What can your internet provider see?

Less detail than most people assume, kept for longer than most people realise.

What they can see

Your provider carries every packet you send, so they can see the shape of your traffic even when they cannot read its contents:

  • Which sites you connect to.Not usually the specific pages — HTTPS conceals the path and the content — but the domain, and when, and for how long.
  • Your DNS lookups, if you use their DNS servers, which is the default. That is a list of every domain you asked about.
  • How much data you move, and when.Enough to infer a great deal about your household’s routine.

What they cannot see

The contents of anything sent over HTTPS, which is nearly everything: your messages, what you typed, what you bought, which page of a site you were on. This is a genuine change from a decade ago and it is why the old warnings have aged badly.

What UK providers are required to keep

Under the Investigatory Powers Act 2016, providers can be required to retain certain communications data — broadly, records of connections rather than their contents — for up to twelve months, and to disclose it to authorised bodies on a lawful request. This is a legal obligation, not a commercial choice, and it applies regardless of what any individual provider would prefer.

We are describing the general position rather than giving legal advice, and the detail depends on the notices a given provider is subject to.

What changes it

  • A VPNhides which sites you visit from your provider, because everything goes to the VPN server first. It does not remove a party who can see your traffic — it changes which party that is, to the VPN company.
  • Encrypted DNS stops your provider seeing your lookups, without moving all your traffic. Most browsers and operating systems now support it, and it is a narrower and often more proportionate change than a VPN.

For what a VPN does and does not cover, see what a VPN can actually hide.