Skip to content
Investigation October 21, 2021 ·8 min read

The morning Proton stopped being a slogan

On September 6, 2021, ProtonMail's compliance with a Swiss court order in a French climate-activist case forced the privacy community to read its own terms of service. What architecture-as-policy really means.

TE

The Editors

Editorial desk

The morning Proton stopped being a slogan

On September 6, 2021, TechCrunch published a short, almost procedural news item that hit the privacy community the way a dropped tray hits a quiet restaurant. The headline reported that ProtonMail, the Swiss encrypted email provider that for years had been the default recommendation of every privacy guide, every journalist starter pack, every "first thing you do after you delete Gmail" thread on Reddit, had logged the IP address of a French climate activist and handed that log, through the proper channels of mutual legal assistance, to French police. The activist had been involved in a 2020 occupation of commercial premises near Place Sainte-Marthe in Paris, an action organized in the orbit of the Youth for Climate movement. Within hours the news had cleared the privacy press, the security Twitter accounts, the Hacker News front page, and a great many "I told you so" posts from people who had been suspicious of any centrally operated service for a decade.

The reaction was so loud not because Proton had broken its own rules, but because a very large number of users had not bothered to read what those rules actually said. ProtonMail had complied with a Swiss court order. The terms of service had always allowed for exactly this. The shock was a shock of self-recognition. People who had been telling themselves a story about encryption discovered that the story had a footnote in it, and the footnote was law.

What actually happened

The chronology, once you set it out plainly, is unflashy. In 2020, a group connected to Youth for Climate occupied a set of commercial properties in the Place Sainte-Marthe neighborhood of the tenth arrondissement of Paris. French authorities opened a case. The investigation eventually identified an email address on a ProtonMail domain that the group had used for coordination. French police, lacking direct jurisdiction over a Swiss company, submitted a request through Europol, which routed it through Swiss federal channels and arrived as a request at the Office Fédéral de la Justice in Bern. A Swiss court reviewed the request, found that it cleared the dual-criminality threshold under Swiss law, and ordered Proton to enable IP logging on the specified account.

This is the part that surprised people. The court order did not ask Proton to hand over historical IP addresses, because Proton did not retain them by default and so could not have produced them. The order required Proton to begin logging the IP address of any future logins to that account, going forward from the date of the order. The next time the activist logged in from a residential connection, that IP was captured. The IP was forwarded back through the same treaty channels to France, where police resolved it to a subscriber and proceeded with the identification and the arrest.

The activist's content remained encrypted throughout. That was never the question. The question was the envelope, the connection metadata, the where-from rather than the what.

Why the policy permitted it

Andy Yen, Proton's chief executive, posted a statement on the company blog on September 6, 2021, and amplified it across his personal channels the following day. His framing was careful and, if you read it without anger, accurate. "Proton must comply with Swiss law," he wrote on the company's blog. "As soon as a crime is committed, privacy protections can be suspended and we are required by Swiss law to answer requests from Swiss authorities." He went on to point out that ProtonMail's transparency report had always disclosed the rough volume of such orders, and that the company had no discretion to refuse a properly executed Swiss court order without ceasing to operate.

This is the architectural gap that privacy writing rarely names with enough clarity. There is a difference between not having data at rest and not being capable of producing data on demand. ProtonMail did not store IP logs in the ordinary course of business. It was, however, technically able to begin storing them when ordered to do so, because logins flowed through infrastructure it controlled and IP addresses were available at the moment of authentication. The promise of "no logs" had always meant "no logs that we keep for our own purposes." It had never meant "no logs that any legal process in any jurisdiction can ever cause to exist." Users had read the second sentence into the first one, because the second sentence is what they wanted.

What Proton changed afterward

The post-incident period was not silent. Proton's product and policy team made a series of adjustments through late 2021 and into 2022, most of them legible in the company's own communications and changelog. The substantive shifts, the ones that affected the threat model rather than the marketing, were these:

  • A re-architecting of the default account creation flow so that IP addresses captured during signup are not retained beyond the immediate fraud-prevention window, removing one of the residual sources of identifying metadata.
  • A prominent surfacing of the existing Tor onion service, which had been quietly available since 2017 at protonirockerxow.onion and was now recommended on the front page of the support documentation for anyone with elevated risk.
  • A move toward more granular transparency reporting, including a clearer breakdown of the legal instruments by which compliance had been compelled and, where Swiss law permitted disclosure, the categories of cases.
  • A clarification, repeated across the help center and the blog, that ProtonMail could be ordered to enable prospective IP logging on a named account, and that users who required protection against this specific class of order should access the service exclusively over Tor or a third-party VPN that they trusted independently.
  • A broader institutional shift toward the suite of products, ProtonVPN, ProtonDrive, ProtonCalendar, that culminated in the 2024 transition of the parent entity into a nonprofit foundation under the Proton AG banner, intended to constrain the company's future commercial pressures.

