Yes, VPNs are legal in most countries, including the United States, the entire European Union, the United Kingdom, Canada, and Australia. A small group of governments restricts VPN use to state-authorised services only; a handful have made most VPN use effectively off-limits.
“Is a VPN legal?” is three separate questions packaged as one, and conflating them is where most confusion starts. Whether your government prohibits VPN use is a criminal law question: the worst outcome is a fine or imprisonment. Whether your streaming platform prohibits it is a contract question: the worst outcome is a blocked session. Whether your employer or university prohibits it is an institutional policy question: the worst outcome is disciplinary action. All three are addressed in turn, starting with the first and most consequential.
TL;DR
- VPNs are legal in the vast majority of countries, including the US, all EU member states, the UK, Canada, Australia, Japan, South Korea, and most of Southeast Asia and Latin America.
- A small group of governments bans or severely restricts them. North Korea, Turkmenistan, Belarus, and Iraq maintain effective bans. China and Iran permit only state-authorised VPNs. Myanmar’s 2025 Cybersecurity Law decriminalised personal VPN use, but checkpoint extortion of VPN users continues without lawful basis.
- Russia and India restrict VPN providers, not users. Individual VPN use is legal in both countries; the laws govern what providers must register or retain, not whether individuals can connect.
- Using a VPN for streaming violates platform terms of service, not the law. The Court of Justice of the European Union ruled in July 2026 (Case C-788/24) that VPN providers are “lawful technical tools” and that publishers are not liable for copyright infringement when users bypass state-of-the-art geo-blocking. The worst realistic consequence of VPN streaming is a blocked session, not a prosecution.
- A VPN does not grant legal immunity. If an activity is illegal in your country without a VPN, it is illegal with one.
- The UAE is widely misreported. VPN use is legal there; the cited fines of AED 500,000–2,000,000 apply under Article 10 of Federal Decree-Law No. 34 of 2021 only when a VPN is used to commit or conceal a crime, not for VPN use itself.
- If you are travelling to China, Iran, or Russia, configure and test obfuscation before you leave: VPN provider websites are blocked in-country, and major VPN apps have been removed from local app stores in both China and Russia.
Three questions, not one
Each of the three questions that “is a VPN legal?” packages carries different enforcers, different consequences, and a different body of law. Conflating them produces the most common errors in this space: treating a streaming platform’s contractual restrictions as a criminal prohibition, or treating an employer’s IT policy as a matter of national law.
| Question | Framework | Enforced by | Worst-case consequence |
|---|---|---|---|
| Is VPN use illegal under local law? | Criminal or civil law | Government | Fine or imprisonment |
| Does it violate a platform’s terms of service? | Contract | The platform | Session block or account suspension |
| Does it violate a workplace or school policy? | Acceptable use policy | Employer or institution | Disciplinary action or termination |
The criminal law question is the rarest of the three. In most of the world, no law prohibits VPN use, and the question does not arise. Where it does arise, it arises in a small number of jurisdictions. The consequences of getting it wrong are the most severe: fines, imprisonment, or both.
The terms of service question is the most commonly misread. Netflix, BBC iPlayer, Disney+, and most major streaming platforms prohibit VPN use to bypass geographic content licensing. That prohibition is contractual, not criminal. The platform can block a session or suspend an account; it cannot bring criminal proceedings. No streaming company has done so.
The acceptable use policy question is institutional. An employer or university can discipline or terminate for VPN use that violates its network policy. That outcome, however severe, is not a matter for police or courts. The law of the country you are in has no bearing on whether your employer’s IT policy was violated.
VPN legality at a glance: status by country
The table below summarises the legal status of individual VPN use in every jurisdiction covered here, plus a selection of commonly searched legal countries. Status refers to individual user legality, not provider obligations.
