Few phrases circulate as widely in privacy and VPN discussions as “5 9 14 eyes countries,” yet many people repeating the warning couldn’t name a single member nation or explain what the alliance actually does. That gap matters, because the decisions made inside this intelligence network shape how much of your personal data governments can legally access, regardless of which country you live in.
The alliance did not appear overnight. It grew out of a World War II era intelligence pact between the United States and the United Kingdom, then expanded in stages as more nations agreed to share signals intelligence, or SIGINT, with one another. Today it spans three overlapping tiers, five countries at the core, nine in the middle ring, and fourteen at the outer edge, each layer adding surveillance capacity and data-sharing reach.
Understanding the 5 9 14 eyes countries is no longer a niche concern for security researchers. It affects which VPN providers can credibly promise a no-logs policy, which messaging apps can resist government subpoenas, and which email services can keep your inbox out of reach of foreign intelligence requests. Below is a complete breakdown of every member nation, the laws that empower their surveillance agencies, and practical steps you can take if you want to reduce your exposure.
What Is the Five Eyes Alliance
The Five Eyes alliance is the founding core of the broader 5 9 14 eyes countries network. It consists of the United States, the United Kingdom, Canada, Australia, and New Zealand.
The partnership traces back to the UKUSA Agreement, signed in the aftermath of the Second World War, when Washington and London formalized a signals intelligence collaboration originally aimed at monitoring the Soviet Union and its allies. Canada joined the arrangement early, cementing what remains one of the closest intelligence relationships among any of the alliance members. Australia and New Zealand rounded out the group, though their involvement stayed out of public view for years and drew criticism once it became widely known.
United States
The National Security Agency leads American signals intelligence collection. Under the PATRIOT Act, US agencies have broad authority to gather data, including emails and call records tied to American citizens, when the government deems it necessary for national security purposes.
United Kingdom
The Government Communications Headquarters, commonly known as GCHQ, is Britain’s primary surveillance agency. The Investigatory Powers Act allows the government to collect internet records and compel internet service providers to retain and hand over user browsing logs. The UK is frequently described alongside the United States as one of the two dominant voices within the wider fourteen eyes structure.
Canada
The Communications Security Establishment operates under the Anti-Terrorism Act, which permits the agency to collect and use information from global communications infrastructure for intelligence purposes. Canada’s intelligence sharing with the US and UK is especially close, a relationship that has drawn scrutiny domestically. Canadian judges have previously raised concerns after it emerged that Canadian authorities asked allied Five Eyes nations to gather intelligence on Canadian citizens, a workaround that sidesteps direct domestic surveillance restrictions.
New Zealand
The Government Communications Security Bureau carries out New Zealand’s surveillance activity under the Intelligence and Security Act 2017, which gives the agency wide latitude to collect and analyze large volumes of data. New Zealand’s Five Eyes membership was not always public knowledge, and disclosure of the arrangement sparked domestic debate. Foreign Minister Winston Peters has since indicated an intent to strengthen the country’s ties within the alliance.
Australia
The Australian Signals Directorate operates under the Telecommunications Interception and Access Act, which authorizes intelligence agencies to intercept and access stored communications when a warrant is obtained. As with New Zealand, public disclosure of Australia’s role prompted debate over the scope of the country’s surveillance powers.
What Is the Nine Eyes Alliance
The nine eyes tier extends the Five Eyes core by adding the Netherlands, France, Denmark, and Norway. The precise formation date of this expanded group is not publicly documented, and it remains far less discussed than either the five eyes or fourteen eyes tiers, despite involving four additional nations with substantial intelligence capacity.
The nine eyes grouping came into public focus in 2013 following disclosures by former NSA contractor Edward Snowden. While the nine eyes arrangement was not the central focus of those disclosures, the leaks brought broader public attention to the existence of multinational surveillance partnerships operating largely outside public oversight.
Netherlands
The General Intelligence and Security Service, known by the Dutch acronym AIVD, operates under the Intelligence and Security Services Act 2017. The law permits interception of communications, decryption of files, and network intrusion into third-party systems at the agency’s discretion.
France
The Directorate General for Internal Security carries out surveillance activity under the French Intelligence Act of 2015. The law authorizes telephone tapping, internet wiretaps, metadata access, and exploitation of computer networks for intelligence purposes.
Denmark
The Danish Defence Intelligence Service operates in the context of the European Union’s Directive on Data Retention, which requires telecom and internet providers across member states to log user data, including IP addresses, for potential government access.
Norway
The Norwegian Intelligence Service functions under the Norwegian Intelligence Service Act 2020, which permits the agency to gather information through third parties and share it through bilateral and multilateral intelligence partnerships. Norway has consistently supported the broader SIGINT collaboration that underpins the alliance.
What Is the Fourteen Eyes Alliance
The fourteen eyes tier represents the full extent of the alliance, combining the five eyes and nine eyes members with Germany, Belgium, Italy, Spain, and Sweden. This fourteen-nation coalition gives the network its widest reach, enabling signals intelligence sharing across a broader swath of Europe than either of the smaller tiers.
Germany
Germany’s Federal Intelligence Service, known as the BND, operates under provisions that allow access to information held by foreign service providers, including through covert server infiltration, along with authority to decrypt encrypted communications. Germany is regarded as one of the more influential contributors to the fourteen eyes framework given its intelligence infrastructure and standing among European partners.
