---
title: "5, 9 & 14 Eyes Countries: What They Mean for Hosting"
description: "The Five, Nine and 14 Eyes countries listed, what these intelligence alliances do and do not mean for a server, and which hosting countries are outside."
url: https://offshoreserv.com/blog/14-eyes-countries-hosting
lang: en
updated: 2026-09-26
source: HTML page at the url above (canonical); this is its Markdown version
---

[Law & jurisdictions](https://offshoreserv.com/blog/category/law-jurisdictions)

# 5, 9 and 14 Eyes countries: what they mean for hosting

Which countries are in the Five, Nine and 14 Eyes, what is official and what was leaked, and what membership really means for a server in each of our seven locations.

26 September 2026 8 min read By the OffshoreServ team

Key takeaways

- The Five Eyes rest on the 1946 UKUSA agreement, officially acknowledged in 2010; the Nine and 14 Eyes are known from leaked NSA documents.
- Stored data is reached through local courts, mutual legal assistance and, in the EU, EU instruments, not through the alliances.
- Encryption hides content on any network path, but not metadata.

**The 14 Eyes countries** are the Five Eyes (the United States, the United Kingdom, Canada, Australia and New Zealand), plus Denmark, France, the Netherlands and Norway, which make the Nine Eyes, plus Belgium, Germany, Italy, Spain and Sweden. For a server, membership concerns how spy agencies share intercepted communications, not who can legally obtain its data.

Of our seven locations, only the Netherlands is on these lists; Iceland, Switzerland, Moldova, Romania, Bulgaria and Malaysia are in none. This guide separates what is official from what was leaked, explains what the alliances can and cannot do to a hosted server, and shows when the question should shape your choice of an [offshore VPS](https://offshoreserv.com/offshore-vps) location among our [seven jurisdictions](https://offshoreserv.com/locations).

## Who are the 14 Eyes countries?

The groups are nested: each contains the smaller ones, and sharing is closest at the core.

| Group | Countries | Evidence |
| --- | --- | --- |
| Five Eyes | United States, United Kingdom, Canada, Australia, New Zealand | UKUSA agreement, officially acknowledged in 2010 |
| Nine Eyes | The Five Eyes plus Denmark, France, the Netherlands, Norway | Leaked NSA documents (2013) |
| 14 Eyes | The Nine Eyes plus Belgium, Germany, Italy, Spain, Sweden | Leaked NSA documents (2013, 2018) |

### Five Eyes countries and the UKUSA agreement

The Five Eyes began as a signals intelligence pact between Britain and the United States, signed on 5 March 1946 as BRUSA and later called UKUSA: the two agreed to exchange what they learned from intercepting, decoding and translating foreign communications. It was extended to Canada in 1948 and to Australia and New Zealand in 1956. Its text was released only in June 2010, through the UK National Archives after freedom-of-information requests in Britain and the United States, which made it officially acknowledged for the first time ([the Guardian](https://www.theguardian.com/world/2010/jun/25/intelligence-deal-uk-us-released)).

### Nine Eyes and 14 Eyes: SIGINT Seniors Europe

The wider groups are known from leaks, not from a published treaty. In November 2013 the Guardian, drawing on NSA documents leaked by Edward Snowden, described the five as sharing raw intelligence, funding, technical systems and personnel, and named wider coalitions with "more restricted" sharing: a "9-Eyes" that adds Denmark, France, the Netherlands and Norway, and a "14-Eyes" that adds Germany, Belgium, Italy, Spain and Sweden ([the Guardian](https://www.theguardian.com/world/2013/nov/02/nsa-portrait-total-surveillance)).

In 2018 the Intercept published NSA newsletters from the same files that name the 14-member group SIGINT Seniors Europe. Formed in 1982 with nine members focused on the Soviet military, it grew to 14 after the September 2001 attacks and turned to counterterrorism. Its members as of April 2013 match the list above, and the NSA sometimes called it the "14 Eyes" ([The Intercept](https://theintercept.com/2018/03/01/nsa-global-surveillance-sigint-seniors/)). Membership may have changed since.

### The labels are shorthand

Three lists do not capture every relationship. The Guardian also mentioned a "41-Eyes" that adds others in the allied coalition in Afghanistan, and the Intercept described SIGINT Seniors Pacific: the Five Eyes, South Korea, Singapore and Thailand, joined by France and India by 2013. Malaysia is not among the members named.