| Country | Status | Key detail |
|---|---|---|
| United States | Legal | No federal restriction; Utah SB 73 creates platform liability, not individual prohibition |
| European Union (all member states) | Legal | CJEU Case C-788/24 (July 2026) confirms VPN providers as lawful technical tools |
| United Kingdom | Legal | IPA 2016 governs provider obligations, not individual use |
| Canada | Legal | No restriction on individual use |
| Australia | Legal | No restriction on individual use |
| New Zealand | Legal | No restriction on individual use |
| Japan | Legal | No restriction on individual use |
| South Korea | Legal | No restriction on individual use |
| Turkey | Legal | Individual use unrestricted; some VPN services blocked at provider level |
| United Arab Emirates | Legal | Individual use legal; AED 500,000–2,000,000 fines under Article 10 of Federal Decree-Law No. 34 of 2021 apply only when a VPN is used to commit or conceal a separate crime; VoIP calling limits sit under a separate TDRA framework |
| Singapore | Legal | No restriction on individual use |
| Thailand | Legal | No restriction on individual use |
| Malaysia | Legal | No restriction on individual use |
| Indonesia | Legal | No restriction on individual use |
| Vietnam | Legal | Individual use legal; Law No. 116/2025/QH15 requires provider data retention |
| Philippines | Legal | No restriction on individual use |
| Brazil | Legal | Legal in general; a 2024 Supreme Court order imposed daily fines on individuals using VPNs to bypass a court-ordered block on X (conduct-specific, provisional; lifted October 2024 when X complied) |
| Mexico | Legal | No restriction on individual use |
| Russia | Providers restricted | Individual use legal; providers must register with FGIS; Article 13.53 applies to extremist-list access via VPN |
| India | Providers restricted | Individual use legal; CERT-In Direction No. 20(3)/2022 requires 5-year subscriber data retention from providers |
| Oman | Grey area | No enacted ban; TRA licensing framework applies; 2010 draft prohibition never passed into law |
| China | State-approved only | Unauthorised use prohibited under Decree 195 Article 6; RMB 15,000 fine ceiling |
| Iran | State-approved only | SCC resolution (Feb 2024) prohibits unauthorised use; prohibited but not criminalised under formal law |
| Iraq | Effectively banned* | MoC ban in force since 2014; Freedom House confirms weakly enforced in practice |
| Myanmar | Legal; blocked & extorted* | Personal use decriminalised under 2025 law; DPI block active; checkpoint extortion documented without lawful basis |
| Belarus | Effectively banned | Prohibited; ISP-level blocking reinforced since 2020 |
| Turkmenistan | Effectively banned | State-controlled internet; ISP-level blocking |
| North Korea | Effectively banned | Structural prohibition; near-total internet isolation |
* Iraq’s 2014 ban is technically in force but weakly enforced; VPN use is common in practice. Myanmar’s 2025 Cybersecurity Law decriminalised personal VPN use; a nationwide DPI block and checkpoint extortion of VPN users both continue regardless.

Countries where VPNs are effectively banned
VPNs are effectively inaccessible in five countries: North Korea, Turkmenistan, Belarus, Iraq, and Myanmar. What the law says, what enforcement looks like in practice, and what a foreign visitor encounters can differ substantially across the group.
North Korea, Turkmenistan, and Belarus
In North Korea, VPN use is prohibited as part of a near-total prohibition on foreign internet access. Ordinary citizens access only a domestic intranet; foreign internet infrastructure is structurally unreachable. The enforcement mechanism is the architecture itself rather than judicial action.
Turkmenistan operates one of the most restrictive internet environments globally. The state controls the national internet infrastructure, and ISP-level blocking makes foreign VPN services inaccessible. VPN use is prohibited under telecommunications regulations.
In Belarus, a prohibition on VPN use has been in force and tightened since the post-2020 political crackdown, which brought new internet controls including ISP-level blocking of VPN services and circumvention tools. VPN provider websites are blocked across all three countries; download and configure before arrival.
Iraq: technically banned since 2014, rarely enforced
VPN use is technically illegal in Iraq. The Ministry of Communications banned circumvention tools in 2014 as part of measures against ISIS communications infrastructure. The ban remains in force.
In practice, Freedom House’s Freedom on the Net reports the ban is weakly enforced. VPN use is common across the country; the government blocks relatively few websites. A 2024 draft regulation from the Communications and Media Commission that would have tightened restrictions was not adopted.
The prohibition is real and unamended; the enforcement posture makes it largely inoperative for ordinary users.
Myanmar: decriminalised on paper, extorted in practice
Personal VPN use is decriminalised in Myanmar. Cybersecurity Law No. 1/2025, enacted 1 January 2025 and in force from 30 July 2025 (via SAC Notification No. 113/2025), targets VPN providers and operators, not individual users. Burma News International confirmed that the law decriminalised personal VPN use by private individuals.
The penalties in the law apply to those who establish or provide VPN services without approval from the relevant Ministry. The law identifies the approval body as “the Ministry” without specifying which one; any attribution to the Ministry of Communications specifically is unverified. The penalty for unauthorised VPN provision is 1–6 months’ imprisonment and/or a fine of MMK 1,000,000–10,000,000.
A separate enforcement mechanism operates independently of the law. A nationwide DPI-based VPN block was implemented in May 2024; most standard VPN protocols are unreachable without obfuscation.
