The General Data Protection Regulation (GDPR) came into force in May 2018. Since then, European companies have had strict obligations regarding your personal data. But the GDPR doesn't cover everything — a VPN can play a complementary role.

What the GDPR protects

The GDPR grants you rights over your personal data collected by companies:

  • Right of access to your data
  • Right to rectification
  • Right to erasure (right to be forgotten)
  • Right to portability
  • Right to object

What the GDPR doesn't directly cover

The GDPR does not address, or addresses only in a limited way:

  • Your ISP's visibility into your traffic
  • Data collection by sites based outside the EU
  • Technical ad tracking (cookies, fingerprinting)
  • Interception of your communications by malicious third parties

How a VPN complements your data protection

Masking your IP address

Your IP address is considered personal data under the GDPR. A VPN masks your real IP address from the sites you visit, which limits direct tracking of your activity by advertising third parties — this does not, however, amount to guaranteed anonymity.

Encryption of data in transit

The GDPR imposes security obligations on companies, but it does not automatically encrypt your connection. A VPN does so systematically.

Reducing your ISP's visibility

Your internet service provider remains subject to certain legal obligations to retain connection data. A VPN encrypts your traffic, which reduces what your ISP can observe about your activity.

PureVPN and data protection

PureVPN applies a no-logs policy, verified by an independent audit conducted by KPMG, confirming that no identifiable user activity is retained.

Legal advice

Use a VPN not to circumvent the law, but to legitimately protect your privacy. In France, using a VPN is 100% legal.

Conclusion

GDPR and VPN are two complementary tools: the former provides the legal framework for how companies use your data, the latter technically strengthens the privacy of your everyday connection.