## Our seven locations and the 14 Eyes countries

Only one of our locations is on any list. The legal notes come from our location pages.

| Location | 5 / 9 / 14 Eyes | EU member | Legal note |
| --- | --- | --- | --- |
| [Iceland](https://offshoreserv.com/locations/iceland) (Reykjavík) | None | No (EEA member) | Telecom undertakings keep minimal traffic records for six months |
| [Switzerland](https://offshoreserv.com/locations/switzerland) (Zürich) | None | No | Telecom providers keep metadata for six months; a paused ordinance revision would widen identification duties |
| Moldova (Chișinău) | None | No (candidate) | Providers store traffic data for 180 days; preservation can be ordered for foreign authorities |
| Romania (Bucharest) | None | Yes | General retention struck down in 2009 and 2014; telecom operators may keep billing traffic data up to three years |
| [Netherlands](https://offshoreserv.com/locations/netherlands) (Amsterdam) | Nine and 14 Eyes | Yes | No general retention duty since a 2015 court ruling; investigators can demand data a provider holds |
| Bulgaria (Sofia) | None | Yes | Retention law annulled in 2015; the EU Court of Justice ruled out general and indiscriminate retention in 2022 |
| Malaysia (Kuala Lumpur) | None | No | No general retention period for hosts; police and regulators can compel disclosure of data a provider holds |

Amsterdam is a 14 Eyes VPS location, yet the Netherlands has had no general retention duty since 2015, while Iceland and Switzerland, on no list, require telecom providers to keep six months of traffic records. Wherever the server runs, we do not log or inspect its traffic.

## What the Eyes alliances mean for a hosted server

### Intelligence sharing is not a legal request for data

The alliances concern signals intelligence: agencies intercepting communications and sharing what they collect. They are not a legal channel to the files on a particular server. Stored data is normally obtained through the courts and competent authorities of the server's country; a foreign authority typically sends a request under a mutual legal assistance treaty (MLAT), which that country examines under its own law. In the EU, instruments such as the Digital Services Act add their own orders.

Our [law enforcement guidelines](https://offshoreserv.com/law-enforcement) apply this in all seven locations. A request can only return what we hold: an email address, payment and service records, and sign-in sessions that record the browser and country, never an IP address. We keep no traffic logs, as our [privacy policy](https://offshoreserv.com/privacy-policy) explains.

### Interception happens on the network path

Eavesdropping works on traffic in transit, so where your traffic goes matters as much as where the server sits. In 2013 the Guardian reported, from Snowden's documents, that GCHQ had attached probes to transatlantic fiber-optic cables where they land in Britain; its Tempora program could store content for three days and metadata for 30 days, and was shared with the NSA ([the Guardian](https://www.theguardian.com/uk/2013/jun/21/gchq-cables-secret-world-communications-nsa)).

A server outside the 14 Eyes does not keep its traffic outside them. If your users are in the UK or the US, every connection crosses those countries' networks. From Reykjavík, traffic to continental Europe passes through Scotland (in the UK), Ireland or Denmark first, and only Ireland is on none of the lists. From Zürich, traffic to Frankfurt, Milan, Paris or Amsterdam enters Germany, Italy, France or the Netherlands, all 14 Eyes countries.

### Encryption hides content, not metadata

TLS (HTTPS), SSH and WireGuard encrypt what travels between you and your server, so an interceptor cannot read it. They do not hide who talks to whom: the network needs the IP addresses at both ends to deliver each packet, and timing and volume stay visible. The IETF lists IP addresses in packet headers among the channels adversaries have used to monitor web services, and notes that standard TLS sends the site's name in cleartext when a connection opens ([RFC 8744](https://www.rfc-editor.org/rfc/rfc8744)). WireGuard "does not focus on obfuscation" either ([WireGuard](https://www.wireguard.com/known-limitations/)). Tempora could keep metadata ten times longer than content, and as the EFF puts it, "even a tiny sample of metadata can provide an intimate lens into a person's life" ([EFF](https://ssd.eff.org/module/why-metadata-matters)).

## Outside the Eyes lists is not outside cooperation

Countries missing from the lists still cooperate with other states, and the channels that reach stored data are legal ones. All six of our European locations have them:

- **The Budapest Convention.** Iceland, Switzerland, Moldova, Romania, the Netherlands and Bulgaria are parties to the Council of Europe's Convention on Cybercrime, which organizes cross-border data preservation and mutual assistance, as our [jurisdictions comparison](https://offshoreserv.com/blog/offshore-hosting-jurisdictions-compared) notes.
- **EU instruments.** In Romania, the Netherlands and Bulgaria, courts and competent authorities can issue DSA orders on specific content or for information, and terrorist content can be ordered offline within one hour.
- **Foreign preservation requests.** In Moldova, the Interior Ministry can order immediate preservation of data at the request of foreign authorities.

In all seven locations, Malaysia included, we act only on requests from an authority competent where the server runs, so a foreign authority goes through mutual legal assistance, and we tell the customer about a request unless the law forbids it.