Checkpoint extortion of VPN users continues, and it now operates without lawful basis in the cybersecurity statute. Security forces conduct checkpoint phone searches and extract money from those found with VPN apps installed. Documented demands cluster around MMK 1,000,000–3,000,000, according to Radio Free Asia and The Irrawaddy. Where counter-terrorism charges appear in checkpoint cases, they typically attach to anti-regime content found during the search, not to VPN possession itself.
Myanmar illustrates the widest law-versus-practice gap: the 2025 law moved toward decriminalisation; the enforcement environment moved in the opposite direction. A traveller carrying a VPN app faces real risk at checkpoints not because the law prohibits personal use, but because the law’s prohibition was removed without removing the practice of extorting users.
Countries where only state-approved VPNs are permitted
China and Iran permit VPN use only through state-authorised channels. In both countries, unauthorised VPN use is prohibited, though the legal footing differs sharply: a binding administrative prohibition in China, and a policy-body resolution in Iran whose criminal-law status is contested.
China
VPN use in China is prohibited for individuals without state authorisation. The governing instrument is State Council Decree 195, formally titled the Interim Regulations on the Administration of International Networking of Computer Information Networks (1996, amended 1997). Article 6 prohibits any unit or individual from establishing or using channels for international networking outside the state-designated carriers.
The current fine ceiling for Article 6 violations is RMB 15,000, set by Article 14 of the same Decree. A 2026 draft revision, added to the State Council’s Legislative Work Plan with a comment period that closed in March 2026, proposes substantially heavier penalties: up to RMB 500,000 plus 15 days’ administrative detention. That draft has not passed. The operative ceiling remains RMB 15,000.
An enterprise carve-out exists. Foreign businesses operating legally in China can access international internet through state-licensed international gateways via the three licensed carriers: China Unicom, China Telecom, and China Mobile. Individuals have no equivalent licensed path.
Enforcement against individuals is sporadic rather than systematic. Documented fines have typically fallen well below the RMB 15,000 ceiling. Enforcement intensifies around major political events, specifically National Party Congresses and the Two Sessions, through DPI blocking rather than a concentration of individual prosecutions; the blocking is a technical measure, not an increase in the number of people charged.
Enforcement has historically been more selective against foreign visitors than against Chinese residents. That asymmetry does not mean zero risk for visitors; it means the practical risk profile differs from the one residents face.
The 2017 Apple App Store purge established the clearest record of VPN access restriction in China. Following new MIIT rules requiring VPN providers to obtain government licences, Apple removed all major VPN apps from its Chinese App Store. When Senators Ted Cruz and Patrick Leahy subsequently pressed Apple in writing on the scope of the removal, Apple’s response put the figure at approximately 674 apps. ExpressVPN, VyprVPN (Golden Frog), and Private Internet Access were among the confirmed named removals. This was a discrete 2017 event, not an ongoing removal campaign. Google Play has largely not complied with removal demands from Chinese authorities. VPN provider websites, including those of the major commercial providers, are blocked within China. Download, subscribe, and configure before crossing the border.
For technique-specific guidance on bypassing the Great Firewall, see what is an obfuscated VPN.
Iran
Iran prohibits VPN use without state authorisation, but that prohibition has not been enacted as criminal law.
The operative instrument is a resolution of the Supreme Council of Cyberspace, approved on 14 November 2023 and announced into effect on 19–20 February 2024. ARTICLE 19 has reported 9 January 2024 as the date of the Supreme Leader’s endorsement, though this date is disputed across credible sources.
Filterwatch, an Iranian internet-freedom monitoring organisation, describes the situation as “prohibited but not criminalised.” The Supreme Council of Cyberspace is a policy-making body. Under the Iranian constitution’s principle of legality of crimes and punishments, defining criminal offences is the exclusive authority of parliament, not a policy body. Iranian jurist Ali Mojtahedzadeh has challenged the SCC’s authority on exactly this basis.
VPN use is near-universal across Iran regardless of the prohibition. The 2026 internet shutdowns, which included a roughly 88-consecutive-day blackout, made the legal question largely irrelevant for much of the year; the binding constraint on VPN use was infrastructure, not law. Post-restoration, heavy filtering continues. The SCC circulated a December 2024 draft proposing enhanced anti-VPN measures and tiered access systems; the trajectory is toward tightening.
Countries with restrictions on providers, not users
Russia and India impose legal obligations on VPN providers, not on individual users. In both countries, individual VPN use is lawful.
