None | No | Telecom providers keep metadata for six months; a paused ordinance revision would widen identification duties |
| Moldova (Chișinău) | None | No (candidate) | Providers store traffic data for |
| Romania (Bucharest) | None | Yes | General retention struck down in 2009 and 2014; telecom operators may keep billing traffic data up to three years |
| Netherlands (Amsterdam) | Nine and 14 Eyes | Yes | No general retention duty since a 2015 court ruling; investigators can demand data a provider holds |
| Bulgaria (Sofia) | None | Yes | Retention law annulled in 2015; the EU Court of Justice ruled out general and indiscriminate retention in 2022 |
| Malaysia ( | None | No | No general retention period for hosts; police and regulators can compel disclosure of data a provider holds |
Amsterdam is a 14 Eyes VPS location, yet the Netherlands has had no general retention duty since 2015, while Iceland and Switzerland, on no list, require telecom providers to keep six months of traffic records. Wherever the server runs, we do not log or inspect its traffic.
What the Eyes alliances mean for a hosted server
Intelligence sharing is not a legal request for data
The alliances concern signals intelligence: agencies intercepting communications and sharing what they collect. They are not a legal channel to the files on a particular server. Stored data is normally obtained through the courts and competent authorities of the server's country; a foreign authority typically sends a request under a mutual legal assistance treaty (MLAT), which that country examines under its own law. In the EU, instruments such as the
Our law enforcement guidelines apply this in all seven locations. A request can only return what we hold: an email address, payment and service records, and
Interception happens on the network path
Eavesdropping works on traffic in transit, so where your traffic goes matters as much as where the server sits. In 2013 the Guardian reported, from Snowden's documents, that GCHQ had attached probes to transatlantic
A server outside the 14 Eyes does not keep its traffic outside them. If your users are in the UK or the US, every connection crosses those countries' networks. From Reykjavík, traffic to continental Europe passes through Scotland (in the UK), Ireland or Denmark first, and only Ireland is on none of the lists. From Zürich, traffic to Frankfurt, Milan, Paris or Amsterdam enters Germany, Italy, France or the Netherlands, all 14 Eyes countries.
Encryption hides content, not metadata
TLS (HTTPS), SSH and WireGuard encrypt what travels between you and your server, so an interceptor cannot read it. They do not hide who talks to whom: the network needs the IP addresses at both ends to deliver each packet, and timing and volume stay visible. The IETF lists IP addresses in packet headers among the channels adversaries have used to monitor web services, and notes that standard TLS sends the site's name in cleartext when a connection opens (RFC 8744). WireGuard "does not focus on obfuscation" either (WireGuard). Tempora could keep metadata ten times longer than content, and as the EFF puts it, "even a tiny sample of metadata can provide an intimate lens into a person's life" (EFF).
Outside the Eyes lists is not outside cooperation
Countries missing from the lists still cooperate with other states, and the channels that reach stored data are legal ones. All six of our European locations have them:
- The Budapest Convention. Iceland, Switzerland, Moldova, Romania, the Netherlands and Bulgaria are parties to the Council of Europe's Convention on Cybercrime, which organizes
cross-border data preservation and mutual assistance, as our jurisdictions comparison notes. - EU instruments. In Romania, the Netherlands and Bulgaria, courts and competent authorities can issue DSA orders on specific content or for information, and terrorist content can be ordered offline within one hour.
- Foreign preservation requests. In Moldova, the Interior Ministry can order immediate preservation of data at the request of foreign authorities.
In all seven locations, Malaysia included, we act only on requests from an authority competent where the server runs, so a foreign authority goes through mutual legal assistance, and we tell the customer about a request unless the law forbids it.
When hosting outside the 14 Eyes matters, and what matters more
The Eyes question answers one narrow threat: agencies collecting and sharing communications in bulk. It is worth weighing when both ends of your traffic are outside those countries, such as a Zürich site for Swiss readers or a
For a personal VPN, a
- The server's jurisdiction. Its courts decide what can be ordered about the data on it.
- The provider's jurisdiction. The company running the host answers to the courts of its own legal system, which may differ from the server's country. Ours is the operating entity described in our Terms of Service.
- The domain and any CDN. The .com registry is run by Verisign, a US operator, through which US authorities took over bodog.com in 2012, and a US CDN in front of your server brings US procedures back in.
- Encryption. TLS, SSH keys and a VPN tunnel protect content on any path.
- What the provider keeps. Data that was never collected cannot be handed over. Compare any host with our privacy policy and run the 12 checks in our guide to whether offshore hosting is safe.
Your own country's law keeps applying to you wherever the server runs, so check it before you rely on any location.
Frequently asked questions
What are the 14 Eyes countries?
The Five Eyes are the United States, the United Kingdom, Canada, Australia and New Zealand. Denmark, France, the Netherlands and Norway join them in the Nine Eyes, and Belgium, Germany, Italy, Spain and Sweden complete the 14 Eyes, which leaked NSA documents call SIGINT Seniors Europe.
Is Switzerland part of the 14 Eyes?
No. Switzerland is in none of the Five, Nine or 14 Eyes groups. That does not mean no cooperation or surveillance law: it is a party to the Budapest Convention on Cybercrime, its telecom providers keep metadata for six months, and data on a server in Zürich is requested under Swiss law.
Is the Netherlands in the 14 Eyes?
Yes. The Netherlands is in the Nine Eyes, and so in the 14 Eyes, but not the Five Eyes. Data on a server in Amsterdam is still reached through Dutch and EU procedures: court orders, criminal-procedure demands for data a provider already holds, and DSA orders. There has been no general data retention duty since 2015.
Does a VPS outside the 14 Eyes protect my privacy?
Partly. A
Which hosting countries are outside the 14 Eyes?
Every country not on the three lists. Among our locations, Iceland, Switzerland, Moldova, Romania, Bulgaria and Malaysia are outside the 14 Eyes. Romania and Bulgaria are EU members, so EU procedures such as the DSA apply there; the other four are outside the EU. Choose by where your users are and the legal profile you need.
Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions.


