Home › Privacy › Email Jurisdictions
Privacy · Updated October 2026Where your email lives: a jurisdiction guide for secure email
Not legal advice
General information only — not legal advice. Laws change; check local counsel for your situation. The cases below are documented public events, reviewed October 2026. We describe what the law says and what happened, not what will happen to you.
The short answer
Switzerland is the strongest jurisdiction on this page — outside every Eyes alliance, with Swiss courts as a gatekeeper against foreign requests. But a Swiss court order is still a court order: in 2021 ProtonMail was compelled to log an activist's IP address. Every jurisdiction we cover — Switzerland, Germany, the Netherlands, Belgium, Canada — has either a documented compulsion case or the legal machinery to run one. Jurisdiction decides which courts can compel your provider; the provider's architecture decides what those courts can actually get.
What the ‘Eyes’ alliances actually are
Five, Nine, and Fourteen Eyes are signals-intelligence sharing arrangements — the 14-eyes group is better known in intelligence literature as SIGINT Seniors Europe. They are agreements between governments about sharing intercepted intelligence, not warrants served on email providers. Two facts that deflate most marketing FUD:
No direct access
No alliance gives a foreign agency direct access to a provider's servers. Orders still go through the provider's home courts — usually via a mutual legal assistance treaty (MLAT).
Membership ≠ compulsion
What membership predicts is how smoothly intelligence flows between those countries' agencies — and how thoroughly domestic law checks those agencies (the EU members have the strongest checks).
Five Eyes
- United States
- United Kingdom
- Canada
- Australia
- New Zealand
Nine Eyes — the Five, plus
- Denmark
- France
- Netherlands
- Norway
Fourteen Eyes — the Nine, plus
- Germany
- Belgium
- Italy
- Spain
- Sweden
Switzerland is in none of these. That is its real, specific advantage — and roughly the entire advantage.
What jurisdiction protects — and what it doesn’t
Which courts can compel
A provider answers to its home country's courts first. Foreign requests arrive via MLAT and must be approved locally.
The data-protection baseline
GDPR (EU members) gives enforceable rights against the provider itself; Swiss nFADP is the non-EU counterpart.
Bulk vs. targeted limits
The ECJ killed blanket data retention in the EU in 2014. What remains everywhere is targeted, court-authorized collection.
What it cannot do
No jurisdiction prevents a lawful targeted order. Metadata — IPs, timestamps, account details — is where every documented case on this page was decided.
Switzerland
Eyes status: Not a member of the Five, Nine, or Fourteen Eyes
Switzerland is the only major email-provider jurisdiction outside every Eyes alliance, and its revised Federal Act on Data Protection (nFADP) took effect on 1 September 2023. That is genuinely favorable — but it is not magic.
In September 2021 a Swiss court ordered ProtonMail to log the IP address of an account used by a French climate activist, after French authorities routed their request through Europol. ProtonMail's founder stated the company was legally obligated to comply and could not appeal that particular order. The message contents were not handed over — the end-to-end encryption held — but the IP was logged and passed along, and the activist was later arrested.
The lesson: Swiss law keeps foreign agencies out (they must go through a Swiss court, via mutual legal assistance), but it does not keep Swiss courts out. The nFADP also fines the responsible individual, not the company — up to CHF 250,000 — and only for willful violations.
Germany
Eyes status: 14 Eyes
Germany sits inside the 14 Eyes (as a SIGINT Seniors Europe third-party partner of the NSA), but it also has the strongest court-level privacy protections in the alliance: the European Court of Justice struck down the EU Data Retention Directive in 2014, and Germany's Constitutional Court has repeatedly curbed blanket state access to online data.
The documented case: in December 2020, a Hanover regional court ordered Tutanota (now Tuta) to monitor the contents of one user's mailbox. Tuta's architecture meant the company could not decrypt the stored encrypted contents — it could only pass on new incoming non-encrypted emails for that account. Tuta's transparency report notes the company responds only to orders from German courts.
Germany is the jurisdiction case that breaks the naive ranking: heavier surveillance-membership, lighter practical exposure — because Tuta's architecture collects almost nothing to hand over.
Netherlands
Eyes status: 9 Eyes (and therefore 14 Eyes)
StartMail is based in the Netherlands, under Dutch law and the EU GDPR. The Netherlands participates in both the Nine Eyes and Fourteen Eyes arrangements.
