We have read a lot of articles about EU metadata retention law and what it means for VPN users. We read them for the same reason a food critic eats at a chain restaurant — not because we expected to learn anything, but because we wanted to understand exactly what the median reader is being served. The median is worse than we remembered. The same three sentences appear in article after article, phrased slightly differently, almost always wrong, and almost always written as though the last decade of European constitutional law simply did not happen.
This piece does not name the offenders. The point is not to shame individual publications — the point is that the error is structural, the incentives produce it mechanically, and a reader trying to understand their actual legal exposure on a European VPN server cannot get what they need from the conventional coverage. So: three sections. What everyone gets wrong. What is almost never said. And what we would write instead, in full, if we had to start from a blank page and explain this to a reader who deserves better than a compliance officer's rumor mill.
What They All Get Wrong
The shared error is temporal. Article after article treats the EU Data Retention Directive as a live instrument — something a European VPN provider must still comply with, something that still imposes a minimum retention period on "telecommunications metadata", something the reader should factor into their provider choice today. The Directive is routinely described in the present tense. Retention periods of six to twenty-four months are quoted as though they were current obligations. VPNs are ranked by the jurisdiction they operate in, with the implicit claim that a provider inside the EU is necessarily bound by these retention rules.
None of that is correct, and it has not been correct for over a decade. The Directive was struck down by the Court of Justice of the European Union in the *Digital Rights Ireland* judgment, handed down on 2014-04-08, on the grounds that blanket, indiscriminate retention of traffic and location data was a disproportionate interference with Articles 7 and 8 of the EU Charter of Fundamental Rights. The Court did not narrow the Directive. It invalidated it — *ex tunc*, from the beginning, as though it had never been valid law. Every subsequent attempt by member states to reintroduce blanket retention at the national level has run into the same court. *Tele2 Sverige* in 2016. *La Quadrature du Net* in 2020. *SpaceNet* in 2022. Each one reaffirmed, in increasingly specific terms, that general and indiscriminate retention of traffic and location data is incompatible with EU law.
The conventional coverage proceeds as if none of this happened. A typical article will mention the Directive, quote a retention period, and move directly to the part where it recommends a VPN outside the EU to avoid it. The recommendation might be sound for other reasons, but the reasoning is built on a ghost statute. When the reader then makes a provider decision using that framing, they are making a decision based on a law that does not exist against an adversary model that does not match reality. The specific error — and it is always the same error — is that the writer read one summary of the Directive at some point, never read the judgment that killed it, and has been recycling the pre-2014 framing ever since. The affiliate incentive reinforces this. A simple "the EU requires retention, therefore use our Panama-based partner" funnel converts better than four paragraphs about constitutional review, so the simple version is what gets written, and it gets written again, and again, by each new cohort of content writers copying the cohort before them.
What Is Almost Always Missing
What never appears in the conventional coverage is the thing that actually matters: national law. The Directive is dead, but retention obligations did not vanish with it. What replaced the single European framework is a patchwork of national statutes, each of which has been stress-tested individually against the CJEU case law, each of which survives in a slightly different shape, and each of which imposes different obligations on different categories of service provider. Germany's *Telekommunikation-Telemedien-Datenschutz-Gesetz* is not France's *Code des postes et des communications électroniques*. Sweden's post-*Tele2* retention regime is not Italy's post-*La Quadrature* regime. A VPN provider's actual legal exposure depends on which of these frameworks the courts of its host country apply to it, and whether the courts of that country classify a commercial VPN operator as an "electronic communications service" at all — a classification question that has gone different ways in different member states and is still unsettled in several.
The second missing piece is the distinction between retention and production. A retention obligation says "you must keep this data for N months." A production order says "you must give us this data now." The conventional coverage collapses these two into a single fear, and then handles both by recommending a provider that claims to retain nothing. But a provider that retains nothing can still be served with a forward-looking production order — a court or prosecutor can legally compel the operator to begin capturing traffic from a specific target going forward, regardless of what the retention policy said yesterday. This is the mechanism that actually matters in the case law. It is what the Court in *La Quadrature du Net* specifically carved out as permissible: targeted, judicially supervised retention of specific individuals, as opposed to blanket retention of everyone. The no-logs marketing frame does not engage with this at all, and the conventional coverage inherits that blindness wholesale.
The third missing piece is the question of who pays for the reader's confusion. Affiliate contracts for offshore VPN providers pay better than affiliate contracts for audited European providers. A framing that says "the EU is dangerous, go offshore" is worth more per click than a framing that says "your actual exposure is a function of a specific national statute applied to a specific provider classification, and here is the case law." So the first framing is the one that gets written. The reader thinks they are getting legal analysis. They are getting a funnel.
What I Would Say Instead
If we had to start over, we would not open with the Directive at all. We would open with the question the reader actually has — "what is my legal exposure if I connect to a commercial VPN server located inside the European Union in 2026" — and we would answer it the way a working lawyer would answer it, with the frame that actually controls the outcome.
The frame is: retention obligations are national, not European; they apply to classified categories of provider, not to every internet-adjacent business; and the operative risk is almost never the retention regime itself — it is the production mechanism that sits on top of it. Everything else follows from that frame.
On the jurisdictional question, we would draw the bridge explicitly. What Germany handles by classifying VPNs as *Telemediendienste* rather than *Telekommunikationsdienste* — and thereby routing them out of the strict retention obligations applied to traditional telecoms — is the same substantive question that France handles in the opposite direction, by reading its national transposition to cover a broader set of service providers and then relying on the CJEU-compatible "targeted retention" carveouts to narrow the practical obligations again. Two member states, same constitutional ceiling, different routes under it, different outcomes for a provider headquartered in each. The 14-eyes slogan cannot see any of this because it operates at the wrong layer.
On the threat model, we would be explicit. The adversary is not a faceless "the EU". The adversary is a specific prosecutor in a specific jurisdiction, with a specific production order, served on a specific provider, in a specific classification category, against a specific target who has already drawn attention. The capability is legal compulsion, not mass surveillance. The likelihood is a function of the user's activity — for an ordinary reader, vanishingly low; for a journalist, an activist, or a defendant in an ongoing investigation, meaningful. The exposure, critically, is not the data retained yesterday. It is the data the provider can be compelled to begin capturing tomorrow. A reader who understands this chooses a provider not on the basis of "where is the headquarters" but on the basis of "what is the provider's architecture for refusing, delaying, or technically defeating a forward-looking capture order, and has that architecture ever been tested in court."
That last question is the one the conventional coverage will not ask. It is harder to answer, it does not convert, and it leads the reader toward a smaller set of providers — the ones with published warrant canaries, the ones with RAM-only server architectures that have survived physical seizure, the ones whose legal team has actually fought a production order and disclosed the outcome. We would give the reader that list, with the case histories attached, and we would tell them plainly that the Data Retention Directive has been dead since April of 2014, that the articles citing it are citing a ghost, and that the real question — the national-law, provider-classification, production-order question — is the one they should have been asked to think about from the first sentence.