Proton VPN refused all 47 court orders to unmask users - here is why

21.07.2026 11
Proton VPN refused all 47 court orders to unmask users - here is why

Proton VPN has published its transparency report for the first half of 2026, and the headline number is a powerful advertisement for the no-logs model: of 47 legally binding orders demanding it identify VPN users, the company handed over data in exactly zero of them. Not because it fought and won 47 court battles, but because there was nothing to give. This is what a genuine no-logs policy looks like when it meets a real court order.

What the report says

In the report, updated on 14 July 2026, Proton disclosed that it received 47 data requests in the first half of the year. Every one came from Swiss authorities and was approved through the Swiss legal system, and every one sought the same thing: the identity of whoever was connected to a specific Proton VPN server at a specific moment in time. Proton complied with none of them. As the company puts it, "our strict no-logs policy means we don't store the information in the first place" - so even a valid Swiss order returns nothing, because the connection data simply does not exist.

458 orders, zero disclosures

The 47 figure is not a one-off. Since 2017, Proton says it has received 458 legally binding orders and has never once been able to identify a VPN user, for the same reason each time. That track record matters far more than any marketing claim, because it has been stress-tested by real law enforcement demands over nearly a decade. It was also backed up in May 2026 by an independent audit from the security firm Securitum, which confirmed the service operates in line with its stated no-logs commitments.

Why "no-logs" only counts if it is real

The reason this is worth reporting is that not every "no-logs" claim survives contact with an investigator. We have covered the opposite case - a VPN whose servers were seized and its users deanonymised because, despite the marketing, it was quietly keeping records. The lesson from both stories is the same: a no-logs policy is only as good as its architecture. If the data is never written to disk, there is nothing to seize, subpoena or leak. If it is, the promise is one court order away from breaking.

The Swiss context

Proton's ability to refuse rests partly on Swiss law, which does not force VPNs to retain connection logs and prohibits it from answering foreign requests that bypass Swiss courts. That advantage is not guaranteed forever - we recently reported on a proposed Swiss surveillance reform that pushed Proton to start moving infrastructure abroad. For now, though, the jurisdiction and the no-logs design are working exactly as intended, and this report is the proof.

What it means for you

If you are choosing a VPN for privacy, this is the kind of evidence to look for: independent audits, a privacy-friendly jurisdiction, and ideally a public record of orders that produced nothing. Those are the criteria behind our roundup of the best no-logs VPNs. And if you want to remove trust from the equation entirely, the only party who can never log you is one you control - your own server. Either way, the takeaway from Proton's report is simple: verifiable beats promised.

Conclusion: Proton's 47-for-47 refusal is not a legal victory so much as an engineering one. A VPN that keeps no connection logs has nothing to surrender, whoever asks. That is the whole point of no-logs - and it only holds when the data was never collected in the first place.
Tags: proton vpn no-logs transparency report switzerland privacy

Read also