Is NordVPN Private? What The 2024 Legal Warrant Revealed

A STACK Investigation

NordVPN makes a specific claim, and it’s worth stating precisely.

The company says it does not track what you do while connected to its VPN. But it does not pretend to be an anonymous service.

Its privacy policy is explicit that it collects “the bare minimum of information needed.” That minimum still includes an email address, payment details and billing records — retained, by the policy’s own terms, for ten years to meet accounting and tax obligations.

That is the real starting point for this investigation. It is a more useful one than simply asking whether NordVPN is “private.”

Almost every mainstream VPN provider knows who its paying customers are. The question that actually separates providers is narrower, and testable: once you’re connected, does the company retain anything that could reconstruct what you did?

NordVPN’s own support documentation draws this line directly. It states that the company does not log online activity, and that a customer’s account is not linked to what they did while connected.

That is a claim about architecture, not intention. Architecture can be tested.

This investigation examines what NordVPN says it collects, what independent auditors have verified, and where genuine unknowns remain — including a previously reported claim that is not supported by the evidence reviewed here.

We evaluate NordVPN across the same five lenses used throughout STACK’s privacy investigations:

  • Privacy Model — what it says it collects
  • Trust Architecture — what evidence supports those claims
  • Evidence Architecture — how strong that evidence actually is
  • Privacy Surface — where personal data touches the business beyond the VPN tunnel
  • Criticisms — how the claims have held up under scrutiny

Privacy model

Two layers, not one

NordVPN’s support documentation describes a clear separation. An account layer exists because the business needs it to operate. An activity layer, the company says, is deliberately not retained.

The account layer — verified through NordVPN’s own privacy policy — includes an email address, payment and transaction records, and support communications. Billing and payment information is retained for ten years after a customer’s last transaction, specifically to comply with accounting, tax and financial regulations.

This is a company disclosure, not an independent finding. But it is a specific, dated commitment rather than a vague marketing statement, and it is consistent with ordinary subscription-business recordkeeping.

The activity layer is where NordVPN’s central privacy claim lives. According to its support documentation, NordVPN does not log any online activity, and a customer’s account is not linked with anything done while connected to the VPN. The company’s general privacy policy reinforces this with a stated (L)no-logs policy(L): NordVPN does not track online activity.

Reading the claim correctly

A privacy policy and a support article describe what a company says it does. That’s a starting point for verification, not a conclusion.

The next two sections examine what independent evidence exists to support that separation.

Trust architecture

Corporate jurisdiction

The operating entity, nordvpn S.A., is registered in Panama, per the Public Registry of Panama (F&F Tower, Suite 32-D, Panama City). This establishes the legal jurisdiction governing the data controller.

What is not established in the evidence reviewed is the precise legal relationship between this Panama-registered entity and its parent structure, (L)Nordsec Ltd.(L) (UK/Lithuania). The exact data-isolation guarantees between the two — what the parent can or cannot access, and under what circumstances — remain unknown.

This is a genuine gap, not a resolved question. It sits in roughly the same place that ownership questions occupy for most VPN providers of this size.

What NordVPN says about legal compulsion

This is worth stating precisely, because NordVPN’s own language is more specific — and more limited — than a blanket immunity claim.

NordVPN’s support documentation states that, under its no-logs policy, it would be unable to provide any relevant information in the case of a valid court order, because the information simply doesn’t exist to hand over.

Separately, in an official 2022 policy statement, NordVPN was explicit that if a Panamanian court issued a legally valid order and rejected the company’s appeal, “there would be no other option but to comply.”

In other words: NordVPN does not claim structural immunity from legal process. It claims that its architecture leaves nothing of substance to disclose even when it does comply.

That is a more testable, and arguably more credible, position than an unconditional immunity claim. But it depends entirely on the underlying no-logs architecture actually holding up — the subject of the next section.

What remains unverified

No independent legal analysis of Panama’s mutual legal assistance treaty exposure, or of how a foreign subpoena would be enforced within that jurisdiction, is available in the evidence reviewed.

The evidence also does not establish what would happen if a third-party data center hosting NordVPN’s infrastructure were served with a wiretap order without NordVPN’s own operational knowledge.

Both are legitimate open questions rather than resolved ones.

Evidence architecture

Independent audit history

NordVPN’s no-logs claim has been tested by independent auditors on a recurring, multi-year basis — not once.

PricewaterhouseCoopers AG (Switzerland) conducted earlier point-in-time assurance engagements in 2018 and 2020, confirming the company’s no-logs operational stance at the time of each review.

Deloitte Audit Lithuania has since taken over this work under the ISAE 3000 assurance standard. Its most recent report — dated 11 February 2025, covering an assessment period of 18 November to 20 December 2024 — is described as the fifth annual such assurance report. It examined system configurations across NordVPN’s Standard VPN, Double VPN, Onion Over VPN, Obfuscated and P2P server types, confirming they aligned with the company’s no-logs claims for that period.

