Skip to content
Privacy

Five Eyes Countries: Who They Are and What It Means for U.S. Privacy

By Veilock Team · Contributor · Published August 5, 2026 · 13 min read

Five Eyes Countries: Who They Are and What It Means for U.S. Privacy

Quick answer

The Five Eyes are Australia, Canada, New Zealand, the United Kingdom and the United States — a signals intelligence partnership built on the 1946 UKUSA Agreement. They share intelligence more deeply than any other grouping of countries, which means data you generate online can, under certain conditions, be collected and shared across all five states without a domestic warrant.

The Five Eyes alliance is a multilateral signals intelligence (SIGINT) partnership built on the UKUSA Agreement, first formalized in 1946. The five member countries are:

  • Australia (Australian Signals Directorate, ASD)
  • Canada (Communications Security Establishment, CSE)
  • New Zealand (Government Communications Security Bureau, GCSB; and New Zealand Security Intelligence Service, NZSIS)
  • United Kingdom (Government Communications Headquarters, GCHQ)
  • United States (National Security Agency, NSA)

These five nations share signals intelligence more deeply and routinely than any other grouping of countries in the world. The alliance’s name comes from a releasability caveat stamped on shared intelligence products: “AUS/CAN/NZ/UK/US Eyes Only.” Over time, that phrase shortened to “Five Eyes.” If you are a U.S. resident wondering what this means for your privacy, the short answer is that data you generate online can, under certain conditions, be collected and shared across all five member states without a domestic warrant.

What are the key facts about Five Eyes at a glance?

Member CountryPrimary AgencyRoleTreaty Basis
United StatesNSASIGINT collection, analysisUKUSA Agreement (1946)
United KingdomGCHQSIGINT, cyber intelligenceUKUSA Agreement (1946)
CanadaCSESIGINT, foreign intelligenceUKUSA Agreement (1948 accession)
AustraliaASDSIGINT, cyber operationsUKUSA Agreement (1956 accession)
New ZealandGCSB / NZSISSIGINT, security intelligenceUKUSA Agreement (1956 accession)

Key milestones at a glance:

  • 1943: — BRUSA Agreement formalizes signals intelligence sharing between the U.S. and U.K. during World War II
  • 1948: — Canada accedes to the UKUSA framework

The Nine Eyes grouping adds Denmark, France, the Netherlands, and Norway to the Five Eyes core. Fourteen Eyes extends further to include Belgium, Germany, Italy, Spain, and Sweden. Both broader groupings represent looser tiers of cooperation, covered in detail later in this article.

How did the Five Eyes alliance form?

Infographic showing Five Eyes and allied countries

The alliance’s roots run directly to World War II. The United States and United Kingdom were sharing signals intelligence informally well before any formal treaty existed, driven by the shared urgency of breaking Axis communications. The BRUSA Agreement of 1943 put that cooperation on paper for the first time, establishing protocols for sharing intercepted communications and cryptographic work.

When the war ended, both governments recognized that the intelligence infrastructure they had built was too valuable to dismantle. On March 5, 1946, U.S. and U.K. officials signed the UKUSA Agreement, creating a permanent bilateral framework for SIGINT sharing, joint collection priorities, and methods cooperation. The treaty’s existence was kept classified for nearly six decades.

The staged expansion followed quickly:

  1. 1948 — Canada accedes, becoming the third member

The long secrecy of the UKUSA Agreement is itself significant. For most of its existence, the treaty was not just classified but officially unacknowledged. Governments in all five countries routinely declined to confirm or deny its existence. The MIT Press analysis of the Five Eyes partnership notes that the accession dates and the staged expansion reflected both strategic trust-building and the practical need to integrate compatible signals collection infrastructure before granting full partnership status.

How is the Five Eyes alliance organized operationally?

Each member country contributes a designated lead agency for signals intelligence, and those agencies operate under the UKUSA framework as what the NSA formally calls “Second Parties,” meaning they receive the deepest level of access and reciprocal sharing. This is distinct from the wider network of “Third Party” partners, which have more limited and conditional access.

Hands organizing intelligence agency documents

National agencies and their primary roles

CountryLead AgencyPrimary Intelligence Function
United StatesNSASIGINT collection and analysis; global technical collection infrastructure
United KingdomGCHQSIGINT, cyber intelligence, and communications interception
CanadaCSEForeign signals intelligence and cybersecurity
AustraliaASDSIGINT, offensive and defensive cyber operations
New ZealandGCSB / NZSISSIGINT (GCSB) and domestic security intelligence (NZSIS)

The Australian Signals Directorate’s public history describes the alliance as built on mutual trust developed over decades of joint operations, shared technical standards, and compatible collection systems. That compatibility is not accidental. The UKUSA Agreement established common protocols for classifying and marking intelligence products, which is why the “Eyes Only” releasability caveat became the alliance’s informal name.

