Law & jurisdiction
What is Five Eyes?
The Five Eyes is a signals-intelligence sharing alliance between the United States, United Kingdom, Canada, Australia and New Zealand. Nine Eyes adds Denmark, France, the Netherlands and Norway; Fourteen Eyes adds Belgium, Germany, Italy, Spain and Sweden. Privacy-oriented hosting typically avoids all fourteen.
Why Five Eyes matters
Nine Eyes adds Denmark, France, the Netherlands and Norway; Fourteen Eyes adds Belgium, Germany, Italy, Spain and Sweden. Privacy-oriented hosting typically avoids all fourteen.
Five Eyes in practice
In day-to-day operations, Five Eyes is a concrete constraint, not a headline. Before you buy, list which of the five jurisdictions your provider's offices, directors, and network gear fall under. If any do, your logs and traffic metadata can be obtained via an intelligence request with no warrant and no notice to you. The fix is choosing a host outside the alliance entirely, in a jurisdiction with no reciprocal arrangements. The cost of getting it wrong is your entire premise of privacy: a single upstream request can lay bare who talks to your server.
What people get wrong about Five Eyes
The common mistake is treating the Five Eyes as a list of countries to avoid without checking where your provider actually stands. Many hosts advertise 'offshore' while routing through, or keeping equipment in, a member country. A Singapore or Switzerland address does nothing if the upstream bandwidth or the data centre floor is in the US or UK. Read the network path and the legal entity, not the marketing language.
Five Eyes — common questions
Is it illegal to host a server in a Five Eyes country?
No. Hosting in a Five Eyes member is legal. The concern is surveillance: intelligence agencies in those countries can compel disclosure of data with fewer obstacles, and sharing within the alliance widens exposure. You need to weigh your risk profile against the legal benefits those jurisdictions sometimes offer.
Do I need to worry about Five Eyes if my server is in a non-member country?
Not directly. The Five Eyes agreement does not give members automatic access to foreign data. However, many non-member jurisdictions still cooperate through treaties or bilateral deals. The effective safeguard is the total absence of your data, logs, and identity from any party that could be compelled, not just your server's physical location.
Where Five Eyes comes up
- How do I get US latency without US jurisdiction? Nassau in the Bahamas is roughly 45 ms from Miami, and Panama City about 60 ms — both outside US jurisdiction, outside the Eyes alliances, and with no DMCA…
- Which countries are in the Five, Nine and Fourteen Eyes? Five Eyes: the United States, United Kingdom, Canada, Australia and New Zealand. Nine Eyes adds Denmark, France, the Netherlands and Norway. Fourteen Eyes …
More from law & jurisdiction
- Warrant canary
- A warrant canary is a regularly republished statement that a provider has not received a secret legal demand; its disappearance implies that one has arrived.
- KYC
- KYC is the set of identity-verification duties imposed on regulated financial institutions before providing services.
- No-KYC hosting
- No-KYC hosting is server hosting that requires no identity verification — no government ID, billing address, phone number or payment card.
- Offshore hosting
- Offshore hosting means placing a server in a jurisdiction other than your own, typically one outside the Fourteen Eyes alliances and outside EU data-retention rules.
- Fourteen Eyes
- The Fourteen Eyes is the widest of the signals-intelligence sharing groupings, comprising the Five Eyes plus Denmark, France, the Netherlands, Norway, Belgium, Germany, Italy, Spain and Sweden.
- MLAT
- An MLAT is a treaty through which one country formally requests another to gather evidence on its behalf.
- DMCA
- The DMCA is United States copyright statute whose notice-and-takedown procedure and safe harbour apply to service providers situated in the United States.
- Data retention
- Data retention laws require communications providers to store connection metadata for a defined period so that authorities can obtain it later.