Five consecutive annual assurance cycles is a materially stronger evidentiary pattern than a single audit. It does not prove continuous compliance in the gaps between assessments. But repeated, dated, independent testing over multiple years significantly reduces the amount of blind trust a reader has to extend to the company. (For more on what these engagements do and don’t verify, see (L)how VPN audits work(L).)

Independent security testing

Cure53 conducted a 55-day application and infrastructure security assessment, dated 4 March 2025. Eleven senior testers examined NordVPN’s Android, iOS, Windows, macOS and Linux applications; its Chrome, Edge and Firefox browser extensions; its Threat Protection Pro feature; and elements of server-side code.

The report states that identified vulnerabilities — including some rated high-severity — were addressed by NordVPN’s engineers, with fixes subsequently verified by Cure53.

This is a meaningful data point in two directions at once. It confirms that independent testing found real weaknesses. It also confirms that those weaknesses were fixed, and the fixes independently checked, rather than simply asserted by the company.

Open-source verification

NordVPN’s NordLynx protocol and LibNeQuick libraries are published in open-source repositories, providing a publicly inspectable code base.

As with any open-source artifact, this supports transparency at the protocol level. It should be read as independently inspectable code — not as a substitute for the third-party audits described above.

The limits of any audit

Every audit named above — PwC’s, Deloitte’s and Cure53’s — evaluated a defined scope during a defined window of time. Deloitte’s most recent engagement, for example, covered roughly one month.

None of these audits amount to continuous, real-time monitoring. None can speak to what happens outside their tested scope — including exactly how much visibility auditors were granted into NordVPN’s proprietary backend orchestration systems, which is not specified in the available materials.

What remains unknown

The evidence does not establish how (L)RAM-only servers(L) handle resident data during an unexpected kernel panic or forced power-cycle, in the moments before any zeroization process would normally complete.

This is a genuine technical gap, not a resolved question.

Privacy surface

The account and billing surface

NordVPN’s privacy policy confirms collection of an email address, payment details and support communications, with billing records retained for ten years.

Its support documentation adds a specific detail: NordVPN states that it stores a transaction or order ID specifically to handle refund requests. Notably, the same documentation recommends CoinPayments as an option for customers who want a more anonymous payment method.

That recommendation is a meaningful, if partial, acknowledgment. The standard payment flow creates an identifiable financial link — and an alternative exists for users who want to reduce it.

The web and account surface

Separately from the VPN tunnel itself, NordVPN’s account and web properties — including nordaccount.com — use diagnostic data, cookies and performance analytics, according to Nord Account’s cookie and tracking policy.

This is a normal part of operating a modern web account dashboard. But it is worth distinguishing clearly from the VPN service itself: it is a website analytics surface, not a network-traffic logging surface.

What independent verification does not yet cover

The evidence available for this investigation does not include independent, vendor-authored documentation for NordVPN’s third-party payment or support processors.

No data-processing agreements or independent privacy notices for named sub-processors such as CoinPayments were available for review. This means the account-level and payment-level surface is currently understood primarily through NordVPN’s own disclosures — not through independent verification of how each connected vendor handles that data.

Similarly, no independent traffic analysis confirming exactly what mobile app stores collect prior to installation, or confirming telemetry opt-out behavior in practice, is available in the evidence reviewed.

Strategic incentives

NordVPN operates a public vulnerability disclosure program through Bugcrowd, offering financial rewards for identified security flaws — a concrete, ongoing incentive aligned with finding and fixing vulnerabilities rather than concealing them.

Commercially, NordVPN’s privacy policy discloses that marketing emails may continue for up to one year after a subscription ends, unless a customer opts out earlier. That’s a modest but real retention incentive tied to customer reactivation.

Separately, the company has committed to publishing monthly transparency metrics on government inquiries and DMCA requests. This functions as an ongoing, self-imposed accountability mechanism, even though it is not independently audited.

The evidence available does not include financial disclosures covering Nord Security’s broader corporate investment structure, or an independent analysis of how cross-selling across its wider product range might create incentives in tension with data minimization. This is a noted gap, not a finding either way.

Criticisms

The 2018 server breach

NordVPN has publicly disclosed a security incident in which an unauthorized party accessed a leased server in Finland, operated through a third-party data center provider, in March 2018.

According to the company’s own post-mortem disclosure, the incident stemmed from datacenter management misconfigurations and resulted in the exposure of an expired TLS private key.

This is a matter of public record, disclosed by the company itself. It demonstrates that infrastructure run through third-party data centers has, at least once, been vulnerable in ways outside NordVPN’s direct control.

What the evidence reviewed does not show is any indication that user activity or connection logs were exposed as part of this incident. The disclosed compromise concerned server infrastructure and a cryptographic key — not evidence of logged user activity being accessed.

Independent testing found real vulnerabilities — and they were fixed

Cure53’s 2025 assessment identified vulnerabilities, including some described as high-severity, across NordVPN’s applications and infrastructure. The same report confirms these were addressed by NordVPN’s engineering team, and that the fixes were independently verified by Cure53.