Operationally, the partnership works through shared databases, joint tasking of collection assets, and agreed-upon geographic divisions of responsibility. The NSA’s declassified UKUSA materials confirm the agreement covers mission-sharing and methods cooperation, though specific operational details remain classified. What is publicly known is that member agencies can task each other’s collection capabilities and share finished intelligence products with relatively few restrictions compared to any other international intelligence arrangement.

The National Geospatial-Intelligence Agency’s international cooperation framework illustrates how the alliance has expanded beyond pure SIGINT into joint analytic work, resource pooling, and coordinated responses to modern intelligence challenges including large-scale data analysis.

Pro Tip: The “Second Party” designation matters practically. When a U.S. agency shares data with a Five Eyes partner, that partner is not subject to U.S. constitutional protections for U.S. persons. This creates a legal gap that oversight advocates have repeatedly flagged.

What does Five Eyes do today?

The alliance has evolved well beyond its Cold War SIGINT roots. The Five Country Ministerial (FCM), established in 2013, is now the primary political coordination forum, bringing together interior and security ministers from all five nations annually. The FCM operates as a policy synchronization mechanism, not just an intelligence-sharing forum.

Current priority areas where public FCM statements and government pages confirm active collaboration include:

The FCM’s scope reflects a broader shift. As Britannica’s overview of Five Eyes notes, the alliance now functions as much as a synchronized policy platform as it does a technical intelligence operation. Ministers issue joint public statements, coordinate legislative approaches, and align regulatory responses to shared threats. That visibility is a deliberate choice: the FCM’s public communiqués serve as both policy signals and deterrence messaging.

What controversies and oversight issues surround Five Eyes?

The alliance’s history includes several high-profile controversies that shaped public understanding of what signals intelligence sharing actually means in practice.

Two professionals discussing privacy oversight

ECHELON

ECHELON was the name given to a global signals intelligence collection network operated by the Five Eyes nations, capable of intercepting satellite, telephone, and internet communications. A 2001 European Parliament report concluded that ECHELON existed and was used for both national security and, controversially, commercial intelligence gathering. The program’s existence was never officially confirmed by member governments at the time, though subsequent declassifications have made the general architecture of such collection systems a matter of public record.

The Snowden disclosures

In 2013, former NSA contractor Edward Snowden released documents revealing the operational scope of Five Eyes collection programs. The disclosures showed that member agencies were collecting bulk metadata and, in some cases, content from major internet platforms, and that this data was shared across the alliance. Programs like PRISM (NSA) and Tempora (GCHQ) became the subject of intense public and legal scrutiny.

Privacy International’s report on secret global surveillance networks documents how the Snowden disclosures revealed that Five Eyes agencies were sharing not just finished intelligence but raw collection data, raising serious questions about whether domestic legal protections could be circumvented by routing surveillance requests through a partner agency.

“The Snowden revelations demonstrated that intelligence agencies were using their international partnerships to access data about their own citizens that they would not have been legally permitted to collect domestically — a practice sometimes called ‘intelligence laundering.’” — Privacy International, Secret Global Surveillance Networks (2018)

Oversight frameworks

Each member country has formal oversight mechanisms, though their depth and independence vary:

  • United States: — The Foreign Intelligence Surveillance Court (FISC), the Privacy and Civil Liberties Oversight Board (PCLOB), and congressional intelligence committees provide judicial and legislative oversight of NSA activities
  • Australia: — The Inspector-General of Intelligence and Security (IGIS) and the Parliamentary Joint Committee on Intelligence and Security oversee ASD

Critics, including Privacy International, argue that these national oversight bodies have limited visibility into cross-border sharing arrangements, creating accountability gaps precisely where the alliance’s most sensitive activities occur.

How do Nine Eyes, Fourteen Eyes, and other groupings differ from Five Eyes?

The Five Eyes is the innermost and most deeply integrated tier of a layered international intelligence architecture. Two broader groupings are frequently referenced in privacy and security discussions.

Nine Eyes adds four countries to the Five Eyes core: Denmark, France, the Netherlands, and Norway. These nations share intelligence with the Five Eyes members under bilateral and multilateral arrangements, but they are not parties to the UKUSA Agreement and do not have the same depth of access or reciprocal obligations as the five core members.