Russia
Individual VPN use is lawful in Russia. Federal Law 276-FZ (2017) requires VPN providers to register with the Federal State Information System (FGIS) and connect to Roskomnadzor’s prohibited resources register so that blocked content remains inaccessible through their service. Non-compliant providers are blocked.
A narrower individual-level restriction took effect in September 2025. Article 13.53 of the Code of Administrative Offences, introduced by Federal Law No. 281-FZ of 31 July 2025 and in force from 1 September 2025, imposes fines of 3,000–5,000 rubles for deliberately accessing materials on Russia’s federal extremist list via a VPN. Deputy IT-committee head Anton Gorelkin stated that merely using a VPN is not an offence under the provision. Digital Development Minister Maksut Shadayev confirmed that accessing Instagram or Facebook via VPN is not covered.
The first prosecution under Article 13.53 has concluded. Sergei Glukhikh of Kamensk-Uralsky was charged in October 2025 following Google image searches for Azov Brigade insignia. The case was returned to police in November 2025 to correct procedural errors, then proceeded to court. On 10 December 2025 a court found Glukhikh guilty and imposed a fine of 3,000 rubles.
The broader enforcement environment has tightened through mechanisms other than criminal law. Apple removed nearly 60 VPN apps from the Russian App Store in 2024 at Roskomnadzor’s request, including NordVPN, ExpressVPN, and Proton VPN, among others; Google Play has largely not complied with equivalent removal demands. From April 2026, major Russian commercial platforms including Ozon and Kinopoisk began blocking users connecting via VPN at the application layer, a technical measure independent of any criminal prohibition.
India
Individual VPN use is legal in India. The applicable instrument is the Indian Computer Emergency Response Team’s Direction No. 20(3)/2022, issued 28 April 2022 under Section 70B(6) of the Information Technology Act. The directive explicitly names VPN service providers and imposes two separate data-retention obligations: subscriber registration data, meaning validated name, allotted IP addresses, contact details, purpose of use, and ownership pattern, must be retained for five years and provided to CERT-In on request. General system and ICT logs are subject to a separate 180-day retention requirement.
The directive contains an enterprise carve-out: it does not apply to corporate or enterprise VPNs used by employees for internal access to company systems.
Several major providers removed their physical Indian servers in 2022 rather than comply with the directive: ExpressVPN, NordVPN, Proton VPN, and Surfshark all announced the step explicitly. Virtual Indian servers, meaning hardware located outside India that issues Indian IP addresses, are still offered by multiple providers. The privacy implications of those virtual servers depend on what data the provider retains and where, not on the physical server location alone.
The directive remains in force. A proposed penalty increase under the Jan Vishwas (Amendment of Provisions) Bill had not passed as of the time of writing.
Three commonly misreported cases
Oman, the UAE, and Turkey appear consistently across VPN comparison guides with inaccurate characterisations.
Oman: the ban that never became law
VPN use in Oman is in a regulatory grey area, not an outright ban. The 2010 Telecommunications Regulatory Authority draft that would have explicitly prohibited private individual VPN use never passed into law. Omani legal specialist Riyadh Al-Balushi has confirmed the draft “never materialised.” The widely cited fine of approximately USD 1,300 derives from that same unenacted draft. It is not current law.
At its April 2025 annual media briefing, the TRA stated that it does not impose outright bans on VPN services but regulates them through a licensing framework. Commercial and corporate VPN use is permitted with TRA approval. For individuals, the situation is a grey area: the telecommunications framework prohibits use of unauthorised encryption and circumvention tools, but this has not been tested or enforced against private individuals.
UAE: legal to use, and the fine is not what most guides say
VPN use is legal in the UAE. Millions of residents use VPNs daily without legal consequence.
The fines cited in most VPN articles, ranging from AED 500,000 to AED 2,000,000, are real. The article of law is wrong. The fines derive from Article 10, of Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes. Article 10 penalises masking or manipulating an IP address for the purpose of committing or concealing a crime. Article 9 covers a different offence entirely, relating to unauthorised access to electronic systems using codes and passwords.
The triggering conduct under Article 10 is using a VPN to commit or conceal a separately illegal act, not VPN use itself. Using a VPN for general privacy, public Wi-Fi security, or accessing streaming content that the UAE has not specifically restricted carries no legal risk under Article 10.
A related but distinct framework governs voice and video calling. WhatsApp calls, Skype calls, and consumer VoIP services more broadly are restricted in the UAE under Telecommunications and Digital Government Regulatory Authority licensing regulations, not under the cybercrime law. Using a VPN to route such calls through a foreign server is the commonly cited enforcement scenario; the legal basis is the TDRA licensing framework, not Article 10.