The counterweight: EU member states cannot compel bulk data retention (post-2014 ECJ ruling), and the GDPR gives users enforceable rights against the provider itself — access, erasure, and limits on what can be collected at all. Dutch law requires judicial authorization for compelled disclosure, and foreign requests are routed through mutual legal assistance treaties, not served directly by foreign police.
No public cases of compelled data collection against StartMail have surfaced as of October 2026. That is reassuring, not conclusive — absence of a public case is not a protection.
Belgium
Eyes status: 14 Eyes
Mailfence is based in Belgium — a 14 Eyes member and an EU member state, so the GDPR applies in full. Like the Netherlands, Belgium requires judicial authorization for compelled disclosure, and foreign requests arrive via mutual legal assistance rather than directly.
Belgium is the least-covered jurisdiction in privacy marketing: no vendor mythologizes it, and no competitor attacks it. The honest read: it is an ordinary, GDPR-grade EU jurisdiction with no documented compulsion cases against its email provider as of October 2026.
Canada
Eyes status: Five Eyes
Canada is a full Five Eyes member, and Hushmail is headquartered in Vancouver, British Columbia. The documented case is also the oldest and starkest: in 2007, a Canadian court order under the Canada–US Mutual Legal Assistance Treaty compelled Hush Communications to hand over decrypted emails from three accounts in a drug-trafficking investigation.
The mechanism matters more than the country: Hushmail's server-side key handling meant the company could decrypt messages for law enforcement. Hushmail's own policy now states it discloses data only under an order from the Supreme Court of British Columbia, and that foreign requests must go through the Canadian government via MLAT.
Canada is the jurisdiction case where the country's intelligence membership and the provider's architecture point the same, negative direction.
Provider-by-provider: jurisdiction and the record
The table ranks nothing — it inventories. Read the "on the record" column first; it is the only column that describes something that actually happened.
| Provider | Legal home | Data law | Eyes | On the record | The honest read |
|---|---|---|---|---|---|
| Proton Mail | Geneva, Switzerland | nFADP (Swiss) | None | 2021: Swiss court ordered IP logging of a French climate activist's account (via Europol); contents stayed encrypted. | Strongest formal protections, and the case that proves courts bite everywhere. Proton's public handling of it — updating policies and recommending Tor/VPN for IP protection — was unusually transparent. |
| Tuta | Hanover, Germany | GDPR (EU) | 14 | 2020: Hanover court ordered monitoring of one user's mailbox; Tuta could only provide new incoming non-encrypted mail. | Heaviest alliance membership, lightest practical exposure — there is almost nothing to seize. The '14 Eyes' label overstates the risk here. |
| StartMail | Amsterdam area, Netherlands | GDPR (EU) | 9 / 14 | No public compulsion cases found as of October 2026. | Ordinary, GDPR-grade EU jurisdiction. Built-in PGP and zero-access storage are the real privacy feature; the flag on the map is secondary. |
| Mailfence | Belgium | GDPR (EU) | 14 | No public compulsion cases found as of October 2026. | GDPR-grade EU jurisdiction, no vendor mythology built around it. Terms disclosed post-approval; judge it on encryption model, not the flag. |
| Posteo | Berlin, Germany | GDPR (EU) | 14 | No public compulsion cases found as of October 2026. | Anonymous signup (including cash by mail) does more privacy work here than German law does. Architecture and operations beat jurisdiction. |
| Hushmail | Vancouver, Canada | Canadian federal/provincial law | 5 | 2007: decrypted emails from three accounts handed to US investigators via a Canadian court order under the Canada–US MLAT. | The weakest combination in the table: Five Eyes jurisdiction plus an architecture that could (and did) decrypt for law enforcement. |
Get the privacy-stack checklist
Our one-page checklist: VPN, email, password manager, and 2FA — the complete privacy stack ranked by effort.
Questions, answered
Is Switzerland really the best jurisdiction for a secure email provider?
Does Tuta being in a 14 Eyes country mean it shares my data with the US?
What does jurisdiction actually protect me from?
Should I use a VPN or Tor with my secure email account?
What about the US CLOUD Act — does it affect non-US providers?
Is this page legal advice?
- October 2026 — Page published: jurisdiction deep-dives for Switzerland, Germany, Netherlands, Belgium, and Canada, with the provider-by-provider table.
Final verdict
If you want the strongest jurisdiction, it is Switzerland — and even that only buys you a gatekeeper, not immunity. For everyone else, the honest priority order is: architecture first (open source, audited, minimal logging), jurisdiction second. A provider that collects nothing in a 14 Eyes country beats a provider that logs everything in Switzerland — and we have the cases to prove it. General information only — not legal advice.