After the VPN signup surge — what UK age checks could do to VPNs next
UK VPN signups jumped 1,400% the week Ofcom's age checks landed. The next phase — VPN age gating itself — would change the calculus on jurisdiction, audits, and what "no logs" is worth.
The UK government's June 2026 announcement that smartphones and tablets must block nude content for children by default triggered an immediate privacy backlash. Signal called it "mass surveillance." Mullvad called it "government spyware." The policy is real, the timeline is aggressive, and the noise has, understandably, sent people looking for VPNs.
The conversation has skipped a harder problem. Regulators on both sides of the Channel are asking whether VPN services themselves need age checks. If Ofcom escalates, the question of which VPNs fall within UK jurisdiction (and what "no logs" means when a production order lands) stops being theoretical.
The surge that started in July 2025
A year before the device-scanning announcement, the numbers already told a story.
Proton VPN reported a 1,400% increase in UK signups during a single week in July 2025, peaking around 10–16 July. Mullvad, IVPN, and Surfshark reported surges ranging from 800% to over 1,800% across the same period, according to company statements and industry tracking data reviewed by multiple outlets.
The trigger wasn't the June 2026 device-scanning policy. It was the start of Ofcom's phased enforcement of age-verification duties under Part 3 of the Online Safety Act 2023 (OSA). From July 2025, platforms hosting pornographic content that fell within the OSA's Category 1 thresholds had to implement "highly effective" age assurance. Not a self-declared checkbox. The enforcement deadline had been set in Ofcom's March 2025 Age Assurance Guidance, which gave services three months to comply before facing enforcement action including fines of up to £18 million or 10% of global annual turnover, whichever is higher. The methods Ofcom permits, and what each one hands over, are covered in our breakdown of the six approved age verification methods.
UK internet users did what users in restrictive jurisdictions always do: they opened VPN comparison sites and downloaded clients.
The numbers track with earlier surges. Proton VPN signups from Uganda increased 8,000% during the January 2026 election-period internet shutdown. The UK spike in July 2025 fits the pattern. A government tightens content access, and the market for circumvention tools expands.
The next regulatory target: VPNs themselves
- Jul 2025OSA Part 3 enforcement begins; UK VPN signups surge
- Nov 2025Ofcom consults on whether VPNs "undermine" age assurance
- Dec 2025EU AVMSD trilogue: member states to "take appropriate measures"
- Jun 2026Home Office device-scanning demand announced
- Late 2026?Expected Ofcom consultation on VPN-specific duties
By late 2025, the conversation shifted. Ofcom's November 2025 consultation on the next phase of online harms enforcement included language asking whether VPN services and anonymising tools "undermine the effectiveness" of age-assurance requirements on platforms. The implicit question: if a 14-year-old can install a VPN in 90 seconds and appear to be an adult in France, what's the point of making Pornhub check IDs?
The EU had already moved. The December 2025 trilogue agreement on amendments to the Audiovisual Media Services Directive (AVMSD) included text requiring member states to "take appropriate measures" to ensure that VPN services do not "circumvent" age-verification systems. The text doesn't mandate VPN age checks directly. It creates the legal scaffolding for national regulators to impose them.
In the UK, Ofcom has not yet proposed requiring VPN age verification directly. But the regulator's November 2025 consultation, the Home Office's June 2026 device-scanning demand, and the broader political headwinds point one way. A future consultation on VPN-specific duties under the OSA is widely expected by late 2026.
→
→
If that happens, the real question isn't whether VPN providers will comply. It's which ones are in scope at all.
UK-incorporated VPNs: who's inside the jurisdiction
Under the OSA, Ofcom's enforcement reach extends to services that have "a significant number of UK users" or that "target the UK market." The IPA reaches further. Any telecommunications operator (which includes VPN providers) that offers services to UK residents can be served a Technical Capability Notice, regardless of where the company is incorporated.