Readers should weigh both halves of this finding: vulnerabilities were found (a real weakness), and they were fixed and independently re-checked (a real strength in how the company responded).

The absence of contradictory court findings

A search of available public judicial records did not identify any court findings or legal records demonstrating that NordVPN has produced user activity or connection logs to law enforcement.

As with any absence-of-evidence finding, this should be read carefully. It is not the same as an affirmative guarantee that no such disclosure has ever occurred anywhere. But it is a meaningful negative finding, since a successful disclosure of this kind would be relatively likely to surface in public records if it had happened.

A note on a previously reported legal disclosure

Earlier public commentary on NordVPN’s privacy practices has referenced a specific 2024 legal warrant, reportedly issued through Panama’s courts, under which the company is said to have disclosed limited account information but no activity or connection logs.

That specific event is not supported by primary evidence in the pack reviewed for this investigation. No court record, official NordVPN disclosure, or independent report of that case is included in the evidence base available here.

Consistent with STACK’s evidentiary standards, this investigation does not restate that claim as verified fact. If primary documentation of that case becomes available, it would meaningfully strengthen the Trust Architecture section above — moving NordVPN’s “nothing to disclose” claim from an untested legal position to a demonstrated one.

STACK view

NordVPN’s core privacy claim is a narrower, and in some ways more disciplined, claim than a blanket promise of anonymity. It does not claim to make you unidentifiable as a customer. It does claim that what you do after connecting is not retained in a form that could be handed over.

That distinction is supported by a genuinely strong body of independent evidence: five consecutive years of third-party assurance audits (PwC, then Deloitte), an independent security assessment that found and confirmed the remediation of real vulnerabilities, and a publicly disclosed infrastructure breach that, on the evidence available, did not implicate user activity data.

That combination — recurring independent audits plus a track record of disclosing rather than concealing its own incidents — is a meaningful trust signal, separate from any single claim in the privacy policy itself.

Two things temper that conclusion, and both are reasons for precision rather than distrust.

First, every audit cited is scope-limited and time-bound by its own design. Deloitte’s most recent assessment, for instance, covered roughly a month. Repeated audits build confidence over time, but they are not a permanent guarantee.

Second, several claims sit on company disclosure alone rather than independent verification: the specific technical claim that servers run entirely from RAM with no persistent storage, the data-isolation boundary between the Panama-registered operating entity and its parent structure, and the handling of third-party payment processors such as CoinPayments. None of these are contradicted by the evidence. They are simply unverified by an independent third party in the material reviewed.

Readers should also note that this investigation deliberately does not repeat a previously circulated claim about a specific 2024 legal warrant, because it is not supported by the evidence base used here. That omission is itself a meaningful part of a rigorous investigation: absence of supporting evidence is a valid reason to leave a claim out, even one that has appeared elsewhere.

Conclusion

Based on the evidence reviewed:

  • NordVPN’s core no-logs claim — that activity is not retained in a way that could be reconstructed or handed over — is supported by five consecutive years of independent third-party assurance audits, and is not contradicted by any court record identified in this investigation.
  • NordVPN operates a conventional account relationship (email, payment, ten-year billing retention) and is direct about this. It does not claim to be an anonymous service, and it points customers toward CoinPayments as a more anonymous payment alternative.
  • Independent security testing (Cure53) found real, including high-severity, vulnerabilities in 2025 — and confirmed that NordVPN fixed them and had the fixes independently re-verified.
  • NordVPN’s own disclosure of a 2018 third-party data-center breach is a legitimate part of its history, though the evidence available does not show that user activity logs were involved.
  • The legal-compulsion posture is more precisely evidenced than a blanket immunity claim: NordVPN states it would comply with a valid, appeal-exhausted court order, but says there is nothing of substance to hand over.
  • Several claims — the exact parent/subsidiary data boundary, the specific RAM-only server implementation, and third-party payment processor practices — remain company-asserted rather than independently verified. A previously reported 2024 legal-disclosure event is not supported by the evidence available for this investigation.

Readers primarily concerned with whether NordVPN can see or hand over their browsing activity will find a genuinely strong, multi-year evidence base supporting the company’s claims. Readers evaluating trust more broadly — corporate structure, third-party vendors and unverified technical specifics — should treat those remaining items as open questions rather than settled ones.

Related investigations

Methodology

This investigation is based on nordvpn S.A.’s official privacy policy and support documentation; independent third-party audits (PricewaterhouseCoopers AG Switzerland; Deloitte Audit Lithuania, ISAE 3000; Cure53); the Public Registry of Panama; NordVPN’s own official incident disclosure; and public judicial record searches.

Claims sourced solely to NordVPN’s own documentation are identified as such throughout. A previously circulated claim regarding a 2024 legal warrant has been omitted because it is not supported by the evidence reviewed for this version of the investigation.