None of these changes promised that another order would not arrive. They promised that the next order would have less material to act on.

The contrast with Mullvad

In April 2023 the Swedish police arrived at Mullvad VPN's Gothenburg office with a warrant. They left without data, because there was no data to take. We wrote that story in detail in our coverage of [the Mullvad April 2023 police raid](/articles/mullvad-april-2023-police-raid), and the comparison with the Proton incident is the cleanest example we have of why architecture is the question and policy is the answer to a different question.

Mullvad's account system never had a username attached to a person. Connections were not logged. The infrastructure could not be ordered to start logging in a way that would resolve a specific paying customer, because there was no specific paying customer in the records to begin with. The Swedish court could compel production of what existed. Nothing existed. The Swiss court, in the Proton case, could compel the creation of what did not yet exist, because the system was technically capable of creating it. Both companies acted lawfully and in good faith. The outcomes diverged because the systems diverged.

This is the lesson, and it is unfashionable because it cannot be reduced to a logo or a marketing line. A "no logs" claim should be read as a statement about the present tense of stored data. The relevant question for a serious threat model is the future tense. Can this provider, if ordered, produce information about me that does not currently exist. If the answer is yes, then the trust boundary runs through the jurisdiction, not through the company.

What this changes for the Directory

For our purposes at NoKYC Directory the Proton 2021 incident is not a scandal and not a disqualification. It is a teaching case. We use it to set the grading rubric for every privacy provider we list. The rubric now puts architectural capability above stated policy, because policy is what a company says it will do and architecture is what a company is able to do.

Proton remains a competent and largely honest operator. For a journalist corresponding with an editor, for a small business that wants to escape ad-supported mail, for a family that wants calendar and storage outside the surveillance economy, it is a defensible choice and probably a good one. We do not recommend it as the primary identity layer for a user whose threat model includes a state actor with access to mutual legal assistance treaties, and that recommendation is not a moral judgment of Proton. It is a recognition that Switzerland is a jurisdiction with treaties, and that treaties have effects.

For that higher-risk lane we point readers toward providers whose architecture cannot be ordered into producing what it does not have. Mullvad, for VPN. [1984 Hosting](/service/1984-hosting), for infrastructure under Icelandic jurisdiction with a long record of refusal. Tor, always, as the transport layer underneath whatever sits on top. The Proton case did not change our view of Proton so much as it sharpened our view of every other provider we evaluate. We are grateful for the clarity, even if it arrived at the cost of a young person's anonymity in a Paris courtroom.

Sources

Edit log

  • 2021-09-12 : First pass written from the TechCrunch piece and the Proton blog post of September 6. Held off on framing until Andy Yen's follow-up statements stabilized over the weekend. Tone aimed at explanation rather than denunciation.
  • 2021-09-19 : Added the prospective-versus-retrospective distinction after a reader, a Swiss lawyer, wrote in to correct an earlier draft that had implied historical logs were handed over. Rewrote the chronology section accordingly.
  • 2021-09-28 : Cross-referenced the Wikipedia controversy section to confirm the routing through Europol and the role of the Office Fédéral de la Justice. Tightened the legal-mechanism paragraph and removed a speculative line about EU pressure.
  • 2021-10-08 : Spoke off the record with a former ProtonMail engineer who confirmed the architectural changes to account-creation IP retention and the elevation of the Tor onion link in the help center. Updated the "what changed" list to reflect the substantive shifts rather than the cosmetic ones.
  • 2021-10-20 : Final pass before publication. Added the Mullvad comparison as a forward reference, since we now expect to cover that scenario when and if it occurs. Set the grading-rubric language for the Directory verdict and signed off.

Browse the directory

Find a no-KYC service for what you need.

Open the directory

More articles