Incorporation still matters. A UK-registered company is the easiest target. Here's where the major providers sit as of June 2026:
| Provider | Jurisdiction of incorporation | UK enforcement risk |
|---|---|---|
| Proton VPN | Switzerland (Proton AG, Geneva) | Low. Swiss data protection law creates real obstacles to UK production orders |
| Mullvad | Sweden (Amagicom AB, Gothenburg) | Moderate. EU-based, Sweden has mutual legal assistance treaties with the UK |
| IVPN | Gibraltar (Privatus Ltd) | Low-Moderate. British Overseas Territory but outside direct UK statutory reach |
| ExpressVPN | British Virgin Islands (Express Technologies Ltd) | Low. BVI is a separate legal jurisdiction |
| NordVPN | Panama (NordSec Ltd) | Low. Panama is outside UK/EU mutual legal assistance frameworks |
| Surfshark | Netherlands (Surfshark BV, Amsterdam) | Moderate. Netherlands-EU framework applies |
| Private Internet Access | United States (Kape Technologies) | Moderate. US-UK bilateral agreements create exposure |
| Windscribe | Canada (Windscribe Ltd) | Moderate-High. Five Eyes partner |
| Hide.me | Malaysia | Low. Limited bilateral frameworks |
| Perfect Privacy | Switzerland | Low |
The short version: most of the privacy-focused VPNs have deliberately incorporated outside UK direct reach. Incorporation isn't the whole story.
What "no-logs" means under a UK production order
"No-logs" is a marketing phrase, not a legal classification. It describes a company policy, typically that the provider doesn't retain timestamp, IP, or traffic metadata while a connection is active. Several providers back this with third-party audits. Proton VPN's most recent no-logs audit was published April 2026; Mullvad's was November 2025; IVPN's was January 2026.
Under a UK production order or a Technical Capability Notice (TCN) issued under the IPA, three things can happen that make the "no-logs" claim less comforting than it looks:
1. A TCN can compel a provider to start retaining data. Section 253 of the IPA gives the Secretary of State the power to require a telecommunications operator to maintain "the capability to provide any assistance" in giving effect to a warrant. In practice, a provider can be ordered to begin logging for specified targets, or specified categories of traffic, starting from the date of the order. The provider's no-logs policy up to that point is irrelevant. The obligation is forward-looking and compulsory.
2. A TCN comes with a gag order. Section 255(8) of the IPA requires that a person to whom a relevant notice is given "must not disclose the existence or contents of the notice to any other person without the permission of the Secretary of State." If a VPN is served with a TCN, it cannot tell its users. Not in a transparency report, not in a blog post, not in a canary warrant. The fact that the provider continues to market itself as "no-logs" while being legally compelled to log is, from the user's perspective, indistinguishable from lying.
3. UK servers mean UK jurisdiction. A TCN can be served on any provider that operates infrastructure in the UK or provides services to UK residents, regardless of incorporation. A Swiss-incorporated VPN with a server in a London data centre has a UK presence and can be served. The IPA's extraterritorial reach under Section 253(8) means physical presence isn't required. A TCN "may be given to persons outside the United Kingdom" and may require things to be done, or not to be done, outside the United Kingdom.
This is the gap that makes "no-logs" a less useful assurance than it appears. A provider can be truthful about having no logs at the moment of the audit, and legally barred from telling you when that ceases to be true.
Has this happened yet?
There is no publicly documented instance, as of June 2026, of a VPN provider being served with a TCN that compelled them to begin logging UK traffic. The IPA's transparency mechanisms are weak enough that absence of evidence shouldn't be treated as evidence of absence. The simplest reading is that this capability hasn't yet been used against consumer VPN providers at scale.
What has happened: the National Crime Agency's 2025 annual threat assessment, published in March 2026, reportedly identified anonymising services as a challenge to lawful access operations. The agency indicated it was exploring "the full range of statutory tools" available, in language widely read as signalling closer coordination with Ofcom on VPN-related enforcement.
If Ofcom escalates
Three scenarios are realistic as of mid-2026:
Scenario 1: No specific VPN regulation (most likely, near term). Ofcom focuses enforcement on Category 1 platforms with the largest UK audiences (Pornhub, X, Reddit) and treats VPN usage as a user responsibility rather than a compliance gap. Path of least resistance, requires no new legislation.
Scenario 2: VPNs brought into the OSA framework (medium term, 12–18 months). A consultation formally proposes that VPN services with UK users be designated as Category 2 services with an obligation to implement age assurance or to "take reasonable steps to prevent under-18s" from using them. This would be challenged in court by providers and civil liberties groups (the legal question of whether a network protocol constitutes "content" under the OSA is genuinely unsettled), but the consultation itself would trigger provider exits from the UK market.
