Tech

Free VPNs can carry hidden privacy and security trade-offs

Engadget says the provider’s business model, data practices and security controls matter more than whether a VPN is free.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Engadget · View original source
Man using a laptop beside blue VPN security graphics showing locks, servers, and network symbols.
Digital privacy

Free VPN services are not automatically unsafe, but their value depends on the provider behind them and the limits attached to the plan, according to an assessment by Engadget. Some reputable companies offer restricted free tiers to attract future paying subscribers, while other services may rely on advertising, collect user information or provide little clarity about how they generate revenue.

A VPN routes internet traffic through its own server and encrypts the connection between the user’s device and that server. This can reduce what an internet provider or Wi-Fi operator sees and can make websites see the VPN server’s public IP address instead. It does not provide complete anonymity, however, as websites can still identify users through accounts, cookies, GPS data and other identifiers.

Free plans may impose speed caps, data limits and smaller lists of server locations. Some websites, streaming platforms and workplace systems also block VPN connections. The Federal Trade Commission has warned that VPN providers can access internet traffic passing through their services, while some free apps may use advertising or share information with third parties.

The risks are illustrated by a 2026 NDSS study of 281 popular Android VPN apps. Researchers found that 29 leaked user traffic outside the VPN tunnel, 61 transmitted some data without encryption and 76 sent Android Advertising IDs, which can be used for tracking. The study covered Android apps only, so its figures cannot be applied directly to VPNs on other platforms.

Users assessing a free VPN should examine its ownership, funding model and privacy policy, including what data is collected and how it is used. The Electronic Frontier Foundation recommends looking for independent security audits rather than relying solely on “no logs” claims. Providers should also identify the protocols they use, such as WireGuard or OpenVPN, and explain whether a kill switch blocks traffic if the VPN connection fails.

A limited free tier linked to a paid subscription can offer a clearer source of funding, but it is not proof that a provider is trustworthy. Conversely, an unlimited service with unclear ownership, revenue sources or data practices presents a less visible trade-off. A VPN also does not replace antivirus or anti-malware protection.

Continue reading

More from Tech

Read next: AI model proposes solution to 370-year-old royal cipher
Read next: Why IMAX 15/70 Cameras Are So Loud
Read next: Insight Partners keeps diversified strategy as AI capital crowds into OpenAI and Anthropic