Belgium
Belgium’s State Security Service, the VSSE, previously operated under a Data Retention Act requiring telecom and internet providers to retain user activity logs. Belgium’s Constitutional Court annulled that law in 2021 after determining it did not comply with exceptions set out by the Court of Justice of the European Union regarding data storage. How that ruling affects Belgium’s ongoing role within the alliance has not been made public.
Italy
Italy’s Intelligence and Security Services, AISE, operate under national anti-terrorism law provisions permitting wiretaps and intelligence sharing for national security purposes. Limited public information exists regarding the specifics of Italy’s day-to-day contributions to the alliance.
Spain
Spain’s National Intelligence Centre, the CNI, works under the country’s Data Retention Law, which allows access to user logs maintained by internet and telecom providers. Spain’s operational role within the fourteen eyes structure is less publicly documented than that of the US or UK.
Sweden
Sweden’s Military Intelligence and Security Service, MUST, operates under the country’s Data Collection Act, which authorizes the Swedish Security Service to obtain data logs from providers and decrypt electronic communications. Public information about Sweden’s specific activities within the alliance remains limited.
Why the 5 9 14 Eyes Countries Matter for VPN Users
For VPN users, the practical significance of the 5 9 14 eyes countries comes down to jurisdiction. A VPN provider headquartered in any member nation can be legally compelled to retain user logs, hand over stored data, or cooperate with government requests, even if the company’s marketing promises otherwise.
How Legal Jurisdiction Undermines No-Logs Claims
A no-logs policy is only as strong as the laws governing the company that makes the promise. If a VPN provider is based in one of these fourteen countries, authorities can, under specific legal circumstances, compel that company to begin retaining user data it previously did not collect. This has happened before. Proton, the Switzerland-based provider best known for encrypted email, faced a legal case that illustrated how government requests can pressure even privacy-focused companies operating adjacent to alliance jurisdictions.
The Data-Sharing Workaround
One of the more consequential aspects of the alliance is that member countries can ask one another to conduct surveillance on each other’s citizens, sidestepping domestic constitutional protections. A government barred from monitoring its own citizens directly can request that an allied nation, unconstrained by the first country’s constitution, carry out that monitoring instead and share the results. Canadian courts have previously raised concerns about this exact practice involving Canadian citizens.
What Data the Alliance Can Access
Collectively, member agencies have the legal authority and technical capacity to gather a wide range of information, including internet browsing activity, IP addresses, personally identifiable information, location data, financial transaction records, biometric data, and the content of calls, texts, and emails, depending on each country’s specific laws and the warrants or directives in place.
How to Reduce Your Exposure to the 14 Eyes Alliance
While no individual can fully opt out of a global intelligence framework, several practical steps can meaningfully reduce your digital footprint within alliance jurisdictions.
Choose Privacy-Focused Browsers and Search Tools
Mainstream browsers and search engines tied to major US tech companies collect substantial user data by default. Privacy-oriented alternatives such as Firefox, Brave, and LibreWolf for browsing, and DuckDuckGo, Startpage, or Searx for search, reduce the volume of data collected during everyday use, though some trade a degree of search accuracy or speed for that added privacy.
Use an Encrypted, Non-US Email Provider
Standard webmail services are not end-to-end encrypted and are based in the United States, placing them squarely within Five Eyes jurisdiction. ProtonMail, based in Switzerland, applies end-to-end encryption and operates outside the fourteen eyes framework entirely, offering both free and premium tiers with identical encryption standards.
Pick a VPN Provider Outside the Alliance
Jurisdiction matters as much as technology when choosing a VPN. Providers headquartered outside the 5 9 14 eyes countries, such as NordVPN, based in Panama, along with ExpressVPN and ProtonVPN, are not subject to the same legal compulsion that alliance-based providers face. Surfshark, based in the Netherlands and therefore within the nine eyes tier, is a notable exception, having undergone independent audits confirming its no-logs practices despite its jurisdiction.
Rely on Genuinely Private Messaging Apps
Not all end-to-end encrypted apps offer equal protection. WhatsApp and Facebook Messenger are both encrypted but are based in the United States and share data across the broader Meta ecosystem. Signal, by contrast, retains almost no user data beyond account creation and last-login timestamps. When the FBI previously subpoenaed Signal’s parent organization for information on specific users, the company could only provide account creation and last-connection dates, since no other data existed to hand over.
Limit Unnecessary Exposure of Personal Information
Reducing your digital footprint also means limiting how much personal information you generate in the first place. Using alias email addresses for non-essential accounts, minimizing social media exposure, and avoiding unnecessary data-sharing permissions all reduce the volume of information available to any government agency, regardless of jurisdiction.
Quick Reference Table
| Tier | Countries Added | Total Members |
|---|---|---|
| 5 Eyes | US, UK, Canada, Australia, New Zealand | 5 |
| 9 Eyes | + Netherlands, France, Denmark, Norway | 9 |
| 14 Eyes | + Germany, Belgium, Italy, Spain, Sweden | 14 |
The Bottom Line
The 5 9 14 eyes countries form the backbone of the world’s most extensive government intelligence-sharing network, and their reach extends well beyond national borders through the companies and services headquartered within their jurisdictions. Whether or not you live in a member nation, the email provider, VPN, or messaging app you choose may still fall under alliance oversight. Understanding which tier a company’s home country belongs to, and choosing services headquartered outside all three tiers where possible, remains the most direct way to limit exposure to this surveillance network.