Turkey: individual providers blocked, use is legal
VPN use is legal in Turkey. Several individual VPN service providers have been blocked at the provider level by Turkish authorities, but this represents blocking of specific services, not a prohibition on VPN use as a category. Social media platforms are periodically restricted and VPNs are widely used to reach them; there are no documented prosecutions of individual users for VPN use.
VPN use is legal in the vast majority of countries
VPN use is fully legal, with no restrictions on individual users, across the United States, all EU member states, the United Kingdom, Canada, Australia, New Zealand, Japan, South Korea, and the major economies of Southeast Asia and Latin America.
United States. VPN use is fully legal at the federal level. No federal law restricts individual VPN use. The FBI, through its Protected Voices initiative, recommends VPN use to encrypt communications on public or untrusted Wi-Fi as a cybersecurity measure for campaigns and organisations; a March 2026 FBI alert separately cautioned against untrustworthy free VPN applications. The recommendation is conditional on the network context, not a general privacy endorsement.
At the state level, Utah became the first US state to pass legislation directly involving VPN use. Under Section 14 of SB 73, signed by Governor Spencer Cox on 19 March 2026 and in effect from 6 May 2026, adult content platforms must treat users physically located in Utah as Utah-based users even when those users employ a VPN to mask their location; platforms are also prohibited from providing instructions on how to use a VPN to bypass age verification. Individual VPN use is not criminalised.
The law’s VPN provisions are on hold pending a ruling from Judge David Barlow in the District of Utah; following a preliminary-injunction hearing on 30 July 2026, the state and Aylo agreed to keep the provisions suspended until Barlow rules, with no ruling date set. Wisconsin’s Online Age Verification bill (SB 130 / AB 105) had originally included a provision requiring covered platforms to block all VPN users.
The Senate stripped the VPN provision on 19 February 2026 following advocacy by the Electronic Frontier Foundation and others on grounds of technical unworkability and privacy; the Assembly concurred the next day. Governor Tony Evers then vetoed the entire bill on 3 April 2026 on separate privacy grounds. Wisconsin currently has no age-verification law.
European Union. VPN use is fully legal across all EU member states. In July 2026, the Court of Justice of the European Union issued its judgment on 9 July in Case C-788/24 (ECLI:EU:C:2026:559). The case arose from a dispute in the Netherlands over the Anne Frank diary: the Anne Frank Fonds had argued that geo-blocking that could be bypassed by a VPN constituted an unauthorised communication of copyrighted work to a protected territory.
The CJEU rejected the argument, ruling that VPN providers are “neutral intermediaries” and “lawful technical tools which users may legitimately use,” and that publishers who deploy state-of-the-art geo-blocking are not liable for copyright infringement when users bypass it. This is a copyright and publisher-liability ruling, not a general declaration of VPN legality across all EU regulatory contexts.
One jurisdiction-specific note: French courts have separately ordered VPN providers to block access to illegal live-sports streaming sites under the French Sports Code. The CJEU ruling does not affect those orders, which rest on a different legal basis.
United Kingdom. VPN use is fully legal. The Investigatory Powers Act 2016 governs what communications service providers can be compelled to produce and retain; it does not restrict individual VPN use in any form.
Canada, Australia, and New Zealand. Fully legal in all three. All are members of the Five Eyes intelligence alliance, which affects what data a government may compel a VPN provider to produce, a question of provider jurisdiction rather than user legality. For a full treatment of how provider jurisdiction affects privacy outcomes, see the Five Eyes, Nine Eyes, and Fourteen Eyes explained.
Japan and South Korea. Fully legal in both.
Southeast Asia. Legal across the region’s major jurisdictions, including Singapore, Thailand, Malaysia, Indonesia, the Philippines, and Vietnam. Vietnam’s Law No. 116/2025/QH15, in force from 1 July 2026, introduces data retention obligations for service providers operating in Vietnam; it does not restrict individual VPN use.
Latin America. Legal across the major economies including Brazil, Mexico, Argentina, and Colombia. Brazil carries one qualification: in August 2024, the Supreme Federal Court imposed daily fines of R$50,000 on individuals using technological means to circumvent a court-ordered nationwide suspension of X. The measure was conduct-specific and provisional; it ended when X complied and the suspension was lifted on 8 October 2024. General VPN use in Brazil is unrestricted. The sanction attached to circumventing a specific court order, not to VPN use as such.
