Priviy
privacy-basicsINFO

5/9/14 Eyes and your cloud privacy: the real world map of surveillance (2026)

The 5/9/14 Eyes alliances are not a conspiracy myth - they structure signal intelligence sharing across 14 democracies. In 2026, we map who shares what, how the US CLOUD Act and EU Data Act overlap these alliances, and which cloud jurisdictions truly remain out of scope.

By Eric Gerard · Editor · Priviy10 min readPhoto: NASA via Unsplash

What are the 5/9/14 Eyes and why do they matter for cloud storage?

The 5/9/14 Eyes are tiered intelligence-sharing alliances. They set which governments can legally demand your cloud data. The 5 Eyes (US, UK, Canada, Australia, New Zealand) share raw signals. The 9 Eyes add France, Denmark, Netherlands, Norway. The 14 Eyes add Germany, Belgium, Italy, Spain, Sweden. In 2026, only 3 of 12 mapped cloud providers sit outside all 14 Eyes, in Switzerland: Proton Drive, Tresorit, pCloud.

The essentials

The signal intelligence (SIGINT) 5 Eyes, 9 Eyes and 14 Eyes alliances are neither a conspiracy myth nor a state secret. Major leaks document them (Snowden 2013, Vault 7 in 2017), and several signatory governments confirm them in official statements. In 2026, their impact on cloud privacy stays large. Not because they enable direct mass surveillance, but because they set which state can legally compel a cloud provider to deliver encrypted data.

So the question for a cloud privacy user is not "do these alliances exist?" (yes). Nor is it "could I be personally spied on?" (statistically no, if you're not a specific target). It is: "if my provider receives a legal request tomorrow, which law applies, and how many states can access it through intelligence sharing?" This is the logic we unfold here, jurisdiction by jurisdiction.

We mapped 12 cloud privacy providers in May 2026. 9 are hosted or registered in 14 Eyes or allied countries. Only 3 - Proton Drive, Tresorit and pCloud (Switzerland) - get real jurisdictional protection outside 14 Eyes. Add to that a few niches: 1984 Hosting (Iceland), Njalla (Nevis), Internxt (Spain, 14 Eyes but decentralized infrastructure).

Where do the 5/9/14 Eyes alliances come from?

The 5 Eyes (FVEY) core dates back to the 1946 UKUSA agreement. The United States and the United Kingdom signed it at the end of WWII, to keep sharing intercepted intelligence against the USSR. Canada joined in 1948, Australia and New Zealand in 1956. These five countries share raw intelligence: phone interceptions, satellite data, direct access to telecom infrastructures.

The 9 Eyes and 14 Eyes extensions (sometimes called SIGINT Seniors Europe) are less privileged outer circles. Members receive filtered and summarized intelligence, but they take an active part in collection. The Snowden documents, published by The Guardian and Der Spiegel in 2013-2014, made the boundaries clear:

  • 5 Eyes (FVEY): United States, United Kingdom, Canada, Australia, New Zealand
  • 9 Eyes: 5 Eyes + Denmark, France, Netherlands, Norway
  • 14 Eyes: 9 Eyes + Germany, Belgium, Italy, Spain, Sweden

Beyond the 14 Eyes, there are linked "Tier B" circles: Japan, South Korea, Singapore, Israel. They share now and then, without belonging to the formal alliance.

What these alliances technically do

Three operational mechanisms:

  1. Database sharing: XKeyscore and similar, where each member feeds and queries.
  2. Bypassing domestic limits: if the NSA cannot legally spy on a US citizen, British GCHQ can do it and pass the data on. The ACLU has documented and challenged this practice.
  3. Mutual requests on cloud providers: a British warrant against a US cloud goes through a fast channel (reinforced MLAT).

For your cloud privacy, mechanism 3 is the key point. If Microsoft, Google or Apple receives a request from a 5 Eyes member, cooperation is almost automatic. If the request comes from a 9 or 14 Eyes member, delay and friction rise, but the outcome stays likely.

How does the CLOUD Act interact with 5/9/14 Eyes alliances in 2026?

Rows of servers in a data center
Rows of servers in a data center

Beyond intelligence alliances, three recent legal texts structure cloud access:

CLOUD Act (United States, 2018)

The Clarifying Lawful Overseas Use of Data Act lets US authorities require American companies (or those with a significant US entity) to provide data wherever it is stored worldwide. This covers Microsoft, Google, AWS, Cloudflare and Apple. A US federal warrant forces the parent company to deliver European customer data. The CJEU struck down Privacy Shield in July 2020 (Schrems II ruling), exactly because this CLOUD Act makes GDPR and US-based hosting clash.

The result in 2026: using Microsoft 365, Google Workspace or iCloud for sensitive data breaks your European privacy expectation in practice, whatever the physical datacenter location.

EU Data Act + DSA (European Union, 2023-2024)

The EU Data Act (in force 2024) requires cloud providers based outside the EU to name a European legal representative and to cooperate with national authorities. Together with the Digital Services Act (DSA, 2022) and Digital Markets Act (DMA), it creates a localization duty for "sensitive data". But it does not block the CLOUD Act on US actors.

