Proton VPN Rejects All 47 Data Requests Targeting Users in 2026

Proton VPN rejected all 47 legally binding data requests in the first half of 2026, citing its no-logs policy.

By Central
The 47 rejected requests mark the latest demonstration of Proton VPN's no-logs policy in action.
Highlights
  • Proton VPN rejected all 47 data requests in H1 2026, continuing its streak of no data disclosures since 2017.
  • The no-logs policy is enforced by system design, making it impossible to identify users even under legal pressure.
  • Swiss jurisdiction adds an extra layer of protection, as foreign governments must go through Swiss legal process.

Proton has disclosed that it rejected all 47 legally binding requests for user data received during the first half of 2026, citing its strict no-logs policy as the reason no information could be provided to authorities. The disclosure, published in an updated transparency report on July 14, 2026, marks the latest demonstration of how a rigorously enforced no-logs architecture can render even court-approved data demands effectively moot.

Proton VPN Rejects All 47 Data Requests in First Half of 2026

The transparency report shows that each of the 47 requests sought to identify which user was connected to a specific Proton VPN server at a particular moment. Proton confirmed that all requests originated from Swiss authorities and had been approved through the Swiss legal system. In every case, the company responded that it could not comply because Proton VPN does not collect or retain connection logs, making it impossible to determine which user was assigned to a given server at any specific time.

Proton stated that it engages only with requests from Swiss authorities when legally obligated to do so and cannot disclose the nature or specifics of individual requests. The company noted that it is legally prohibited from responding directly to foreign government requests that have not first gone through the Swiss legal process.

How Proton VPN’s No-Logs Policy Prevents Data Disclosure

The core mechanism that rendered these requests unsuccessful is Proton VPN’s no-logs policy, which means the service does not store connection timestamps, IP addresses, browsing activity, or session metadata. When authorities demand information about which user was connected to a server at a given time, the provider simply has no data to produce. A Proton spokesperson stated that since 2017, the service has received 458 legally binding orders approved by Swiss authorities, and in every case, no user data was handed over.

This approach relies on system design rather than policy alone: the infrastructure is built so that the data required to identify users by connection time is never recorded or retained. This design choice is what allows Proton to state unequivocally that it cannot share what it does not possess.

Because Proton is headquartered in Switzerland, it operates under Swiss law and responds only to requests that have been authorized through the Swiss judicial system. This jurisdictional boundary provides an additional layer of protection for users, as foreign governments cannot directly demand data from the company without Swiss legal approval. For users in the United States, the United Kingdom, Australia, and Canada, this matters because it places a neutral third-party legal system between the user and potentially expansive surveillance authorities in their home countries.

Independent Audit Validates No-Logs Claims

Proton VPN’s no-logs policy has been verified through multiple independent audits. The most recent assessment was conducted by Securitum, which examined Proton AG’s Switzerland-based infrastructure between May 20 and 27, 2026. The audit confirmed that the service operates in full accordance with its publicly stated no-logs commitments, finding no evidence of user activity retention or any data that could be used to identify individual users after their sessions end.

For readers asking: Is Proton VPN safe to use? The service has demonstrated through both operational practice and independent audit that it does not retain the data necessary to identify users by connection time. This design means that even when legally compelled to respond to Swiss-approved data requests, the company has nothing to produce. The 47 rejections in H1 2026 and the 458 total rejections since 2017 provide a consistent operational track record.

What Users Should Look for in a VPN Service

While Proton VPN’s no-logs policy has been tested repeatedly through real legal demands, the broader lesson for users is that a VPN’s privacy guarantees are only as strong as its technical design and jurisdictional protections. When evaluating a VPN service, look for a provider with a verified no-logs policy that has been confirmed through independent audits, and one that is based in a jurisdiction with strong privacy protections and no mandatory data retention laws. A paid VPN service with AES-256 encryption, a kill switch, and a publicly documented transparency report provides the clearest evidence that the provider can be held accountable to its stated commitments. For anyone concerned about government surveillance or data requests, selecting a service that has demonstrated it cannot comply is the most reliable safeguard.

Share This Article