Is using a VPN for streaming legal?
Using a VPN to access streaming content is legal in every jurisdiction where VPNs themselves are legal. No court in any jurisdiction has held that using a VPN to access a streaming service’s content catalogue constitutes a criminal act.
In July 2026, the CJEU ruled in Case C-788/24 that VPN providers are “lawful technical tools which users may legitimately use” and that publishers who deploy state-of-the-art geo-blocking are not liable for copyright infringement when users bypass it. The ruling’s legal effect is within the copyright and communication-to-the-public framework, not across all areas of EU law. One counter-note applies: French courts have issued separate orders under the French Sports Code requiring VPN providers to block illegal live-sports streaming sites; the July 2026 ruling does not affect those orders.
Most major streaming services prohibit using a VPN to circumvent geographic content licensing in their terms of service. Netflix, BBC iPlayer, Disney+, and similar platforms include this prohibition in their subscriber agreements. The prohibition covers VPN use to bypass geographic licensing restrictions, not VPN use as such.
Violating a streaming service’s terms of service is a contractual matter between the subscriber and the platform, with consequences determined by the platform rather than any court. Netflix’s documented enforcement practice is to block the connection and display an error (historically M7111-5059, now commonly shown as E106), rather than to terminate accounts or take legal action. No platform has initiated criminal proceedings against a subscriber for VPN use.
A VPN provides no protection from copyright enforcement mechanisms. If downloading a specific file constitutes copyright infringement in your jurisdiction, a VPN does not shield you from a DMCA notice, a rights-holder settlement letter, or prosecution. Accessing a streaming service’s licensed catalogue via VPN is a ToS question; downloading infringing content is a copyright enforcement question. Either way, VPN detection enforces a licensing obligation, not a law.
Is using a VPN on a work or school network a legal issue?
Using a VPN on a network that prohibits it via an acceptable use policy is an institutional matter, not a criminal one. The consequences are employment or academic, not penal.
On a personal device connected to a corporate or institutional network, the acceptable use policy governs what traffic may pass through the institution’s infrastructure; it does not govern what applications are installed on the device itself. On a corporate or institutional device, many organisations permit their own managed VPN clients and prohibit consumer VPN applications, for reasons of network security: a consumer VPN routes device traffic outside the corporate perimeter, bypassing endpoint monitoring and data-loss-prevention controls. Check the applicable policy before installing any VPN application on a work device.
Disciplinary consequences for AUP violations can be significant: access revocation, employment termination, academic sanction. They are not a police matter. The law of the country in which you are located has no bearing on whether your employer’s or institution’s policy was violated.
If the content accessed via VPN on a work network is independently illegal under local law, the criminal law question remains separate from and additional to the AUP question. The AUP consequence does not extinguish the criminal one.
A VPN does not grant legal immunity
A VPN does not make an illegal activity legal. The law that governs an activity is the law of the jurisdiction where the activity is illegal; the country of the VPN server has no bearing on that.
Downloading a file that constitutes copyright infringement is copyright infringement whether or not a VPN is active. Accessing content that is prohibited in your country remains prohibited whether your traffic is encrypted and rerouted or not. Fraud, harassment, and other criminal activity remain criminal when conducted through a VPN.
A VPN adds technical difficulty to identifying you: it hides your IP address and encrypts your traffic. It does not prevent identification through other means, including account logs, payment records, device fingerprinting, and records held by the VPN provider itself. For a complete explanation of how a VPN encrypts and routes your traffic, see How Does a VPN Work.
For users in countries where VPN use is restricted: configuring an obfuscated protocol reduces the likelihood of detection by DPI systems. It does not create legal authorisation for VPN use where none exists.
The same criminal-law principles apply to other privacy tools. Tor, proxies, and encrypted messaging applications are lawful in every jurisdiction where VPNs are legal, though specific features can be separately regulated; VoIP calling in the UAE, for instance, is restricted under TDRA licensing rules rather than criminal law. In Turkey and Russia, Tor is technically blocked at the ISP level by administrative order, though individual Tor use is not prohibited by law in either country. For a full comparison of VPN and Tor legal status, including the specific anonymity properties that distinguish the two, see Tor vs. VPN.
Before you travel to a country that restricts VPNs
VPN provider websites are blocked in China, Iran, and frequently in Russia. You cannot download, subscribe, or configure after crossing into those countries. In China, Apple removed approximately 674 VPN apps from the local App Store in a 2017 purge following new MIIT licensing rules; the apps have remained unavailable there since. In Russia, removals have continued in waves: a large round in 2024 removed nearly 60 major VPN apps at Roskomnadzor’s request, and a further round of custom VPN client removals followed in 2026. In both countries, major commercial VPN apps are unavailable from the local App Store and provider websites are blocked, so install and configure before arrival.
