Back to the Norton VPN review

Research record

What the public record says about Norton VPN privacy and security

We read what auditors, courts, security researchers and the press have published about Norton VPN, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
25
Cleared for this page
4
Separate sources behind them
6
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Ownership and jurisdiction

Where the company is incorporated, who owns it, and which laws reach it.

Sources agree

Norton VPN is operated by Gen Digital Inc., a Delaware corporation with dual headquarters in Tempe, Arizona (United States) and Prague (Czech Republic); the European contact for Norton privacy is NortonLifeLock Ireland Limited, Dublin.

2 separate sources: Gen Digital Inc. / SEC EDGAR and TechTarget

Sources and caveats (3)
  1. Gen Digital Inc. / SEC EDGAR · Provider own statement · No publication date stated

    With dual headquarters in Tempe, Arizona, and in Prague, Czech Republic, we have over 1,400 active employees located in the United States

    Counts toward the two-source rule

    Conflict of interest: Gen's own statement to the SEC, which carries legal liability for its accuracy, but it is still Gen describing Gen. Filing date not captured; the auditor report inside is dated 21 May 2026.

  2. Norton (Gen Digital) · Provider own statement · No publication date stated

    Europe: NortonLifeLock Ireland Limited – Privacy, Ballycoolin Business Park Blanchardstown, Dublin 15, Ireland

    Listed for context, adds no independence

  3. TechTarget · Press report · Published August 11, 2021

    The combined company from NortonLifeLock and Avast will be dual-headquartered in Arizona and Prague, and will serve 500 million users, including 40 million direct customers.

    Counts toward the two-source rule

Researcher notes

The 10-K cover page lists Delaware as the state of incorporation and Tempe as principal executive offices; those facts were read but the quote is the headquarters sentence. TechTarget's 2021 piece reports the planned dual headquarters at merger announcement (not a completion report); the 10-K confirms the arrangement in 2026. Privacy notice names Gen Digital Inc. (Tempe) as the global privacy contact and an independent EU DPO (Pembroke Privacy Ltd). Jurisdiction implication: a US-incorporated provider is subject to US legal process; Norton's own transparency report counts National Security Letters (T7-01). Czech/EU data-protection law applies to Gen's Czech operations (see T6-02). Data-retention law exposure was not analysed beyond that.

Sources agree

Gen Digital owns the Norton, Avast, AVG and Avira consumer brands; NortonLifeLock completed its acquisition of Avast on 12 September 2022 and renamed itself Gen Digital in November 2022.

2 separate sources: Gen Digital Inc. / SEC EDGAR and SecurityWeek

Sources and caveats (2)
  1. Gen Digital Inc. / SEC EDGAR · Provider own statement · No publication date stated

    which became effective upon the close of acquisition on September 12, 2022.

    Counts toward the two-source rule

    Conflict of interest: Gen's own statement to the SEC, which carries legal liability for its accuracy, but it is still Gen describing Gen. Filing date not captured; the auditor report inside is dated 21 May 2026.

  2. SecurityWeek · Press report · Published June 20, 2023

    Gen Digital (NASDAQ: GEN), the company behind known cybersecurity brands such as Avast, Avira, AVG, Norton, and LifeLock

    Counts toward the two-source rule

Researcher notes

Gen's IR release (read raw, 2022-09-02) said the close was expected 12 September 2022 following the CMA's final report clearing the deal. The 10-K states the September 2022 restructuring plan became effective on close. The name change date (7 November 2022) came from a search summary and was not read raw, so it is not relied on. Ownership matters for this ledger because the FTC and Czech actions in T6 concern Avast, now a Gen subsidiary. Gen's VPN products under those brands: Norton VPN and Avast SecureLine (VPN policy read raw); AVG Secure VPN and Avira Phantom VPN ownership by Gen rests on the brand list only.

Court cases and legal demands on the provider.

Sources agree

In February 2024 the US FTC announced, and in June 2024 finalised, an order requiring Avast (now a Gen Digital subsidiary) to pay $16.5 million and banning it from selling or licensing web browsing data for advertising, after alleging Avast sold browsing data collected through its antivirus software and browser extensions to third parties via its Jumpshot subsidiary from 2014 to 2020. Respondents neither admitted nor denied the allegations.

3 separate sources: US Federal Trade Commission, VICE Motherboard, and Gen Digital Inc. / SEC EDGAR

Sources and caveats (7)
  1. US Federal Trade Commission · Regulator record · Published February 21, 2024

    The Federal Trade Commission will require software provider Avast to pay $16.5 million and prohibit the company from selling or licensing any web browsing data for advertising purposes to settle charges

    Counts toward the two-source rule

  2. US Federal Trade Commission · Regulator record · Published June 27, 2024

    The Federal Trade Commission has finalized an order banning software provider Avast from selling, disclosing, or licensing any web browsing data for advertising purposes

    Counts toward the two-source rule

  3. US Federal Trade Commission · Regulator record · No publication date stated

    they neither admit nor deny any of the allegations in the Complaint, except as specifically stated in this Decision and Order

    Counts toward the two-source rule

    Conflict of interest: Consent order: respondents neither admit nor deny the allegations.

