Comments on ISOC’s draft policy brief, ‘VPN Restrictions’ (2026)
by Piyush Mathur
As a member of the Internet Society (ISOC), I have been offered the opportunity to go over its draft policy brief on the practice of banning Virtual Private Networks (VPNs). As many Thoughtfox readers will be aware, VPNs allow their users to conceal their Internet Protocol (IP) address, physical location, and browsing activity, whereby elevating the users’ level of security, safety, and privacy in the digital world. But for the same reasons, these networks may also inconvenience civil administrators and other authorities, who may also fear losing control over what people say (and do) in the digital sphere.
Ergo, for motives that may not even be legal, leave aside justifiable in other ways, authorities may venture to disable particular capabilities of VPNs, block some or all such networks within particular jurisdictions, or restrict their usage in particular ways and/or for particular durations. Indeed, governments as diverse as those of China, India, Iran, Russia, Syria, Pakistan, Turkey, and the United Kingdom (UK), among several others, have been having different levels and/or types of issues with VPNs. They have thus been seeking to control VPNs or have already been controlling access to them in specific ways.
But inasmuch as VPNs are a component of the global Internet infrastructure, controlling them inevitably translates into controlling the Internet itself—which is but a vehicle for expression. Founded to promote an open, seamless, and affordable Internet, ISOC has opposed this restrictive, authoritarian approach to VPNs; its draft policy brief, thrown open to wider consultation, underscores its commitment to Internet freedoms. The draft is very clear overall and very much needed; but in my personal opinion, a tiny aspect of it could use greater clarification and nuance—and I get into those details in the rest of this short piece. (In a summary form, I have shared this opinion with ISOC.)
How ISOC may improve its draft policy brief on VPN bans and restrictions
In the draft, a key solution-oriented statement pleading policy makers not to interfere with VPNs includes the following two sentences of recommendation: ‘Address the issue at the source. The least damaging approach for the Internet is to address illegal content and activities at their origin.’ As a statement of principle, it is difficult to disagree with that recommendation—in that measures directed at the underlying unlawful conduct should always have to be preferred over broad restrictions on general-purpose Internet technologies; yet the phrases ‘the source’ and ‘origin’ risk obscuring an important practical distinction.
Assuming that ‘the source’ or ‘origin’ is meant to refer to some composite human-machine unit, i.e., a person or team of persons using some digital equipment, say a computer, to put out illegal content, then of course it is far better to trace out and discipline or punish that source/origin than to impose a ban on the digital tunnel (or VPN) used to transport it. The latter action will hinder the activities of millions of legitimate users while hoping to discourage some bad actors. What is obscured here, however, is the fact that in many instances the very reason VPNs feature in these debates is that they conceal or manipulate the network trail that might otherwise assist investigators in identifying the source/origin of an illegal piece of content/activity.
Where the alleged illegality lies precisely in publishing or accessing content via the Internet, identifying the relevant actor may itself depend upon information that VPNs are designed to shield. This does not invalidate the broader policy argument against interfering with VPNs; it just highlights the distinction between a desirable enforcement objective and the practical means of achieving it. ‘Addressing the issue at the source’ is not a self-executing solution, but an aspiration that may be significantly complicated by the technical realities of online anonymity and associated privacy softwares. A policy brief should not make the reader come out with a naive sense that alternatives to VPN restrictions or bans are simple or straightforward.
Getting to ‘the source’ of an aggressively concealed or camouflaged online activity often requires highly targeted investigative techniques, cooperation from service providers, account-level evidence, financial records, endpoint forensics, or operational errors by offenders. While stressing that these administrative challenge should not be used to justify imposing broad restrictions on VPN-related software services or hardware), ISOC’s brief should admit that VPNs do impede fast attribution. Such a move would allow ISCO to signal that its policy preference remains coherent even if the enforcement pathway is neither simple nor guaranteed.
ISOC could go further and sweeten its advisory pill (if I may use that verbiage) by appending a robust, briefly descriptive, list of justifiable administrative/policing alternatives to VPN bans or interferences. Those alternatives are far from unknown, of course; however, mentioning them in the brief might strengthen its appeal to global policy makers, law enforcers, ordinary technology watchers as well as cybersecurity professionals. The alternatives should have to include device forensics; cross-network metadata correlation; court orders to obtain relevant data from VPN providers; Open Source Intelligence (OSINT); covert online sleuthing; Blockchain analysis; financial record investigation; platform records; malware surveillance; and international policing cooperation on globally recognised infractions.
Last but not least, the draft brief makes no mention of VPN bans practised by private players. For instance, for one reason or another, Hulu, Netflix, and the British Broadcasting Corporation’s iPlayer, among others, have indulged in banning VPN users attempting to access their services. While private players—such as streaming services and VPN providers—may resolve access disputes through the courts, ISOC might like to acknowledge in its brief this dimension of the whole VPN discourse as it would make the document more nuanced; it does not have to take a position on it either way.
On a related note, the brief might also consider mentioning special-case scenarios whereby a VPN service or the VPN-enabled aspect of a digital service may have to be restricted or forced to discontinue. In this regard, readers of the brief will benefit from learning from the past about how a VPN may be abused by its provider—and what policy makers could do about it within the framework of a general preference for not interfering with VPN services. I have in mind here the recorded abuse by Meta of its erstwhile VPN service, Onavo, as well as Facebook Research.
Readers should note that they, too, can give their feedback (until July 29, 2026) to ISOC on the draft policy brief via this online form (which includes a link to the document itself): https://www.internetsociety.org/community/news-and-opportunities/community-consultation-open-on-vpn-restrictions-policy-brief
Piyush Mathur, Ph.D., is a member of the Internet Society and the Coalition for Independent Technology Research (CITR). The opinions expressed in this piece are his own and are not meant to represent any organisation.
See also his ‘Review: ‘Internet Shutdowns in Africa (2025).’