VPN data collection practices in the industry are far murkier than marketing promises suggest. A TechRadar investigation into how 10 major VPN providers handle user data requests under GDPR exposed a troubling pattern: 90% of them failed to meet basic transparency and timeliness standards. The investigation prompted Surfshark to overhaul its data collection practices, specifically by ceasing to log malware-related information—a tangible privacy win in an industry that rarely delivers on its “no-logs” claims.
Key Takeaways
- TechRadar found 90% of 10 VPN providers failed to meet GDPR data request standards
- Surfshark responded to data requests within 4-24 hours, the fastest of all providers tested
- Surfshark’s logs revealed collection of financial data, subscription history, and antivirus malware detection records
- Following the investigation, Surfshark stopped logging malware-related data entirely
- NordVPN and TunnelBear provided no response within 30 days without additional prompts
What the Surfshark Investigation Revealed About VPN Data Collection
When TechRadar submitted Data Subject Access Requests (DSARs) to 10 VPN providers, Surfshark stood out—but not for the reasons it would want. While competitors dragged their feet or ignored requests entirely, Surfshark responded instantly with a detailed PDF report. That speed, however, revealed a problem: the company was collecting far more data than its privacy-first marketing suggested. The DSAR report showed Surfshark was logging financial signatures including Payer ID, payment email, amount paid, payment status, and coupon usage. Subscription history data—active, cancelled, and expired status with creation and expiry dates—was also stored centrally.
Most concerning was the antivirus malware logging. Surfshark maintained detailed records of specific malware names detected on user devices, the device used, and country-level location data at the time of detection. This directly contradicted the privacy model one would expect from a VPN provider. As TechRadar noted, in a truly privacy-centric service, this data should be wiped immediately after a session ends, not archived in a centralized database. The question became unavoidable: why does a VPN company need to store a history of every malware infection detected on a user’s device?
How VPN Providers Failed Transparency Standards Across the Board
The broader investigation painted a grim picture of industry accountability. NordVPN and TunnelBear provided no response to data requests within 30 days without explicit follow-up prompts. IPVanish delayed for more than 30 days before sending a minimal CSV file containing only the signup IP address. Seven other providers similarly failed to meet thorough and timely standards. Surfshark’s rapid, detailed response made it the clear winner on transparency—a distinction that simultaneously revealed why transparency matters so little in the VPN market. When one provider’s compliance effort exposes problematic data practices, transparency becomes a liability rather than an asset.
This pattern reflects a systemic problem in the VPN industry. Most providers operate in regulatory gray zones, banking on the assumption that users will never actually request their data. GDPR gives users the right to know what companies collect, but enforcement relies on individual requests. TechRadar’s investigation showed that most VPN providers treat these requests as inconveniences, not obligations. The few that respond do so grudgingly or minimally. Only Surfshark treated the request as an opportunity to demonstrate compliance—which inadvertently exposed the gap between its “no-logs” branding and its actual data collection practices.
The Malware Logging Problem and Surfshark’s Response
The malware logging revelation was the investigation’s most significant finding. Surfshark’s antivirus feature detects malware on user devices and logs those detections server-side. While the company framed this as a security feature, the practice raised fundamental privacy questions. A user employing a VPN specifically to protect their privacy would reasonably expect that data about malware infections on their device would not be centrally logged and retained. The infection information could reveal sensitive details about the user’s browsing habits, the websites they visited, and the security posture of their device—precisely the kind of behavioral data that VPN users seek to hide.
Following TechRadar’s investigation, Surfshark made the decision to stop logging malware-related data. This represents a concrete privacy improvement and acknowledges that the previous practice conflicted with user expectations. However, the fact that external pressure was required to change the policy raises questions about how thoroughly Surfshark had evaluated its data collection practices from a privacy perspective. The company still processes user data for service delivery, analytics, customer support, and legal compliance—standard practices, but practices nonetheless. Surfshark also uses limited personal information for automated decision-making on user behaviors, a capability that sits uneasily alongside its privacy-first positioning.
Why This Matters for VPN Users Globally
The investigation exposed a fundamental tension in the VPN industry. Providers market themselves as privacy champions while simultaneously collecting data that contradicts those claims. Surfshark’s case is particularly instructive because the company did respond to transparency requests—it simply revealed uncomfortable truths about what it was collecting. Other providers avoided this problem by ignoring requests entirely, a strategy that worked precisely because most users never submit them. For users relying on VPNs to protect their privacy, the lesson is clear: transparency requirements exist, but they are rarely enforced, and when they are, the results are often disappointing. The malware logging practice, now discontinued, exemplified how privacy-oriented companies can drift into practices that undermine their core value proposition without anyone noticing. Surfshark’s response to the investigation demonstrates that pressure works, but it should not be necessary. A truly privacy-first company would audit its own data collection practices proactively rather than waiting for external investigations to expose problems.
Does Surfshark still collect user data after the changes?
Yes. Surfshark continues to collect financial data (payment information, subscription status), subscription history, and behavioral data for analytics and customer support purposes. The change was specifically to stop logging malware-related information. The company processes this remaining data for service delivery, legal compliance, and automated decision-making on user behaviors.
How did TechRadar’s investigation change the VPN industry?
The investigation exposed that 90% of major VPN providers failed to meet GDPR transparency standards. Surfshark’s response prompted it to eliminate malware logging, setting a precedent for privacy-focused practices. However, the broader industry response was minimal—most providers continued ignoring or minimizing data requests.
Why is VPN data collection a privacy concern?
VPN data collection becomes problematic when it reveals behavioral patterns, device security details, or subscription choices that users expect to remain private. Centralized logging of malware detections, for example, could expose which websites a user visited before infection. The core issue is that detailed data collection contradicts the privacy-first positioning that VPN providers use in marketing.
The TechRadar investigation proved that privacy in the VPN industry is not a feature—it is a promise that most providers fail to keep. Surfshark’s decision to stop logging malware data shows that accountability works, but only when users have tools to demand it. For the broader market, the real question remains: how many other data collection practices exist that no one has investigated yet?
Edited by the All Things Geek team.
Source: TechRadar