  4. US Federal Trade Commission · Regulator record · Published February 24, 2025

    The FTC is emailing notices to 3,690,813 consumers who bought antivirus software from Avast between August 2014 and January 2020.

    Counts toward the two-source rule

  5. Hunton Andrews Kurth LLP (Privacy & Information Security Law blog) · Analysis · Published February 29, 2024

    On February 22, 2024, the Federal Trade Commission announced a settlement order against Avast Limited

    Listed for context, adds no independence

    Conflict of interest: Law-firm client-alert blog; restates the FTC announcement.

  6. VICE Motherboard (joint investigation with PCMag) · Press report · Published January 27, 2020

    An antivirus program used by hundreds of millions of people around the world is selling highly sensitive web browsing data to many of the world’s biggest companies, a joint investigation by Motherboard and PCMag has found.

    Counts toward the two-source rule

  7. Gen Digital Inc. / SEC EDGAR · Provider own statement · No publication date stated

    reached a negotiated agreement on the terms of a Consent Decree resolving this investigation, the terms of which are now final. This includes a provision for a non-material amount of monetary relief, which has been paid.

    Counts toward the two-source rule

    Conflict of interest: Gen's own statement to the SEC, which carries legal liability for its accuracy, but it is still Gen describing Gen. Filing date not captured; the auditor report inside is dated 21 May 2026.

Researcher notes

Scope matters: the FTC case concerns Avast antivirus and browser extensions (Gen's 10-K says Avast announced the Jumpshot wind-down on 30 January 2020), predating Gen's September 2022 acquisition of Avast. It is NOT about Norton VPN or Avast SecureLine and the order text does not mention VPN. It is relevant as a documented history of the corporate parent's browsing-data practices; the order's injunctive terms (privacy programme, deletion of Jumpshot data) bind Avast and its subsidiaries. The 10-K calls the monetary relief "non-material amount" (immaterial to Gen), against $16.5M in the FTC's figure; both are right at different scales. Hunton restates the FTC release (FTC group). Independent groups: FTC (regulator), Motherboard/PCMag (original investigation that triggered the case), Gen 10-K.

pr_topic_other

pr_topic_lead_other

Sources agree

Between 2014 and 2020 Avast collected users' browsing data through its antivirus software and browser extensions and, through its Jumpshot subsidiary, sold it to more than 100 third parties; Avast wound Jumpshot down on 30 January 2020 after press coverage.

4 separate sources: VICE Motherboard, US Federal Trade Commission, Czech Office for Personal Data Protection, and Gen Digital Inc. / SEC EDGAR

Sources and caveats (4)
  1. VICE Motherboard (joint investigation with PCMag) · Press report · Published January 27, 2020

    The documents, from a subsidiary of the antivirus giant Avast called Jumpshot, shine new light on the secretive sale and supply chain of peoples’ internet browsing histories.

    Counts toward the two-source rule

  2. US Federal Trade Commission · Regulator record · Published February 21, 2024

    The FTC alleged Avast sold that data to more than 100 third parties through its subsidiary, Jumpshot.

    Counts toward the two-source rule

  3. Czech Office for Personal Data Protection (UOOU) · Regulator record · Published April 15, 2024

    It transferred a part of these data, which related to roughly 100 million of its users, to Jumpshot INC. during the period under review in 2019

    Counts toward the two-source rule

  4. Gen Digital Inc. / SEC EDGAR · Provider own statement · No publication date stated

    Avast announced the decision to terminate its provision of data to, and wind down, Jumpshot on January 30, 2020.

    Counts toward the two-source rule

    Conflict of interest: Gen's own statement to the SEC, which carries legal liability for its accuracy, but it is still Gen describing Gen. Filing date not captured; the auditor report inside is dated 21 May 2026.

Researcher notes

The strongest-corroborated item in the file: four groups (press investigation, FTC, Czech DPA, Gen). The FTC states its case as allegations; UOOU made a finding. The VICE article is the original investigation (Joseph Cox, with PCMag). Avast and Jumpshot data practices predate Gen's ownership (acquisition 12 September 2022) but the company that did them is now a Gen subsidiary and Avast SecureLine VPN is one of Gen's VPN products. No source in this file says Norton VPN or Avast SecureLine users' VPN data was sold.

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits0 of 5 shown
  • Security reviews0 of 2 shown
  • Servers and protocols0 of 2 shown
  • Ownership and jurisdiction2 of 2 shown
  • Incidents and vulnerabilities0 of 6 shown
  • Legal actions1 of 4 shown
  • Transparency0 of 3 shown
  • pr_topic_other1 of 1 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

See every published research record

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures