Originally reported by Sam Bent
TL;DR
Analysis of Proton's transparency reports reveals the company has complied with 94% of over 40,000 government data requests since 2017, including cases that helped law enforcement identify protesters. This compliance rate contradicts Proton's public messaging about protecting user privacy from surveillance.
This reveals a significant gap between Proton's privacy marketing and actual data sharing practices, affecting user expectations and operational security for privacy-conscious users.
Security researcher Sam Bent's analysis of Proton's own transparency reports reveals a substantial disconnect between the company's privacy-focused marketing and its actual data sharing practices with government entities.
According to Bent's examination of Proton's published documents, the Swiss-based company has responded to over 40,000 government data requests since 2017, maintaining a 94% compliance rate. This figure encompasses requests from law enforcement agencies across multiple jurisdictions, including cases where user data helped identify protesters and activists.
Bent highlights a specific incident where Proton provided user data that assisted FBI investigations in unmasking a protester's identity. Following public scrutiny of this case, Proton initially denied the extent of their cooperation before their transparency reports contradicted these public statements.
The discrepancy between Proton's public denials and documented compliance rates raises questions about the company's transparency regarding their data sharing practices with law enforcement.
For security practitioners and privacy-conscious users, these findings underscore critical operational considerations:
Proton operates under Swiss jurisdiction, which requires compliance with lawful data requests. However, the 94% compliance rate suggests limited use of available legal challenges or data minimization practices that could reduce successful request outcomes.
The transparency report data indicates that while Proton markets itself as a privacy-first service, its operational reality involves substantial cooperation with government surveillance requests across multiple jurisdictions.
Originally reported by Sam Bent