Skip to content
DnsLister Forum

Where domain hunters compare notes

On in-flight Wi-Fi your VPN connects after the captive portal, not before it. That ordering decides most of what a VPN can and cannot do up there.

What a VPN does not do on a flight?

It does not retrieve what the portal already has. Most in-flight services put a captive portal in front of the internet. Email address, loyalty login, seat, booking reference, card details – all are submitted before any tunnel can exist. That data is collected, and nothing you do afterwards unsubmits it.

It does not change jurisdiction. The airline, the connectivity provider, the portal operator and the payment processor each sit under their own legal obligations. Encrypting your traffic has no effect on any of them.

It does not cancel retention. Whatever has been logged stays logged according to that company's schedule and its legal obligations.

It adds a party rather than removing one. Running a VPN puts a provider, its infrastructure and its jurisdiction into the path. That includes us. Where the parent company sits, what the logging policy actually says, where the servers are, all of it deserves the same examination you would give the Wi-Fi operator. A VPN is a transfer of trust, not an elimination of it.

What the network still sees with a VPN running: that an encrypted connection exists and where it terminates, join time, session length, approximate data volume, packet sizes and timing patterns. Locally your device still exposes its MAC address, device name and assigned address to the Wi-Fi system.

The thing most people get backwards

The country the plane is flying over does not determine which privacy law applies. Neither does the flag on the tail.

The Chicago Convention establishes state sovereignty over airspace and gives an aircraft the nationality of its state of registration. It does not say that every company processing passenger internet data follows only that state's privacy law. It was drafted long before any of this existed.

The Tokyo Convention, 1963, deals with offences and disruptive acts on board. The registration state generally has jurisdiction over those, but the convention does not make that exclusive and does not establish a data protection regime for commercial Wi-Fi.

International waters do not create a gap either. A provider established in the EU can remain subject to the GDPR for relevant processing even when the servers and the passenger are elsewhere, since that obligation attaches to the provider rather than to a location.

The operative principle is that jurisdiction follows the processing. Which entity collects what, why, where it is established, where the data travels, and which laws reach that far.

Your counterparty is probably not the airline

This is the practical finding. The portal carries airline branding, but on several carriers the Wi-Fi agreement is between the passenger and the connectivity provider. The airline's own privacy policy governs ticketing, check-in and loyalty, and will tell you nothing about connection logs held by a different company.

Reading the airline's policy and concluding you understand the situation is a natural mistake and a complete miss.

Two specifics from published notices

One provider's January 2026 mobility notice locates its servers primarily in the US, UK, Ireland and the Netherlands, and states that data may additionally be transferred to India, Australia, the countries where its business operates and potentially others. A geolocated IP address will not tell you where records are held or which entity administers them.

One major provider's retention wording covers the duration of the customer relationship plus lawful business needs, legal obligations and applicable limitation periods, with an additional two months added beyond the end of any limitation period, and longer if a claim arises.

Content versus metadata

Worth separating these properly. With HTTPS configured correctly, page content, full URL path, search terms, cookies and form entries are not readable in transit. Destination IP and traffic timing remain visible, and the domain can still be exposed through conventional DNS or an unencrypted TLS SNI field unless Encrypted Client Hello is in play.

Also worth distinguishing what infrastructure could technically observe from what a provider states it actually records. Those are not the same list.

Where a VPN genuinely helps here

It removes the browsing itself from the operator's visibility. Instead of a sequence of destinations, they see encrypted traffic to a single endpoint. That is a real and meaningful narrowing, and it is the whole of what is on offer. It fails on split tunnelling, on a dropped connection without a kill switch, and on DNS leaking outside the tunnel.

Also: government access to stored records is not the same thing as live interception. Different legal powers, different thresholds, different technical processes. A provider stating it complies with lawful requests is not the same as a government watching your session.

Full write-up including a pre-flight checklist for identifying the actual controller: https://hide.me/en/blog/who-has-jurisdiction-on-an-international-flight/

Question for the sub: has anyone here actually read the portal terms before tapping connect, or does everyone just accept and move on? I am curious whether anyone has changed their behaviour after reading one.

https://i.redd.it/iclfthpfpnph1.png

Source: r/hidemeVPN · by /u/hidemevpn

Leave a Reply

Your email address will not be published. Required fields are marked *