A VPN appears on almost every digital nomad packing list.
We are told to use one in airports, hotels and cafés. VPN companies warn that public Wi-Fi is dangerous. Travel influencers promote discount codes. Some remote workers leave their VPN connected permanently, while others barely understand what it is doing in the background.
So, is a VPN actually worth using when traveling?
For most frequent travelers and remote workers, yes — a reputable VPN can be a useful security and privacy tool. It is particularly valuable when we regularly connect to networks we do not control, want to reduce how much information local networks can see, or need an additional layer of protection while working abroad.
But a VPN does much less than some advertising suggests.
It does not make us anonymous online.
It does not automatically make an unsafe device safe.
It does not protect us from phishing.
It does not stop Google, Facebook or other services from knowing who we are when we log into our accounts.
It does not necessarily hide our physical location from an employer.
And public Wi-Fi is not quite the unencrypted Wild West that some VPN advertisements still portray it as.
Understanding those limitations is important because a VPN is most useful when we see it for what it actually is: one layer of protection rather than a magic privacy button.
Here is what travelers and remote workers should know before deciding whether a VPN is worth paying for.
What Is a VPN?
VPN stands for Virtual Private Network.
Normally, when we connect to the internet, our device sends traffic through the local network and our internet service provider before reaching websites and online services.
A VPN changes part of that route.
Our device creates an encrypted connection to a VPN server. Internet traffic is sent through that connection before continuing toward its final destination.
In simplified terms, the route becomes:
Our laptop → encrypted VPN connection → VPN server → internet
instead of:
Our laptop → local network → internet
That provides two particularly important benefits.
First, people or organisations controlling the local network have less visibility into the traffic traveling between our device and the VPN server.
Second, websites generally see the VPN server’s public IP address rather than the public IP address assigned by the hotel, café, home connection or mobile network we are actually using.
Those two functions explain most of what a VPN can realistically do.
Everything else should be understood around them.
What Does a VPN Actually Protect?
The most important benefit is encryption between our device and the VPN server.
This is useful when traveling because we frequently use networks we did not configure ourselves.
At home, we generally know which router we are connecting to.
While traveling, we might use:
- airport Wi-Fi;
- hotel networks;
- coworking spaces;
- cafés;
- train or airport lounge Wi-Fi;
- Airbnb networks;
- conference venues;
- or other shared connections.
We often know very little about how those networks are configured or maintained.
A VPN creates an encrypted tunnel through that local network.
The UK’s National Cyber Security Centre describes VPNs as a way to create a secure network connection over an untrusted network.
That is probably the simplest way to understand their main value.
The hotel Wi-Fi might still be poorly configured.
We simply become less dependent on that network being trustworthy.
Does a VPN Make Public Wi-Fi Safe?
This is where the answer becomes more nuanced.
For years, travelers were repeatedly warned never to enter passwords, use online banking or access sensitive information while connected to public Wi-Fi.
That advice made considerably more sense when much of the web was transmitted without encryption.
Today, the internet works differently.
Most major websites use HTTPS, meaning information traveling between our browser and the website is already encrypted.
The US Federal Trade Commission now explicitly says that public Wi-Fi is usually safe because most websites use encryption, while still recommending good general security practices such as strong passwords, two-factor authentication and updated software.
That does not make VPNs pointless.
It means the argument has changed.
We no longer need a VPN simply because connecting to café Wi-Fi will otherwise expose every password we type.
HTTPS already protects much of our web traffic.
A VPN instead provides another layer of protection around the connection and reduces the amount of information visible to the local network.
For travelers who regularly jump between unfamiliar networks, that can still be valuable.
But it is very different from saying:
“Public Wi-Fi without a VPN means hackers can see everything you do.”
That statement is increasingly misleading.
What Can the Hotel or Café Wi-Fi See Without a VPN?
Even when HTTPS protects the content of our web traffic, the network can still potentially learn certain information.
For example, network operators may be able to see:
- that our device is connected;
- how much data we are transferring;
- our device’s network identifiers;
- connection times;
- and some information about which services or domains we contact.
Exactly what is visible depends on the technology being used.
When we use a VPN, much of that activity is instead wrapped inside the encrypted connection between our device and the VPN server.
From the local network’s perspective, a significant portion of our activity may simply look like encrypted traffic going to the VPN.
That is useful from a privacy perspective.
But we should remember that visibility has not magically disappeared.
Some of it has simply shifted elsewhere.
Your VPN Provider Becomes Part of the Trust Equation
This is one of the most important things VPN advertising rarely emphasises.
Without a VPN, our internet provider or local network may have some visibility into our connection.
With a VPN, traffic first passes through the VPN provider’s infrastructure.
We are therefore not eliminating trust.
We are changing whom we trust.
This is why choosing a reputable VPN provider matters.
A free VPN run by an unknown company with an unclear business model may not necessarily improve our privacy.
VPN infrastructure costs money.
Servers cost money.
Bandwidth costs money.
Software development costs money.
Customer support costs money.
If a service provides all of this for free, it is reasonable to ask how the company earns revenue.
There are legitimate free or limited VPN services, but we should not automatically assume that “free” and “private” go together.
For people who genuinely care about privacy, the provider’s reputation, transparency and privacy policies matter at least as much as the technical feature itself.
Does a VPN Hide Your IP Address?
