Brussels — 12 Aug 2026. The European Commission published final guidance on Aug. 12, 2026, requiring app stores to collect and surface explicit disclosures from VPN apps distributed in EU member states about server operator locations, third‑party hosts, logging and retention practices, and how providers respond to lawful requests. The measure, aimed at improving consumer transparency and policing deceptive "no‑logs" marketing, applies to apps on the Apple App Store, Google Play and other marketplaces available to EU users; app‑store operators issued developer instructions on Sept. 1, 2026, and vendors have until Dec. 31, 2026 to meet the new metadata requirements or face delisting starting Jan. 15, 2027.

Why this matters now

The final guidance formalizes a leaked draft first reported in July 2026 and turns transparency proposals into operational requirements tied to Digital Services Act (DSA) obligations and the Commission's consumer‑protection agenda. For privacy‑minded users the change promises comparable, machine‑readable facts at the point of download; for vendors it imposes fast deadlines for operational mapping, contract updates with cloud and datacenter partners, and proof‑backed marketing.

What the final guidance requires

The Commission's document narrows and formalizes the draft's items. Key obligations in the Aug. 12 text are:

  • Server‑operator disclosure: a labeled list of countries where a provider or its subcontractors operate servers that may terminate EU user traffic;
  • Third‑party operator identification: names of subcontractors (cloud providers, reseller hosts, CDN partners) that operate exit nodes or routing infrastructure, with links to their published policies;
  • Logging and retention statements: standardized, machine‑readable statements on whether connection or usage logs are kept, retention periods, and the legal basis (e.g., contract, legitimate interests, legal obligation);
  • Law‑enforcement compliance profile: high‑level description of jurisdictions whose orders could compel disclosure and the provider's process for handling requests (e.g., court orders, MLATs);
  • Verification artifacts: links to recent independent audit reports, server‑attestation evidence (RAM‑only attestations, TEE use), or instructions on how a customer can independently verify claims.

How enforcement and timelines work

Rather than creating a new EU‑level inspection agency, the Commission relies on existing DSA enforcement and app‑store self‑policing. The guidance requires app‑store operators to reject or delist apps that omit required metadata fields for EU storefront listings. Apple and Google published developer guidance on Sept. 1, 2026 adding dedicated metadata fields for "VPN Transparency" and warned developers that noncompliance could result in removal from EU app stores beginning Jan. 15, 2027. National consumer protection authorities and digital‑services coordinators will be able to request proof of compliance and escalate violations under the DSA framework.

What we found: compliance snapshot (Aug–Sep 2026)

VPN Security Review conducted a baseline audit between Aug. 20 and Sept. 8, 2026 of the top 150 VPN apps by EU downloads (Apple EU/Google Play EU). Findings:

  • 48% (72 apps) published complete disclosures matching the new metadata fields, including third‑party operator names and links to attestations;
  • 36% (54 apps) provided partial disclosures (server countries listed but missing subcontractor names or verification artifacts);
  • 16% (24 apps) had no EU‑specific disclosures and required app‑store metadata updates before the Dec. 31 deadline.

Large vertically integrated providers (e.g., providers that operate their own hardware footprint) adapted fastest; smaller "reseller" models and services that layer on major cloud providers were most likely to be noncompliant or to limit advertised locations.

Industry and advocacy reactions

The European Digital Rights (EDRi) network welcomed the guidance. In a Sept. 3, 2026 statement, EDRi called the measure "a necessary step to curb misleading marketing." Apple and Google declined to comment beyond their developer notes; both companies pointed developers to the Commission text and to the new EU metadata schema.

"Transparency at download will change buyer expectations," said Kasia Nowak, editor‑in‑chief at VPN Security Review. "But disclosures are only the first step — robust auditing, reproducible attestations and contractual rights to verify subcontractors are what will shift engineering."

VPN trade groups urged pragmatism. The European Cloud & Connectivity Association (ECCA) recommended that the Commission clarify acceptable attestation formats and allow grace periods for smaller vendors to obtain third‑party audit evidence.

Practical impact for providers and users

Providers: expect immediate operational work. Our advisory work with five mid‑size vendors found common tasks required to meet the EU fields:

  • Inventorying instances across cloud regions and mapping which IPs are provisioned by subcontractors;
  • Updating contracts with cloud/datacenter partners to allow publication of locations and to permit technical attestations or audits;
  • Publishing standardized, concise retention statements and linking to full privacy and law‑enforcement response procedures;
  • Commissioning independent audits or producing verifiable RAM‑only server attestations where feasible.

Users: the immediate benefit is clearer side‑by‑side information at the point of download. Expect some smaller providers to remove dubious location claims (for example, "100 countries") until they can substantiate where exit traffic may actually be handled.

Updated recommendations — what VPN providers should do right now

  1. Complete an infrastructure audit by Oct. 31, 2026 that maps server operators, subcontractors and geographic footprints with IP ranges tied to each host.
  2. Negotiate contractual amendments with cloud and datacenter partners before Nov. 30, 2026 to permit location disclosure and to allow technical attestations or audits.
  3. Publish short, standardized metadata for app stores (use the EU metadata schema fields) and maintain a machine‑readable disclosure document linked from app pages.
  4. Obtain an independent audit or produce reproducible attestations (RAM‑only, ephemeral instances, or TEE evidence) and make executive summaries available to users.
  5. Prepare customer communications explaining any changes to advertised locations or marketing language before Dec. 15, 2026.

What's next — what to watch

  • Dec. 31, 2026: vendor compliance deadline. Vendors that miss it risk delisting in EU app stores starting Jan. 15, 2027.
  • Q1 2027: first national enforcement actions under the DSA for noncompliant apps; expect consumer authorities to focus on repeat offenders and misleading "no‑logs" claims.
  • 2027: potential push for a standard verification format. Industry coalitions and consumer groups are already discussing a machine‑readable attestation standard to avoid fragmentation.

Frequently asked questions

Does this rule affect desktop or router VPN clients?

The guidance targets app stores and mobile distribution channels, so desktop clients downloaded directly from vendor sites are not subject to the app‑store metadata requirement. However, the Commission explicitly encouraged consistent public disclosures across all platforms; national consumer laws could still apply to misleading claims on vendor websites.

Will publishing server locations make users less private?

Publishing the countries where servers operate does not, by itself, expose individual users. The disclosures are about operator jurisdiction and subcontractor relationships, not live user logs. That said, providers should avoid publishing detailed per‑server identifiers that could facilitate targeted legal orders or attacker mapping; the guidance permits aggregated lists (by country and operator).

How will app stores verify claims?

App stores will perform metadata completeness checks and may request supporting artifacts (audit summaries or attestations). The Commission expects app stores to rely on a mix of automated schema validation and manual review. National authorities retain the power to request proof and pursue enforcement where claims appear false.

What if my VPN uses cloud providers in multiple regions?

Disclose the cloud provider names and the countries where traffic may exit or be terminated. If your infrastructure is dynamic, explain the operational model (e.g., ephemeral instances in cloud regions) and provide the legal basis for any retention. Contracts with cloud providers should permit the publication of this information.

VPN Security Review will publish a downloadable compliance checklist and a sample machine‑readable disclosure template on Sept. 15, 2026. Providers and buyers should monitor national DSA coordinators for enforcement updates in Q1 2027.