- Download and install the app before crossing the border. If you have not installed the app before arriving, you will be unable to retrieve it in-country.
- Subscribe and pay before arrival. Payment processing through provider websites may be restricted or unavailable from within restricted countries. Complete your subscription on a home network.
- Enable and test obfuscation on your home network before leaving. Standard WireGuard and OpenVPN traffic has an identifiable signature that DPI systems in China, Russia, and Iran are configured to detect and block. Obfuscated or stealth protocol modes disguise VPN traffic as ordinary HTTPS, making it substantially harder to identify. Enable obfuscation in your provider’s settings before departure, confirm the connection establishes on your home network, and test it again on the specific network you encounter after arrival.
- Test on the destination network, not only at home. DPI infrastructure varies between countries and between ISPs within the same country. A configuration that connects on your home broadband may fail on the specific mobile or hotel network you land on. Test the connection on arrival before relying on it.
- Know your enforcement reality before assuming your risk level. A foreign tourist on a short visit to China faces a different practical enforcement profile than a Chinese resident. A business traveller using a state-licensed international gateway through one of the three licensed carriers faces no restriction.
- Configure a backup. A second VPN provider installed before departure, obfs4 bridges for Tor, or a locally purchased SIM with home-routed international roaming all function as fallbacks if your primary configuration fails after arrival.
- Understand what device inspections target in each country. In Myanmar, checkpoint phone searches for VPN apps are documented and ongoing; junta forces have searched devices specifically for VPN applications, with extortion demands of approximately MMK 1,000,000–3,000,000 recorded by Radio Free Asia and The Irrawaddy. Some travellers use a secondary device for in-country use in Myanmar specifically. In China and Russia, border and checkpoint device inspections are documented, but the recorded searches there have targeted extremist or prohibited content, anti-government material, and specific foreign social media applications rather than VPN apps as such. The legal status differs between the two: in Russia individual VPN use is lawful, so a VPN app is not an independent enforcement trigger; in China individual unauthorised VPN use is itself prohibited under Decree 195, though documented device searches have still centred on content rather than the mere presence of a VPN app.
Obfuscation reduces the likelihood of detection by DPI systems. It does not create legal authorisation for VPN use where none exists.
Frequently asked questions
Are VPNs legal in the US?
Yes, fully legal at the federal level. No US federal law restricts individual VPN use. Utah SB 73, signed in March 2026 and in effect from May 2026, created the first state-level legislation directly involving VPN use, but it does not prohibit or criminalise VPN use by individuals. Under Section 14, adult content platforms must treat users physically located in Utah as Utah-based users even when those users employ a VPN; platforms are also prohibited from providing VPN bypass instructions. The law’s VPN provisions are on hold pending a ruling from a federal district court judge; the hold is open-ended with no date set as of the time of writing.
Are VPNs legal in the UK, Canada, and Australia?
Yes, fully legal in all three. No law in any of these countries restricts individual VPN use. All three are Five Eyes members, which affects what intelligence agencies may compel VPN providers to produce; it does not restrict what individuals may do.
Are VPNs legal in China?
VPN use in China is prohibited for individuals without state authorisation under State Council Decree 195, Article 6. The current fine ceiling is RMB 15,000 under Article 14. A 2026 draft revision proposes penalties up to RMB 500,000 plus 15 days’ administrative detention; that draft has not passed and is not current law. Enforcement against individuals is sporadic and has historically been more selective against foreign visitors than Chinese residents. Configure a VPN with obfuscation before entering the country; provider websites are blocked in-country and major VPN apps have been removed from the local App Store.
Are VPNs legal in the UAE?
Yes. VPN use is legal in the UAE. The fines of AED 500,000–2,000,000 that appear in most coverage apply under Article 10 of Federal Decree-Law No. 34 of 2021 only when a VPN is used to commit or conceal a crime. VPN use for privacy, remote access, or streaming content not specifically restricted by the UAE carries no legal risk under that provision. VoIP restrictions, including those on WhatsApp and Skype calling, are governed by a separate TDRA licensing framework, not the cybercrime law.
Are VPNs legal in Russia?