The result: a cloud actor can be ordered at the same time by the US CLOUD Act and the EU Data Act, with no way to reconcile the two. This is exactly the grey zone in which Microsoft, Google and AWS have worked since 2024.

Swiss Intelligence Act (LRens, 2017, revised 2024)

The LRens lets the Federal Intelligence Service (SRC) request data access, but under three conditions that all apply at once: prior approval by a federal administrative tribunal, proven national interest, and documented proportionality. In 2024, the SRC's public report lists 172 formal requests, of which 43 were partially satisfied. There is no extraterritorial duty.

This gap is large: a factor of 30 to 50 between US and Swiss cooperation on request volumes. It explains why Proton and Tresorit have spoken so much about their Swiss jurisdiction since 2018.

The 2026 world map: where can your cloud really be?

CountrySIGINT statusCloud legal frameworkPrivacy verdict
United States5 EyesCLOUD Act, FISA 702, NSLAvoid for sensitive data
United Kingdom5 EyesInvestigatory Powers Act 2016Avoid (Snoopers' Charter)
Canada5 EyesBill C-26 (2024)Avoid
Germany14 EyesBND-Gesetz revised 2021Meh (Hetzner ok for standard use)
France9 Eyes2015 Intelligence Act + LPM 2023Meh (OVH ok for non-sensitive)
Spain14 EyesLey 11/2002 CNIMeh
SwitzerlandOutside 14 EyesLRens 2017 (independent tribunal)OK - reference
IcelandOutside 14 EyesIMMI 2010OK (narrow market)
PanamaOutside 14 EyesNo Data Retention LawOK (few consumer offers)
RomaniaOutside 14 EyesLaw 506/2004 lightOK (cheap datacenters)
NevisOutside 14 EyesConfidentiality Act 1985OK (Njalla, specialized VPS)
Norway (Svalbard?)9 Eyes formallyLRens-like framework on SvalbardOK with asterisk

This table looks only at the law that applies to storage. The law that applies to the owning legal entity of the provider matters just as much. Proton is Swiss (✅). Tresorit is Swiss but was bought in 2021 by Swiss Post (✅, neutral state, outside 14 Eyes). pCloud is Swiss (✅). MEGA is based in New Zealand (❌, 5 Eyes). Internxt is Spanish (14 Eyes, but its decentralized infrastructure makes legal enforcement harder).

Common myths to discard

Myth 1: "If I'm honest, I have nothing to hide"

This is a false argument that mixes up privacy with illegality. Your talks with your doctor, lawyer or tax advisor are legal. But if a third party sees them (employer, ex, insurer, foreign state actor), it can harm you in real ways. Privacy is not criminal secrecy. It is control over who gets to share your data.

Myth 2: "Germany is safe because GDPR"

Germany is a 14 Eyes member. The BND-Gesetz, revised in 2021, lets the German agency intercept traffic passing through Frankfurt and Berlin datacenters with no individual warrant. GDPR protects your data against abusive commercial use, not against intelligence access. That is a key difference.

Myth 3: "With a VPN, I'm untraceable"

A VPN hides your IP from the site you visit. But your cloud provider still sees your uploads, their volume and their timing. If the cloud is not zero-knowledge (see E2E vs zero-knowledge cloud storage), it also sees the content. VPN + non-zero-knowledge cloud = problem moved, not solved.

Myth 4: "Iceland is necessarily safe because IMMI"

IMMI is a forward-looking legal framework. But Iceland is a NATO member and cooperates informally with 5 Eyes through that channel. For journalist or whistleblower use, Iceland is still better than Sweden or France. Yet it ranks below Switzerland on how well its institutions are kept apart.

2026 practical strategy: jurisdiction × threat matching

Jurisdiction choice depends on your threat model:

  • Competitive/commercial threat (basic industrial espionage): Germany, France or Netherlands are enough. Their legal framework makes unauthorized access harder.
  • Foreign state surveillance threat (US citizen who fears the NSA, French citizen who fears the DGSE): Switzerland is a must, Iceland is acceptable.
  • Domestic state surveillance threat (activist, journalist or whistleblower facing their own state): Switzerland + zero-knowledge service + native clients + Tor access.
  • Post-quantum threat (long-term, encryption that may be broken tomorrow): pick a provider that uses hybrid PQC (Proton Mail has done so since 2024 with Kyber-768 + X25519). Jurisdiction matters less here, and the cryptographic model matters more.

The Priviy methodology applies this matching to each provider we test. We score jurisdiction, cryptographic model, independent audit and operational resilience on their own. No provider maxes out all 4 dimensions, so you must prioritize based on your threat.

Our 2026 verdict

For the majority of cloud privacy users in 2026, the winning combination is:

  • Swiss provider (Proton Drive by default, pCloud Crypto if you want lifetime)
  • Zero-knowledge client encryption verified by independent audit
  • Native desktop/mobile client rather than web app
  • Paper recovery key stored offline

For high-risk profiles, add:

  • Access via Tor or multi-hop VPN
  • Strict separation between public identity and protected identity
  • Redundant backups across two different non-14-Eyes jurisdictions

The real value of understanding 5/9/14 Eyes alliances is not getting paranoid. It is knowing how to read a provider's marketing. When pCloud writes "swiss-based servers", that is a jurisdictional claim you can check. When Dropbox writes "your data is secure", that is a contract promise with no jurisdictional backing. This difference is exactly what sets reliable cloud privacy apart from marketing cloud privacy.