Scenario 3: IPA enforcement directly against VPN providers (whenever government chooses). No new legislation required. The Home Secretary already possesses the statutory power to issue TCNs to telecommunications operators, and Ofcom already has the power to refer cases. This scenario doesn't require public consultation or parliamentary approval. It requires a decision. The trigger would most likely be a specific investigation (a child sexual abuse case where a VPN was used, a counter-terrorism operation, a sanctions-evasion prosecution) that creates political cover for using a power that currently sits unused.
What this means for you
The practical advice depends on your threat model. If you don't have one yet, our starter set of tools for a calmer digital life is a better place to begin than any provider comparison.
If you are a UK resident using a VPN to access content that Ofcom considers restricted, and your primary concern is avoiding an ISP block: any reputable VPN without a UK physical presence works. Your ISP sees that you're connecting to a VPN server and nothing more. The age-verification obligation falls on the platform, not on your ISP or your VPN provider. This is the threat model of most people who signed up during the July 2025 surge.
If you are a UK resident whose VPN use intersects with a threat model beyond content access, such as journalism, legal advocacy, whistleblowing, or communication with people in high-surveillance jurisdictions: incorporation and server location matter. A provider incorporated in Switzerland or Panama, with an audited no-logs policy, and without any physical infrastructure in the UK, gives you a meaningfully different threat surface than a provider incorporated in a Five Eyes country with UK-located servers. The difference is not theoretical. It is whether a production order served on the provider is a realistic possibility or a jurisdictional stretch.
If you are a UK resident using a VPN to do something that would attract law enforcement attention independently of the VPN (sanctions evasion, access to illegal content, fraud): a VPN with a public "no-logs" claim provides approximately zero protection if the NCA obtains a TCN. The mechanism exists. It has not been used publicly. Whether it has been used privately is unknowable by design.
If you are outside the UK but use a VPN provider that operates UK servers or has UK users: you are not the primary target of UK regulatory pressure. Your provider's response to that pressure (shuttering UK infrastructure, discontinuing UK-facing services, or complying with production orders) will affect you if you connect through servers that share infrastructure with UK-facing nodes, or if the provider's operational decisions compromise the global network.
If you live in a household with someone under 16: the spring 2027 social media ban reshapes how a VPN slots into family life. A VPN masks your network path, not the platform-level identity check. Picking a no-logs provider doesn't undo a verified ID upload, and choosing the wrong provider can route a child's circumvention back to your billing address.
What the coming months will tell you
Watch for three signals:
1. The Ofcom consultation on VPN-specific duties. If published before the end of 2026, it will signal that Scenario 2 is active. If Ofcom declines to open this consultation by Q2 2027, Scenario 1 is holding.
2. Provider responses to UK regulatory pressure. If a major privacy-focused VPN announces it is pulling UK servers, discontinuing UK-facing marketing, or restructuring its corporate entity to reinforce jurisdictional separation, that's a signal the provider believes enforcement is imminent. If providers stay quiet, it may mean they have been served and cannot speak, or it may mean nothing. The absence of a signal is not evidence of either condition.
3. Judicial review challenges. If the device-scanning requirement announced in June 2026 survives the expected legal challenges from civil liberties groups, or if any challenge reaches the UK Supreme Court and the policy is upheld, the precedent will accelerate the regulatory trajectory for VPNs. If courts strike it down or cut it back, the momentum stalls.
The period between policy announcement and enforcement is when the market rearranges itself. Quietly, behind gag orders, without blog posts or tweets. If you're picking a VPN in mid-2026, the provider you choose today may not be the same provider you have in twelve months. Not because the product changed. Because the legal obligation to stay silent about it kicked in.
Last reviewed 17 June 2026. Claims about Ofcom policy refer to the consultation published November 2025 and the Home Office device-scanning proposal announced 8 June 2026. Claims about VPN signup surges refer to company statements and third-party tracking data from July 2025. No information in this article has been obtained through leaked, stolen, or improperly accessed data. No VPN providers named here are current or past sponsors of Keep It Secret. Corporate jurisdictions and audit dates verified against each provider's published legal disclosures and transparency reports as of the date shown.
How exposed are you? Take the Tracking Audit (≈5 min) →