Skip to content
VPSDen
Legal7 min read627 words

Five, Nine and Fourteen Eyes, explained

What the intelligence-sharing tiers are, which countries sit in each, what membership does and does not imply for a hosted server, and how much it matters.

Short answer

Does the Fourteen Eyes alliance affect where I should host?

Five Eyes is the US, UK, Canada, Australia and New Zealand, descended from the 1946 UKUSA Agreement. Nine Eyes adds Denmark, France, the Netherlands and Norway. Fourteen Eyes — formally SIGINT Seniors Europe — adds Belgium, Germany, Italy, Spain and Sweden. These are signals-intelligence sharing arrangements, not law-enforcement mechanisms: membership means intelligence collected in one member state can be shared with the others through a channel invisible to you and outside your local courts. For hosting it is a meaningful factor for adversarial threat models and close to irrelevant for ordinary ones. It should be weighed alongside data-retention law and MLAT responsiveness rather than treated as the single deciding question.

Almost every privacy-hosting page mentions the Fourteen Eyes. Very few explain what it is, and the resulting folk understanding — "these countries read everything and share it" — is wrong in ways that lead to bad decisions in both directions.

Where the arrangement comes from

The core is the UKUSA Agreement, signed in 1946 between the United States and the United Kingdom to continue wartime signals-intelligence cooperation. Canada joined in 1948; Australia and New Zealand in 1956. The full text remained classified until 2010, when both the UK National Archives and the NSA released it.

The wider groupings are looser. "Nine Eyes" and "Fourteen Eyes" are informal labels for cooperation circles of decreasing intimacy; the fourteen-member group is formally SIGINT Seniors Europe (SSEUR). They are not treaties in the way UKUSA is, and the terms entered public vocabulary largely through documents published from 2013 onward.

The three tiers

TierMembers
Five EyesUnited States, United Kingdom, Canada, Australia, New Zealand
Nine EyesFive Eyes + Denmark, France, Netherlands, Norway
Fourteen EyesNine Eyes + Belgium, Germany, Italy, Spain, Sweden

Several other countries are recurrently described as third-party partners, including Israel, Japan, Singapore and South Korea. The boundaries are not crisp, which is a reason to treat the lists as a heuristic rather than a bright line.

What membership actually implies

  • Default shareability. Intelligence gathered by one member's SIGINT agency can flow to the others without a further legal process that is visible to you or reviewable by your courts.
  • Collection infrastructure. Member states host cable-tap and collection capability. Traffic transiting them is more likely to be within reach of that capability than traffic that does not.
  • Reduced domestic-restriction friction. Where an agency faces domestic limits on collecting against its own nationals, a partner agency may face none — the concern usually summarised as agencies "asking a friend."
  • Opacity. None of this appears in a transparency report. Your provider will not know it happened and could not tell you if it did.

What it does not imply

  • It is not law enforcement. A prosecutor who wants your server's contents as evidence uses an MLAT or a domestic warrant, not the Eyes arrangement. Intelligence product is generally not admissible and agencies guard sourcing closely.
  • It is not a claim that your VPS is being read. These are strategic collection programmes with finite capacity. Membership raises structural exposure; it does not indicate targeting.
  • It does not override encryption. Properly implemented TLS and a LUKS volume with a key you hold are not defeated by an intelligence-sharing agreement.
  • It does not make member states lawless. Germany and the Netherlands have some of the strongest domestic data-protection jurisprudence anywhere. A German server is a poor choice against a state-level adversary and a perfectly good one against a commercial one.

How much weight to give it

Our honest ranking of the factors, most to least decisive for hosting:

  1. Data-retention law. Directly determines whether your provider is compelled to keep records about you. This is the one that bites in real cases.
  2. Takedown and court-order regime. Determines how hard it is to remove your content or compel disclosure.
  3. MLAT responsiveness. Determines how quickly a foreign investigation becomes a local order.
  4. Fourteen Eyes membership. Matters for adversarial threat models; largely theoretical otherwise.

Concretely: Romania is in the EU and not in the Eyes, has had its retention law struck down twice, and is one of the better jurisdictions we sell. The Netherlands is a Nine Eyes member with excellent domestic privacy law and the best network we have. Neither fact alone settles the question, which is exactly why we publish the whole matrix rather than a single ranking.


Compare all nine of our regions across every one of these dimensions in the Jurisdiction Matrix.

Cite this page

VPSDEN, “Five, Nine and Fourteen Eyes, explained”, vpsden.com/kb/fourteen-eyes-explained, revised 2026-03-30. Published under CC BY 4.0 — reproduce it freely, with attribution.

Found an error? We amend the article and name the reader who reported it. Tell us.

Offshore VPS from €4.40/month. No KYC, no email, paid in Monero.

Nine jurisdictions, RAM-only options, disks we cannot read, live in about 48 seconds.

No email · No KYC · Pay in Monero · Deployed in under a minute