Fourteen Eyes extends the network further, adding Belgium, Germany, Italy, Spain, and Sweden to the Nine Eyes group. The Fourteen Eyes grouping, sometimes called SIGINT Seniors Europe (SSEUR), represents a forum for coordinating signals intelligence priorities among Western allies rather than a deep integration arrangement.

Privacy International’s Five Eyes explainer is direct about the practical difference: Five Eyes members operate as a single integrated intelligence community for most purposes, while Nine and Fourteen Eyes partners participate in more selective, topic-specific sharing.

What this means in practice:

  • Five Eyes: — Joint technical infrastructure, shared databases, reciprocal collection tasking, near-seamless intelligence product sharing

The distinction matters for privacy. Data held by a Five Eyes member is, for practical purposes, accessible to all five. Data held by a Nine or Fourteen Eyes partner is shared more selectively and under different legal frameworks.

What does Five Eyes mean for your privacy as a U.S. resident?

For most people in the United States, Five Eyes surveillance is not a targeted threat. The alliance’s collection priorities focus on foreign intelligence, counter-terrorism, and state-level threats. That said, the infrastructure built for those purposes is broad, and ordinary internet users generate data that passes through it.

The practical threat model for a U.S. resident looks like this:

  • Cross-border routing: — Internet traffic frequently routes through cables and infrastructure in other Five Eyes countries, where it may be subject to collection under that country’s laws

Here are the most effective steps U.S. residents can take to reduce their exposure:

  1. Choose a no-logs VPN. A VPN with a verified no-logs policy means the provider has no records to hand over if served with a legal request. Veilock’s no-logs policy is built around this principle: no connection timestamps, no IP addresses, no browsing activity stored.
  2. Enable two-factor authentication (2FA) on all accounts — Account compromise is a far more common vector for data exposure than signals intelligence collection for most people.

Pro Tip: A VPN is most effective when the provider is based outside Five Eyes jurisdictions and holds no logs. A VPN provider based in the U.S., U.K., Canada, Australia, or New Zealand is subject to legal orders from those governments. Veilock’s architecture is designed with this in mind. For a deeper look at how VPNs function as shields against surveillance, the trade-offs are worth understanding before you choose a provider.

Legal note: VPN use is legal in the United States. For a full overview of the applicable legal framework, see Veilock’s guide on VPN legality in the U.S. Signals intelligence law is complex and subject to change; consult a qualified attorney for advice specific to your situation.


If you want a practical tool that addresses the risks described above, Veilock offers a no-logs VPN with AES-256-GCM encryption, DNS-over-HTTPS, and Vortex threat blocking, starting at $4.46/month. Plans are available at veilock.com.

Veilock VPN app connected on a laptop and phone

Explore Veilock’s full feature set to see how each capability maps to the threat model described in this article.


Key Takeaways

The Five Eyes alliance is the world’s most deeply integrated intelligence-sharing partnership, built on the 1946 UKUSA Agreement and now operating across SIGINT, cybersecurity, and ministerial-level policy coordination.

PointDetails
Five member countriesAustralia, Canada, New Zealand, the United Kingdom, and the United States form the alliance under the UKUSA Agreement.
Founded in 1946The U.S. and U.K. signed the UKUSA Agreement on March 5, 1946; Canada joined in 1948, Australia and New Zealand in 1956.
Deeper than 9 EyesFive Eyes members share joint infrastructure and databases; Nine and Fourteen Eyes partners have looser, more selective arrangements.
Snowden disclosures changed the debate2013 revelations showed bulk collection and cross-border data sharing that raised questions about domestic legal protections.
Practical privacy steps existNo-logs VPNs, end-to-end encryption, DoH, and minimal data sharing reduce exposure, though no single tool eliminates all collection vectors.

Why Five Eyes surveillance deserves more attention than it gets

Most coverage of the Five Eyes alliance focuses on the dramatic: leaked documents, spy programs with code names, and geopolitical maneuvering. That framing misses something more important for ordinary people. The alliance’s real significance is structural. It means that the legal protections you rely on as a U.S. resident, specifically the Fourth Amendment’s warrant requirements, apply to what U.S. agencies do domestically. They do not automatically apply to what a partner agency collects abroad and then shares with the NSA.

That gap is not a bug in the system. It is, by design, how the alliance creates value for its members. Each country collects under its own legal framework, and the shared product flows across borders under the UKUSA framework rather than domestic constitutional law. Oversight bodies in each country have acknowledged this dynamic, and some have pushed for reforms. Progress has been slow.

