Home › Privacy › Email Jurisdictions

Privacy · Updated October 2026

Where your email lives: a jurisdiction guide for secure email

Affiliate disclosure: This is a research guide with no purchase recommendations and no affiliate links. If you do click through to a provider elsewhere on this site, our affiliate disclosure applies.

General information only — not legal advice. Laws change; check local counsel for your situation. The cases below are documented public events, reviewed October 2026. We describe what the law says and what happened, not what will happen to you.

Lab status: legal sources and documented cases reviewed

The short answer

Switzerland is the strongest jurisdiction on this page — outside every Eyes alliance, with Swiss courts as a gatekeeper against foreign requests. But a Swiss court order is still a court order: in 2021 ProtonMail was compelled to log an activist's IP address. Every jurisdiction we cover — Switzerland, Germany, the Netherlands, Belgium, Canada — has either a documented compulsion case or the legal machinery to run one. Jurisdiction decides which courts can compel your provider; the provider's architecture decides what those courts can actually get.

What the ‘Eyes’ alliances actually are

Five, Nine, and Fourteen Eyes are signals-intelligence sharing arrangements — the 14-eyes group is better known in intelligence literature as SIGINT Seniors Europe. They are agreements between governments about sharing intercepted intelligence, not warrants served on email providers. Two facts that deflate most marketing FUD:

1

No direct access

No alliance gives a foreign agency direct access to a provider's servers. Orders still go through the provider's home courts — usually via a mutual legal assistance treaty (MLAT).

2

Membership ≠ compulsion

What membership predicts is how smoothly intelligence flows between those countries' agencies — and how thoroughly domestic law checks those agencies (the EU members have the strongest checks).

Five Eyes

  • United States
  • United Kingdom
  • Canada
  • Australia
  • New Zealand

Nine Eyes — the Five, plus

  • Denmark
  • France
  • Netherlands
  • Norway

Fourteen Eyes — the Nine, plus

  • Germany
  • Belgium
  • Italy
  • Spain
  • Sweden

Switzerland is in none of these. That is its real, specific advantage — and roughly the entire advantage.

What jurisdiction protects — and what it doesn’t

1

Which courts can compel

A provider answers to its home country's courts first. Foreign requests arrive via MLAT and must be approved locally.

2

The data-protection baseline

GDPR (EU members) gives enforceable rights against the provider itself; Swiss nFADP is the non-EU counterpart.

3

Bulk vs. targeted limits

The ECJ killed blanket data retention in the EU in 2014. What remains everywhere is targeted, court-authorized collection.

4

What it cannot do

No jurisdiction prevents a lawful targeted order. Metadata — IPs, timestamps, account details — is where every documented case on this page was decided.

Switzerland

Eyes status: Not a member of the Five, Nine, or Fourteen Eyes

Switzerland is the only major email-provider jurisdiction outside every Eyes alliance, and its revised Federal Act on Data Protection (nFADP) took effect on 1 September 2023. That is genuinely favorable — but it is not magic.

In September 2021 a Swiss court ordered ProtonMail to log the IP address of an account used by a French climate activist, after French authorities routed their request through Europol. ProtonMail's founder stated the company was legally obligated to comply and could not appeal that particular order. The message contents were not handed over — the end-to-end encryption held — but the IP was logged and passed along, and the activist was later arrested.

The lesson: Swiss law keeps foreign agencies out (they must go through a Swiss court, via mutual legal assistance), but it does not keep Swiss courts out. The nFADP also fines the responsible individual, not the company — up to CHF 250,000 — and only for willful violations.

Germany

Eyes status: 14 Eyes

Germany sits inside the 14 Eyes (as a SIGINT Seniors Europe third-party partner of the NSA), but it also has the strongest court-level privacy protections in the alliance: the European Court of Justice struck down the EU Data Retention Directive in 2014, and Germany's Constitutional Court has repeatedly curbed blanket state access to online data.

The documented case: in December 2020, a Hanover regional court ordered Tutanota (now Tuta) to monitor the contents of one user's mailbox. Tuta's architecture meant the company could not decrypt the stored encrypted contents — it could only pass on new incoming non-encrypted emails for that account. Tuta's transparency report notes the company responds only to orders from German courts.

Germany is the jurisdiction case that breaks the naive ranking: heavier surveillance-membership, lighter practical exposure — because Tuta's architecture collects almost nothing to hand over.

Netherlands

Eyes status: 9 Eyes (and therefore 14 Eyes)

StartMail is based in the Netherlands, under Dutch law and the EU GDPR. The Netherlands participates in both the Nine Eyes and Fourteen Eyes arrangements.

The counterweight: EU member states cannot compel bulk data retention (post-2014 ECJ ruling), and the GDPR gives users enforceable rights against the provider itself — access, erasure, and limits on what can be collected at all. Dutch law requires judicial authorization for compelled disclosure, and foreign requests are routed through mutual legal assistance treaties, not served directly by foreign police.

No public cases of compelled data collection against StartMail have surfaced as of October 2026. That is reassuring, not conclusive — absence of a public case is not a protection.

Belgium

Eyes status: 14 Eyes

Mailfence is based in Belgium — a 14 Eyes member and an EU member state, so the GDPR applies in full. Like the Netherlands, Belgium requires judicial authorization for compelled disclosure, and foreign requests arrive via mutual legal assistance rather than directly.