Individual VPN use is lawful in Russia. Federal Law 276-FZ imposes registration and content-filtering obligations on VPN providers, not restrictions on individual users. Federal Law No. 281-FZ, in force from 1 September 2025, introduced a narrower individual-level provision: Article 13.53 imposes fines of 3,000–5,000 rubles for deliberately accessing materials on Russia’s federal extremist list via VPN. Named officials have confirmed that ordinary social media access via VPN is not covered.
Are VPNs legal in India?
Yes, individual VPN use is legal in India. The 2022 CERT-In directive requires VPN providers to retain subscriber registration data for five years and system logs for 180 days; it does not restrict individual use. Several major providers removed their physical Indian servers rather than comply with the directive; they continue to offer virtual Indian servers. The directive’s enterprise carve-out exempts corporate VPNs used for internal company access.
Is it legal to use a VPN for Netflix?
Yes, in every country where VPNs themselves are legal. Netflix’s terms of service prohibit using a VPN to circumvent geographic content licensing, which is a contractual restriction, not a criminal one. The CJEU ruled in July 2026 that VPN providers are lawful technical tools and that publishers are not liable for copyright infringement when users bypass their geo-blocking measures. The consequence of violating Netflix’s terms is a blocked session, not a prosecution.
Can I go to jail for just having a VPN app installed?
In most countries, no. In Myanmar, Cybersecurity Law No. 1/2025 decriminalised personal VPN use by individuals; the law’s penalties apply to providers and operators, not individuals who have a VPN app installed. Security forces at checkpoints in Myanmar extort those found with VPN apps, but without lawful basis in the cybersecurity statute. In China, the prohibition in Decree 195 targets use of unauthorised cross-border internet channels, not the installation of an application.
Are free VPNs legal?
Yes, in countries where VPNs are legal generally. The risk from free VPN use is informational, not criminal. Many free VPN services recover infrastructure costs by collecting and monetising user data. Citizen Lab and Arizona State University research published in August 2025 found popular free Android VPN applications with over 700 million combined downloads covertly collecting location data. Zimperium’s October 2025 analysis identified approximately 800 free VPN apps requesting permissions well beyond what a VPN requires. A 2026 study of 281 free Android VPN apps documented traffic leaks, unencrypted data transmission, and embedded tracking. An independently audited no-log policy is the relevant quality signal, not the absence of a subscription fee.
Can I get in trouble for using a VPN?
That depends on your jurisdiction and what you use it for. In most countries, no. In China, using an unauthorised VPN is illegal and carries fines under Decree 195. In Iran, unauthorised VPN use is prohibited by an SCC resolution whose criminal-law status is legally contested; the practical consequence is restriction rather than prosecution in most cases. In Russia, Article 13.53 creates a narrow individual-level restriction for accessing the federal extremist list via VPN.
Does using a VPN make illegal activities legal?
No. A VPN hides your IP address and encrypts your traffic. It does not change the law that governs your activity. If an act is illegal in your jurisdiction without a VPN, it is illegal with one.
Can my ISP see I am using a VPN?
Yes. Your ISP can see that your device is connected to a VPN server and that encrypted traffic is passing to that server, even though it cannot see the content of that traffic. In countries with active DPI infrastructure, including China, Russia, and Iran, ISPs are also able to identify the specific VPN protocol in use from the traffic’s structure and block it. Obfuscated protocols disguise VPN traffic as ordinary HTTPS, making protocol identification substantially harder, but no obfuscation technique is undetectable under all DPI configurations.
Is it legal to torrent with a VPN?
Using a VPN to torrent is legal wherever both VPN use and the specific file transfer are themselves legal. A VPN changes your detectability, not the legality of the download. Downloading copyrighted material without authorisation remains copyright infringement regardless of whether a VPN is active: a VPN hides your IP address from peers and trackers, but does not shield you from a DMCA notice, a rights-holder settlement letter, or prosecution. Some VPN providers restrict P2P traffic to specific servers or prohibit it altogether in their terms of service; that is a contractual restriction on the provider relationship, not a statement about legality.
Is it legal to run your own VPN server?
Running your own VPN server is legal in every country where using a VPN is legal. The provider-registration regimes in Russia and India differ in how clearly they address personal servers. India’s is the clearer case: CERT-In Direction No. 20(3)/2022, confirmed by CERT-In’s own FAQ, defines a VPN Service Provider as one serving “general Internet subscribers and users,” a definition that places a personal own-use server outside its scope by agency guidance. Russia’s Federal Law 276-FZ is less definitive: the statute targets “owners of means providing access to blocked resources,” a functionally-defined category with no explicit personal-server carve-out and no Roskomnadzor or court guidance on where that line falls. In both cases the exact boundary is not codified in the statute itself.