The practical implication is that the threat model for a privacy-conscious U.S. resident is not “will the NSA target me?” It is “what data do I generate that passes through Five Eyes infrastructure, and under what conditions could it be accessed?” That is a more tractable question, and the answer points toward specific, concrete steps: encrypted communications, no-logs VPN services, careful cloud choices, and reduced metadata exposure.

Veilock’s tools are built around exactly this threat model. The no-logs architecture, AES-256-GCM encryption, and DNS-over-HTTPS are not marketing features. They are direct responses to the collection vectors that the public record, including declassified documents and the Snowden disclosures, has confirmed are real. Understanding the Five Eyes alliance is the first step. Choosing tools that account for it is the second.

Useful sources and further reading

These primary sources and authoritative overviews were used to build this article. Each is worth consulting directly if you want to verify specific claims or read deeper.

  1. UKUSA Historical Releases — NSA: The NSA’s own declassification archive, including the original UKUSA Agreement text and related documents. The definitive primary source for dates, legal framing, and the agreement’s structure.

  2. Why the Five Eyes? Power and Identity in the UKUSA Partnership — MIT Press / Journal of Conflict Resolution: Academic analysis of the alliance’s formation, accession dates, and the strategic logic behind its membership. Useful for the history and origins sections.

  3. Intelligence Partnerships — Australian Signals Directorate: ASD’s own account of its role in the Five Eyes and its relationship with partner agencies. Authoritative for agency roles and the alliance’s operational culture.

  4. Five Country Ministerial — Public Safety Canada: The Canadian government’s official page on the FCM, including background on its mandate and recent ministerial topics. Best source for the alliance’s modern political coordination function.

  5. Five Eyes — Privacy International: A concise explainer on the alliance’s structure, the difference between Five, Nine, and Fourteen Eyes, and the privacy implications. Useful for the related groupings section.

  6. Secret Global Surveillance Networks — Privacy International (report): Detailed analysis of intelligence-sharing arrangements and their implications for human rights and oversight. The source for the “intelligence laundering” concept and oversight critique.

  7. Five Eyes — Britannica: A reliable secondary overview covering membership, history, and the alliance’s contemporary role. Good starting point for readers new to the topic.

  8. NGA International Cooperation — National Geospatial-Intelligence Agency: Illustrates how the alliance’s mission has expanded beyond SIGINT into joint analytic and geospatial intelligence work.

  9. Newly Disclosed Documents on the Five Eyes Alliance — Yale Law School: Legal analysis of recently disclosed Five Eyes documents and what they reveal about intelligence-sharing obligations and limits.

  10. Veilock No-Logs VPN: Veilock’s explanation of its no-logs architecture and what it means for users concerned about data retention and Five Eyes data requests.

  11. Veilock Transparency Report and Warrant Canary: Veilock’s public transparency materials, including its legal response record. Useful for readers who want to assess a VPN provider’s accountability practices before subscribing.

Frequently asked questions

Which countries are in the Five Eyes?

Australia (Australian Signals Directorate), Canada (Communications Security Establishment), New Zealand (Government Communications Security Bureau), the United Kingdom (GCHQ) and the United States (National Security Agency).

What is the difference between Five Eyes, Nine Eyes and Fourteen Eyes?

Five Eyes is the innermost tier, whose members are treated as 'Second Parties' with the deepest reciprocal access. Nine Eyes and Fourteen Eyes are progressively wider intelligence-sharing groupings whose members have more limited and conditional access to shared material.

When was the Five Eyes alliance formed?

It was formalized by the UKUSA Agreement in 1946, building on the 1943 BRUSA Agreement between the United States and the United Kingdom. Canada, Australia and New Zealand joined in the years that followed.

Does Five Eyes affect my privacy as a U.S. resident?

For most people it is not a targeted threat — collection priorities focus on foreign intelligence and state-level threats. The structural issue is that Fourth Amendment warrant protections govern what U.S. agencies do domestically, not what a partner agency collects abroad and then shares.

Does a VPN protect against Five Eyes surveillance?

A VPN encrypts traffic between your device and the VPN server and hides your browsing from your ISP, but it is not a blanket shield against state-level signals intelligence. A provider with a verified no-logs policy has no records to hand over if served with a legal request, which is the part of the threat model a VPN actually addresses.

Get Veilock and put this into practice

Fast, no-logs, censorship-bypassing VPN — plans from $4.46/month.