NordVPN
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Panama-incorporated VPN (NordVPN S.A.) under NL holding Nord Security, LT operations; Deloitte + PwC no-logs audits, RAM-only diskless servers, ISO 27001.
NordVPN is a European service hosted in Lithuania, with at most minor, transient US exposure under the CLOUD Act. It is listed under VPN.
Assessment notes
NordVPN's ownership chain is genuinely complex and not EU-owned in the strict sense: the VPN service is operated by NordVPN S.A. (Panama), historically Tefincom S.A., a Panamanian entity chosen for its no-data-retention jurisdiction, under the Nord Security holding company in Amsterdam, Netherlands, with operations and staff in Vilnius, Lithuania, and the holding company has taken $200M of US-led growth capital across two rounds, the 2022 $100M round co-led by US VC General Catalyst alongside Novator (IS) and Burda (DE), and a second $100M round led by Warburg Pincus (US) on 28 September 2023 at a $3B valuation, both minority; the product itself is one of the most rigorously audited consumer VPNs (annual no-logs assurance engagements by PwC and then Deloitte, most recently Deloitte Lithuania under ISAE 3000 for November to December 2025, full transition to colocated diskless RAM-only servers, ISO 27001), so it is included as a privacy-pick rather than a sovereignty-pick. Ownership signals: Panama operating entity (not EU-owned), US minority stakes in the holding (General Catalyst, Warburg Pincus), CLOUD Act exposure rated minor due to Panama incorporation + RAM-only architecture eliminating data-at-rest exposure. No public DPA at the NordVPN S.A. level for individual consumers; a business DPA is available at business.nordsec.com.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: Yes
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About NordVPN
NordVPN is the flagship product of Nord Security, the Lithuanian cybersecurity group that also operates NordPass, NordLayer, NordLocker, NordStellar and, since the 2022 merger, Surfshark. It is one of the largest consumer VPN services in the world (Nord Security reports more than 20M users across its products with NordVPN accounting for around 15M). It is included in this directory as a privacy-pick rather than an EU-sovereignty pick. The distinction matters, because the ownership chain is unusually layered.
The legal entity that operates the VPN service is NordVPN S.A., registered in Panama. Historically named Tefincom S.A., this entity was deliberately set up in Panama for its absence of mandatory data-retention laws, which is itself a privacy positioning. The group holding company is Nord Security in Amsterdam, Netherlands. Day-to-day operations and the bulk of the engineering team are in Vilnius, Lithuania. And the cap table includes US capital across two rounds: the 2022 $100M round was co-led by General Catalyst (US) alongside Novator (Iceland) and Burda (Germany), and a second $100M round led by Warburg Pincus (US growth equity) closed on 28 September 2023 at a $3B valuation, with Novator and Burda participating again. Both US stakes are minority and the founders are still reported as the largest holders after dilution. None of those layers makes NordVPN US-incorporated (the CLOUD Act does not apply directly to a Panamanian entity), but the company is also clearly not EU-owned in the way Mullvad (founder-owned Swedish AB) or ProtonVPN (Swiss non-profit Foundation) are.
Where NordVPN is genuinely strong is product security and audit history. Independent no-logs assurance engagements have validated the no-retention claim, first by PwC and since by Deloitte on what is now an annual cadence: the sixth engagement was run by Deloitte Lithuania under ISAE 3000 (Revised) with access from 10 November to 12 December 2025 and announced on 6 February 2026; the entire server fleet has been transitioned to colocated, diskless RAM-only servers so configuration is loaded fresh on every boot and nothing persists; Nord Security holds ISO/IEC 27001; and the product offers WireGuard (NordLynx), kill-switch, multi-hop, Tor-over-VPN, and threat-protection extras. cloud_act_exposure is set to minor rather than material to reflect the Panama incorporation + RAM-only architecture (no data-at-rest exposure). The US minority stakes and likely US payment / CDN sub-processors keep it above none.
Pricing is paid-only (no free tier; 30-day money-back): Basic from around €3.99/month on a 2-year plan, Plus and Complete tiers above. The affiliate programme is one of the most lucrative in the entire VPN category (see affiliate block). Best fit: mainstream privacy-conscious buyers who want a heavily audited, RAM-only no-logs VPN with broad device coverage and aggressive pricing on long commitments. EU buyers who specifically want sovereignty rather than just privacy should prefer Mullvad (SE), ProtonVPN (CH), IVPN, or AirVPN (IT), all elsewhere in this directory.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of NordVPN
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Italy · €7/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
Sweden · €3.75/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
Romania · €2.19/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
€7/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
€3.75/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
€2.19/mo |