Sitemap

Privacy Under Siege: Why the EU’s VPN Crackdown is a Cybersecurity Suicide Mission

I will go to jail before I let any government ban my use of a VPN to protect myself and people I’m connected to from adversaries that are very real.

3 min readMay 1, 2026

--

In a recent address regarding the rollout of the EU Age Verification App, Henna Virkkunen described tackling the use of VPNs to bypass age gates as “an important part of the next steps.”

When you put that alongside everything else coming from governments and regulators, they mean banning VPNs.

Press enter or click to view image in full size

Henna Virkkunen is the European Commission’s Executive Vice-President for Tech Sovereignty, Security, and Democracy. A seasoned Finnish politician and former MEP, Virkkunen is now the primary architect of the EU’s digital enforcement strategy under the Digital Services Act (DSA).

Banning VPNs would devastate personal safety for a lot of people. VPNs encrypt internet traffic and mask location, which stops companies and hostile actors from monitoring activity, intercepting data, or building profiles that can be used against them. They also protect government officials from state-sponsored adversaries, though those same officials would likely ignore any ban when it suits “national security.

”VPNs are also used like “digital seatbelts” for remote workers and sensitive industries. By restricting them, the EU risks creating backdoors that leave corporate data and personal communications vulnerable to hackers and foreign intelligence.

Treating VPN use as “suspicious behaviour” flips democracy on its head, recasting privacy from a fundamental right into a loophole the state feels entitled to close in order to exert control.

Attempting to ban VPNs would lead to “over-blocking,” where the pursuit of a few “rule-breakers” results in legitimate international services and educational tools becoming inaccessible to the entire public.

Society is being reshaped and controlled in plain sight by governments and major tech companies that profit from it. If you think companies like OpenAI, reliant on favourable regulation and government contracts, care about identity and authentication in chatbots to keep people safe, you haven’t been paying attention.

Tech companies once fought hard against voluntary end user account verification for the purpose of online safety. I know because I pushed for it throughout the 2000s and co-founded the global standard that made it possible in 2004, and was told it was too expensive and unnecessary. What you now see with Twitter Verified comes from that idea, but it wasn’t implemented properly, which is another story.

My aim was simple: let platforms verify accounts so people can decide who or what to trust. If Instagram allowed it for example, you could choose whether to trust a video from a verified account to avoid deepfakes and disinformation, while others could ignore it and consume everything. The point is choice. Account owners choose to verify, and everyone else chooses who and what to believe. I conceived that long before it was technically possible and helped formalise it at the W3C, replacing PICS, the original content labelling system used so companies like Microsoft and Apple could help parents filter content, so I understand the full stack, the human behaviour around trust signals, and what actually works.

Everything we’re seeing from governments, regulators, and tech companies has nothing to do with child safety. None of these measures protect kids, but they are exactly what you would design if you wanted to control who can access what, monitor what people say, and restrict access based on that.

ID verification and persistent authentication, and banning VPNs point to a dystopian outcome, and when you put that alongside plans for state backed digital currencies, you end up with a world where they decide who communicates with who, who travels where, and who can move money.

I never argued that verification should be mandatory to access platforms, people, and information.

--

--

Paul Walsh
Paul Walsh

Written by Paul Walsh

MetaCert CEO. Passionate about Cybersecurity, Blockchain, Crypto, Snowboarding & Red Wine. Part of the AOL team that launched AIM. Co-founded 2 W3C Standards.