## When hosting outside the 14 Eyes matters, and what matters more

The Eyes question answers one narrow threat: agencies collecting and sharing communications in bulk. It is worth weighing when both ends of your traffic are outside those countries, such as a Zürich site for Swiss readers or a Kuala Lumpur service for Malaysian users, where domestic traffic can be exchanged at SwissIX or MyIX. It matters less when your users are in the 14 Eyes, and it never decides who can obtain a court order.

For a personal VPN, a non-14 Eyes exit keeps the networks right after the tunnel outside those countries, though not a destination site hosted in one of them; our guide to an [offshore VPS for a personal VPN](https://offshoreserv.com/blog/offshore-vps-for-vpn) covers the other trade-offs. Before the lists, check these:

1. **The server's jurisdiction.** Its courts decide what can be ordered about the data on it.
2. **The provider's jurisdiction.** The company running the host answers to the courts of its own legal system, which may differ from the server's country. Ours is the operating entity described in our [Terms of Service](https://offshoreserv.com/terms).
3. **The domain and any CDN.** The.com registry is run by Verisign, a US operator, through which US authorities took over bodog.com in 2012, and a US CDN in front of your server brings US procedures back in.
4. **Encryption.** TLS, SSH keys and a VPN tunnel protect content on any path.
5. **What the provider keeps.** Data that was never collected cannot be handed over. Compare any host with [our privacy policy](https://offshoreserv.com/privacy-policy) and run the 12 checks in our guide to [whether offshore hosting is safe](https://offshoreserv.com/blog/is-offshore-hosting-safe).

Your own country's law keeps applying to you wherever the server runs, so check it before you rely on any location.

## Frequently asked questions

### What are the 14 Eyes countries?

The Five Eyes are the United States, the United Kingdom, Canada, Australia and New Zealand. Denmark, France, the Netherlands and Norway join them in the Nine Eyes, and Belgium, Germany, Italy, Spain and Sweden complete the 14 Eyes, which leaked NSA documents call SIGINT Seniors Europe.

### Is Switzerland part of the 14 Eyes?

No. Switzerland is in none of the Five, Nine or 14 Eyes groups. That does not mean no cooperation or surveillance law: it is a party to the Budapest Convention on Cybercrime, its telecom providers keep metadata for six months, and data on a server in Zürich is requested under Swiss law.

### Is the Netherlands in the 14 Eyes?

Yes. The Netherlands is in the Nine Eyes, and so in the 14 Eyes, but not the Five Eyes. Data on a server in Amsterdam is still reached through Dutch and EU procedures: court orders, criminal-procedure demands for data a provider already holds, and DSA orders. There has been no general data retention duty since 2015.

### Does a VPS outside the 14 Eyes protect my privacy?

Partly. A non-14 Eyes VPS keeps the server in a country outside those alliances, but traffic to users in member countries still crosses their networks, and metadata stays visible under encryption. Encryption, what the provider stores and how you pay matter more. We keep no traffic logs and never record the IP address you connect from.

### Which hosting countries are outside the 14 Eyes?

Every country not on the three lists. Among our locations, Iceland, Switzerland, Moldova, Romania, Bulgaria and Malaysia are outside the 14 Eyes. Romania and Bulgaria are EU members, so EU procedures such as the DSA apply there; the other four are outside the EU. Choose by where your users are and the legal profile you need.

**Host it where the law is on your side.**

Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions. No KYC, paid in crypto.

## More from the blog.

- [Law & jurisdictions The EU Digital Services Act: what it means for hosting The EU's Digital Services Act sets the rules for hosting providers in every member state. What it requires, article by article, how it compares with the US DMCA and where it applies to our servers.26 September 2026 9 min read](https://offshoreserv.com/blog/digital-services-act-hosting)
- [Law & jurisdictions DMCA-ignored countries in 2026: what "ignored" really means The DMCA stops at the US border, so every other country ignores it in a sense. Here is what decides takedowns instead, country by country, and what still reaches a server anywhere.26 September 2026 10 min read](https://offshoreserv.com/blog/dmca-ignored-countries)
- [Law & jurisdictions DMCA-ignored hosting explained: what it means in 2026 US takedown notices have no legal force outside the United States, but DMCA-ignored does not mean copyright law stops applying. Here is what the label really covers in 2026.26 September 2026 9 min read](https://offshoreserv.com/blog/dmca-ignored-hosting-explained)

---

OffshoreServ is an offshore hosting provider: VPS, dedicated servers, Windows RDP and GPU servers in seven jurisdictions (Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria and Malaysia), paid only in cryptocurrency (Bitcoin, Ethereum, Monero, Tether (USDT) and Solana), with no identity checks (no KYC).

Prices and plans: https://offshoreserv.com/pricing · Answers: https://offshoreserv.com/faq · Every page: https://offshoreserv.com/llms.txt