For quick definitions of the key terms used in this article - jurisdiction, CLOUD Act, GDPR, Five Eyes, Swiss LPD, data residency - see our encrypted cloud and privacy glossary.


Article published June 4, 2026. Methodology: review of primary legal texts (declassified 1946 UKUSA, 2018 CLOUD Act, 2024 EU Data Act, 2017 Swiss LRens), cross-referenced with 2023-2024 transparency reports from Proton, Tresorit, pCloud, MEGA, Mailfence; SIGINT status verification via archived Snowden documents (The Guardian, Der Spiegel). No claim of own classified sources. Logs and notes archived internally.

To dig deeper, see whether iCloud is secure, whether OneDrive is secure and what data sovereignty means.

Frequently asked questions

What are the 5 Eyes, 9 Eyes and 14 Eyes alliances - and do they affect cloud privacy?
The 5/9/14 Eyes are tiered intelligence-sharing alliances. The 5 Eyes (US, UK, Canada, Australia, New Zealand) share raw signals data. The 9 Eyes add France, Denmark, Netherlands, Norway. The 14 Eyes add Germany, Belgium, Italy, Spain, Sweden. For cloud privacy, this matters: a provider based inside these alliances can be ordered by law to hand over data. That data can then flow to partner states.
What exactly are the 5 Eyes, 9 Eyes and 14 Eyes?
The 5 Eyes (FVEY) is the old signal intelligence sharing alliance. It was born from the 1946 UKUSA agreement: United States, United Kingdom, Canada, Australia, New Zealand. The 9 Eyes extend sharing to Denmark, France, Netherlands and Norway. The 14 Eyes (SIGINT Seniors Europe group) add Germany, Belgium, Italy, Spain, Sweden. These levels are tiered. A 5 Eyes member can access raw intelligence that a 14 Eyes member only sees in summary form.
If my cloud is hosted in France, who can access my data?
France is a 9 Eyes member. In practice, the DGSE can require access to data under the 2015 Intelligence Act (articles L.851 and following of the CSI). It also shares with other 9 Eyes members under bilateral agreements. So a cloud like OVHcloud, hosted in France, stays within the 9 Eyes perimeter. To escape 14 Eyes, pick a jurisdiction outside the alliance: Switzerland, Iceland, Panama, Romania, or a self-hosted cloud in Svalbard. Oddly, despite Norway's 9 Eyes status, Svalbard servers have a protective legal framework.
Does the US CLOUD Act apply to a European cloud?
Yes, if it's a subsidiary or operator whose parent company is American. Microsoft Azure, AWS and Google Cloud stay subject to the CLOUD Act (2018), even for data physically stored in Europe. A US judicial warrant can force the parent to deliver data. The CJEU struck down Privacy Shield in 2020 (Schrems II ruling), exactly because of this jurisdictional conflict. This is why Proton (Switzerland), Tresorit (Switzerland) and Mailfence (Belgium) speak loudly about their non-US jurisdiction.
Is Switzerland really outside 14 Eyes?
Yes. Switzerland never signed the UKUSA agreement or the SIGINT Seniors Europe protocols. The Federal Intelligence Service Act (LRens, 2017) allows international sharing. But it sits under an independent federal administrative tribunal, with a high bar. In practice, Proton Mail and Tresorit publish yearly transparency reports that show how isolated they are (Proton 2024: 4,920 state requests received, 2,105 partially satisfied, 0 deliveries of encrypted content). Switzerland stays the reference jurisdiction for cloud privacy in 2026.
Is Iceland really safe for hosting a cloud?
Yes, for legal and map-based reasons. Iceland adopted the Icelandic Modern Media Initiative (IMMI) in 2010. It is a legal framework that protects whistleblowers and journalists. Iceland has no formal SIGINT alliance, and its geothermal power draws datacenters. So it hosts providers like 1984 Hosting and OrangeWebsite. The limits: informal cooperation with 5 Eyes exists via NATO, and the market is narrow (few consumer offers). For personal use, the order is Switzerland > Iceland > Panama.
If I self-host my cloud, am I outside jurisdiction?
You reduce the attack angle but don't remove it. Self-hosting Nextcloud on a Hetzner VPS (Germany, 14 Eyes) or OVH (France, 9 Eyes) puts you under the VPS provider's jurisdiction. To really exit 14 Eyes, use a VPS at 1984 Hosting (Iceland), Njalla (Nevis), or Buyshared (Bulgaria, outside 14 Eyes). But self-hosting also means you own all the security (updates, TLS certificates, backups). A Nextcloud left unmaintained for 6 months becomes an open door, whatever the jurisdiction.
Choix éditorial
4.5 / 5

Store your files privately → pCloud

Swiss privacy · 10 GB free · optional zero-knowledge Crypto

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre