Mullvad VPN
VERIFIEDSwedish founder-owned VPN (Mullvad VPN AB / Amagicom AB, Gothenburg, 2009), anonymous numbered accounts, Cure53-audited, flat €5/month.
Why this score?
Mullvad VPN, operated by Mullvad VPN AB (parent Amagicom AB) in Gothenburg, Sweden, founded March 2009 by Fredrik Strömberg and Daniel Berntsson and 100% founder-owned with no PE/VC/parent-company on record — anonymous numbered accounts (no email, no username, no personal data), Cure53-audited no-logs policy (2018 apps, 2020 infrastructure, 2024 apps + WireGuard/OpenVPN relay code), flat €5/month price unchanged since 2009, open-source apps, cash/Monero accepted. Rated 3/5: an otherwise gold-standard privacy profile under Swedish EU jurisdiction, but Mullvad does not publish a publicly accessible DPA — the anonymous-account architecture means no traditional controller-to-processor relationship is established, and only a privacy policy and no-logging data policy are available; under EU Vetted''s rubric a DPA that small EU buyers cannot self-serve caps the score at 3/5.
- SCORE
- 3.0/5
- CLOUD ACT
- CLOUD ACT EXPOSURE
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- OWNERSHIP
- OWNERSHIP
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
US-owned US-headquartered, or has a US parent company.
-
Other Swiss, UK or another non-EU jurisdiction.
-
- SUB-PROCS
- 0 none disclosed
JUMP TO
About Mullvad VPN
Sub-processor map · none disclosed
Frameworks & certifications · none listed
Capability matrix
Pricing & tiers
Public documents
Alternatives in this category
CERN-founded Swiss VPN (Proton AG, Geneva), owned by non-profit Proton Foundation; 15,000+ servers, audited no-logs, open-source apps, free tier.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Italian hacktivist-founded VPN (Perugia, 2010), no-logs, port forwarding — but no longer serves Italian residents (Piracy Shield).
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Gibraltar-incorporated VPN (IVPN Limited / ex-Privatus, founded 2009), Cure53-audited no-logs, open-source apps, independent ownership.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.