Belgium is the least-covered jurisdiction in privacy marketing: no vendor mythologizes it, and no competitor attacks it. The honest read: it is an ordinary, GDPR-grade EU jurisdiction with no documented compulsion cases against its email provider as of October 2026.

Canada

Eyes status: Five Eyes

Canada is a full Five Eyes member, and Hushmail is headquartered in Vancouver, British Columbia. The documented case is also the oldest and starkest: in 2007, a Canadian court order under the Canada–US Mutual Legal Assistance Treaty compelled Hush Communications to hand over decrypted emails from three accounts in a drug-trafficking investigation.

The mechanism matters more than the country: Hushmail's server-side key handling meant the company could decrypt messages for law enforcement. Hushmail's own policy now states it discloses data only under an order from the Supreme Court of British Columbia, and that foreign requests must go through the Canadian government via MLAT.

Canada is the jurisdiction case where the country's intelligence membership and the provider's architecture point the same, negative direction.

Provider-by-provider: jurisdiction and the record

The table ranks nothing — it inventories. Read the "on the record" column first; it is the only column that describes something that actually happened.

ProviderLegal homeData lawEyesOn the recordThe honest read
Proton MailGeneva, SwitzerlandnFADP (Swiss)None2021: Swiss court ordered IP logging of a French climate activist's account (via Europol); contents stayed encrypted.Strongest formal protections, and the case that proves courts bite everywhere. Proton's public handling of it — updating policies and recommending Tor/VPN for IP protection — was unusually transparent.
TutaHanover, GermanyGDPR (EU)142020: Hanover court ordered monitoring of one user's mailbox; Tuta could only provide new incoming non-encrypted mail.Heaviest alliance membership, lightest practical exposure — there is almost nothing to seize. The '14 Eyes' label overstates the risk here.
StartMailAmsterdam area, NetherlandsGDPR (EU)9 / 14No public compulsion cases found as of October 2026.Ordinary, GDPR-grade EU jurisdiction. Built-in PGP and zero-access storage are the real privacy feature; the flag on the map is secondary.
MailfenceBelgiumGDPR (EU)14No public compulsion cases found as of October 2026.GDPR-grade EU jurisdiction, no vendor mythology built around it. Terms disclosed post-approval; judge it on encryption model, not the flag.
PosteoBerlin, GermanyGDPR (EU)14No public compulsion cases found as of October 2026.Anonymous signup (including cash by mail) does more privacy work here than German law does. Architecture and operations beat jurisdiction.
HushmailVancouver, CanadaCanadian federal/provincial law52007: decrypted emails from three accounts handed to US investigators via a Canadian court order under the Canada–US MLAT.The weakest combination in the table: Five Eyes jurisdiction plus an architecture that could (and did) decrypt for law enforcement.

Questions, answered

Is Switzerland really the best jurisdiction for a secure email provider?

It is the strongest of the common options — outside every Eyes alliance, with Swiss courts as a gatekeeper against foreign requests. But the 2021 ProtonMail case shows a Swiss court order is still a court order: IP metadata was logged and handed over. 'Best jurisdiction' is a real but small advantage; the provider's architecture (what it can technically hand over) matters more. This is general information, not legal advice.

Does Tuta being in a 14 Eyes country mean it shares my data with the US?

No. The 14 Eyes is a signals-intelligence sharing arrangement (SIGINT Seniors Europe) — it does not give foreign agencies direct access to a provider's servers, and it does not compel providers to share anything. What it means in practice is that intelligence agencies in those countries cooperate; a targeted legal order still goes through German courts and German law. Tuta's no-IP-collection architecture means there is very little to seize even under such an order.

What does jurisdiction actually protect me from?

Three concrete things: (1) which country's courts can issue binding orders against the provider; (2) whether foreign requests must pass through a local court via mutual legal assistance treaties (MLAT); and (3) the baseline data-protection regime (GDPR rights vs. Swiss nFADP). What it does not protect you from: targeted, court-authorized surveillance in the provider's home country — every jurisdiction on this page has documented cases of it.

Should I use a VPN or Tor with my secure email account?

If your threat model includes hiding your identity from law enforcement, yes — metadata is where every documented case on this page was decided. Proton itself recommends connecting via Tor or a VPN to mask the IP address, because even the best provider can be ordered to log IPs. For ordinary privacy (keeping your email content private from hackers, advertisers, and data brokers), the provider's encryption model alone is enough.

What about the US CLOUD Act — does it affect non-US providers?

The CLOUD Act (2018) lets US law enforcement compel US-based companies to produce data regardless of where it is stored. None of the providers in our table are US-domiciled, so the Act does not reach them directly. But US-owned services with servers abroad are covered — jurisdiction means the company's legal home, not where the data center sits. This is general information, not legal advice.

Is this page legal advice?

No. This is general information about public laws and documented cases, current as of October 2026. Laws change, enforcement varies, and individual situations differ. If you are a journalist, activist, or anyone whose safety depends on this, consult a lawyer in the relevant jurisdiction.
What's changed
  • October 2026 — Page published: jurisdiction deep-dives for Switzerland, Germany, Netherlands, Belgium, and Canada, with the provider-by-provider table.

Final verdict

If you want the strongest jurisdiction, it is Switzerland — and even that only buys you a gatekeeper, not immunity. For everyone else, the honest priority order is: architecture first (open source, audited, minimal logging), jurisdiction second. A provider that collects nothing in a 14 Eyes country beats a provider that logs everything in Switzerland — and we have the cases to prove it. General information only — not legal advice.