VPN logging policies: what data collection is actually necessary

Craig Nash
By
Craig Nash
Tech writer at All Things Geek. Covers artificial intelligence, semiconductors, and computing hardware.
9 Min Read
VPN logging policies: what data collection is actually necessary

VPN logging policies determine whether your VPN provider can actually track your activity—or whether they’re genuinely protecting you. The difference between a legitimate operational log and invasive surveillance is where the real privacy battle happens, and most users have no idea what their VPN is actually collecting.

Key Takeaways

  • No-log policies are the gold standard but require providers in privacy-friendly jurisdictions to be meaningful.
  • OpenVPN retains minimal session data (IPs, connection times, bytes) for 14-30 days for billing and security, not traffic content.
  • Five Eyes countries have data retention laws that can compel VPN logging despite no-log claims.
  • A 2019 analysis of 100+ VPN policies found 51% log bandwidth, 49% log timestamps, 40% log original IP addresses.
  • Usage logs (browsing history, DNS queries) are far more invasive than connection logs (times, servers, data transferred).

What VPNs Actually Need to Collect

VPNs are not legally required to keep logs that could identify or track users. Yet some data collection is genuinely necessary for basic service operation. OpenVPN Private Tunnel, for example, retains minimal session information: your source IP address, the IP address assigned to you, connection times, and total bytes transferred. This data is kept for only 14 to 30 days and serves specific purposes—billing, troubleshooting, terms-of-service enforcement, and preventing abuse. Critically, OpenVPN does not store traffic content, perform deep packet inspection, or throttle based on activity.

This represents the bare minimum a VPN legitimately needs to function. Connection logs differ fundamentally from usage logs. Connection logs record when you connected, which server you used, and how much data transferred. Usage logs—the invasive stuff—record what websites you visited, which DNS queries you made, your browsing timestamps, and bandwidth per application. If your VPN is collecting usage logs, it is collecting your actual activity, and that is a red flag.

The Logging Landscape: What Providers Actually Collect

Reality diverges sharply from marketing claims. A comprehensive analysis of over 100 VPN privacy policies conducted in 2019 revealed widespread data collection: 51% of providers log bandwidth usage, 49% log connection timestamps, 40% log your original IP address, and 19% log websites you visit. Many of these providers collect this data for bandwidth management, data sales to third parties, or legal compliance—not operational necessity.

Perimeter 81 operates under a strict no-logs policy, recording neither user activities, connections, nor transmitted data. Private Internet Access (PIA) has proven its no-log claims in court despite operating in the United States, a Five Eyes jurisdiction—the company handed over no usable information to law enforcement. These exceptions exist, but they require deliberate architectural choices and transparent policies.

Other providers are far less scrupulous. Hotspot VPN logs webpage addresses and data fields, potentially sharing non-personally identifiable information with third parties. AVG VPN stores VPN data for 2 to 3 months on its servers. VPN In Touch shares aggregated logs with third-party hosting and analytics providers. These are not edge cases—they represent standard industry practice for many commercial VPN operators.

Why Jurisdiction Matters More Than Policy Promises

A no-log policy is only as strong as the jurisdiction that enforces it. Countries in the Five Eyes alliance—the United States, United Kingdom, Canada, Australia, and New Zealand—have data retention laws that can legally compel VPN providers to log user activity. A provider claiming zero-logs while operating under Five Eyes jurisdiction faces a fundamental contradiction: if a government demands logs, the provider must either comply or face prosecution.

Transparency in logging policies is essential. Reputable providers should detail exactly what data is collected, why it is collected, how long it is retained, and what procedures exist for handling legal requests. This transparency allows users to make informed decisions. A provider in a privacy-friendly jurisdiction with a published no-log policy and a clear legal framework is more trustworthy than one making vague promises from a surveillance-friendly country.

Data retention laws themselves undermine privacy even for providers with genuine no-log intentions. Many countries mandate storing user activity logs for fixed periods, forcing VPN operators to choose between compliance and privacy. This is why jurisdiction selection matters as much as the policy itself.

No-Log vs. Minimal-Log: Understanding the Difference

No-log policies mean no storage of data passing through VPN servers—not even encrypted traffic metadata. This is the gold standard and protects users even from subpoenas or server breaches. Minimal-log policies, like OpenVPN’s approach, retain specific session data for defined periods and specific purposes.

The distinction matters. A provider retaining your source IP, assigned IP, connection times, and bytes transferred for 30 days is not the same as one logging every website you visit for six months. One is operationally justified; the other is surveillance. Neither approach is wrong in isolation, but users must understand what they are accepting.

Red Flags in VPN Logging Policies

Avoid providers collecting usage logs—your online activities, browsing history, and DNS queries. These are intrusive by design and rarely necessary for VPN operation. Be skeptical of providers making broad no-log claims without independent audits or court-verified proof. Many providers claim zero-logs while actually logging for bandwidth limits, data sales, or legal compliance.

Providers in high-retention jurisdictions without proven non-compliance records are higher risk. If a VPN operates in a Five Eyes country and has no history of resisting government requests, assume it will comply with logging demands when pressured.

What Should You Actually Look For?

Prioritize providers with transparent, detailed logging policies that specify what data is collected, why, retention periods, and legal request procedures. Verify the provider’s jurisdiction—prefer operators in privacy-friendly countries with strong data protection laws. Look for independent audits or court cases proving the provider’s claims.

No-log policies from providers outside Five Eyes jurisdictions are stronger than no-log claims from US or UK operators, though court-proven providers like PIA demonstrate that jurisdiction is not destiny. Read the actual policy, not the marketing language. A provider admitting to minimal session logging for legitimate purposes is often more trustworthy than one making absolute zero-log claims without specifics.

FAQ

Do VPNs have to keep logs?

VPNs are not legally required to keep logs that could identify or track users. However, some data retention is operationally useful for billing, troubleshooting, and abuse prevention. The legal requirement depends on jurisdiction—Five Eyes countries have data retention mandates that can compel logging.

What is the difference between no-log and minimal-log policies?

No-log policies mean zero storage of any data passing through VPN servers, protecting users even from subpoenas. Minimal-log policies retain specific session data like connection times and bytes transferred for defined periods and purposes, as OpenVPN does. No-log is stronger privacy, but minimal-log can be operationally justified.

Which VPN providers have the best logging policies?

Perimeter 81 operates under a strict no-logs policy, and Private Internet Access has proven its no-log claims in court despite US jurisdiction. OpenVPN retains only essential session data for 14-30 days. Always verify a provider’s jurisdiction and check for independent audits or court records confirming their claims.

Your VPN’s logging policy is not a marketing detail—it is the core of what you are paying for. Understand what your provider collects, why, and where it operates. A transparent provider admitting to minimal operational logging is far more trustworthy than one making sweeping privacy claims without specifics. In 2025, as surveillance intensifies globally, the difference between a genuine no-log VPN and one that merely claims privacy could determine whether your activity remains private or becomes a data asset.

Edited by the All Things Geek team.

Source: TechRadar

Share This Article
Tech writer at All Things Geek. Covers artificial intelligence, semiconductors, and computing hardware.