Yes — from most websites and services we connect to.
Suppose we are physically in Spain.
Without a VPN, websites may see an IP address associated with the Spanish internet provider we are using.
If we connect to a VPN server in Germany, those websites will normally see the German VPN server’s IP address instead.
This can make our apparent internet location different from our physical location.
That is why VPNs are often used to access services while traveling that behave differently depending on the user’s country.
But hiding our IP address should not be confused with becoming anonymous.
They are very different things.
Does a VPN Make You Anonymous?
No.
This is probably the biggest misconception around consumer VPNs.
Our IP address is only one way online services can recognise us.
Imagine we connect through a VPN server in Switzerland and then immediately log into:
Google,
Facebook,
LinkedIn,
Amazon,
our bank,
our company email,
and several other personal accounts.
Those companies do not suddenly wonder who this mysterious Swiss visitor might be.
We literally logged in.
Websites may also use cookies, account information, browser characteristics and other signals to maintain sessions and recognise users.
A VPN changes our network-level IP address.
It does not erase our digital identity.
For ordinary travelers, this distinction may not matter very much.
But anyone buying a VPN because they believe it will make their online activity anonymous should adjust those expectations.
Can a VPN Hide Your Location From Your Employer?
Not necessarily.
This is particularly relevant for remote employees working internationally.
Imagine we are employed in Belgium but decide to spend two months working from Thailand.
We install a consumer VPN and connect through a Belgian server.
Will our employer assume we are still in Belgium?
Perhaps.
But relying on this would be risky.
Corporate systems can potentially use many signals beyond the public IP address visible to a website.
Employers may have access to security logs, identity systems, company-managed devices, corporate VPN connections, authentication data and other information.
Corporate cybersecurity systems also actively look for unusual account behaviour because a login from another country can indicate that credentials have been compromised.
We explored this issue in much greater detail in Can Your Employer Tell You’re Working Abroad? How AI Is Changing Remote Work Compliance. Can Your Employer Tell You’re Working Abroad?
The important lesson is simple:
A consumer VPN should not be treated as a reliable way to secretly work from another country.
If our company requires permission before international remote work, the sensible approach is to follow that policy rather than assuming a different IP address makes us invisible.
A Corporate VPN Is Different From a Consumer VPN
The term “VPN” can also create confusion because corporate and consumer VPNs often serve different purposes.
A commercial consumer VPN primarily routes our internet traffic through the VPN provider’s servers.
A corporate VPN may instead be designed to securely connect our computer to our employer’s internal network.
For example, someone working remotely might connect to a company VPN before accessing internal files, databases or applications.
The company controls that infrastructure.
The VPN is therefore not designed to hide our activity from our employer.
Quite the opposite.
It exists partly so that corporate systems can authenticate us and securely manage access.
Employees should therefore not disable corporate VPNs simply because they make the connection slower or because another consumer VPN is installed.
Company security rules should take priority.
Does a VPN Protect You From Hackers?
Sometimes — but this phrase is too broad to be especially useful.
A VPN can protect certain network traffic from interception between our device and the VPN server.
That is valuable.
But most successful attacks against ordinary internet users do not require a criminal sitting at the next table in Starbucks intercepting packets.
Consider phishing.
We receive an email that appears to come from Microsoft.
It tells us our account will be suspended unless we immediately log in.
We click the link.
The fake website looks perfect.
We enter our email address and password.
A VPN does nothing to stop us from voluntarily giving those credentials to a scammer.
The same applies to malicious downloads.
If we download and execute malware, a VPN does not make the malware safe.
If we reuse the same password across 12 websites and one of those sites suffers a breach, a VPN does not solve the problem.
If someone convinces us to reveal a verification code, the encrypted VPN tunnel does not matter.
Cybersecurity requires layers.
A VPN can be one of them.
What a VPN Does Not Replace
Travelers should therefore avoid using a VPN as an excuse to neglect more important security basics.
We still need:
Strong, unique passwords.
A password manager makes this much easier.
Two-factor authentication.
Ideally using an authenticator app, security key or another strong method where available.
Software updates.
Operating systems, browsers and applications should remain current.
Device encryption.
If a laptop is stolen, full-disk encryption can be far more important than whether we used a VPN at the airport.
Automatic locking.
Especially in coworking spaces and public environments.
Backups.
Losing a laptop should not mean losing our business.
Phishing awareness.
No encrypted connection can protect us from willingly entering credentials into the wrong website.
A VPN complements these measures.
It does not replace them.
Is a VPN Useful for Streaming While Traveling?
This is probably the second major reason travelers use VPNs.
Streaming libraries and services differ between countries.
A VPN can sometimes make our connection appear to originate from another location, potentially allowing us to access services as though we were there.
However, this is not guaranteed.
Streaming services actively detect many VPN servers.
A server that works today may not work tomorrow.
Some services may also restrict VPN use through their terms or licensing arrangements.
We should therefore treat geo-location features as a useful possibility rather than a guarantee.
It is also worth remembering that changing our apparent IP location does not change the rules governing the service we use.
Can a VPN Help With Websites That Block Foreign Visitors?
Sometimes.
Banks, payment platforms and other services occasionally respond differently when an account suddenly connects from another country.
A VPN server in our home country may make our connection appear more familiar.
But again, sophisticated security systems use more than IP addresses.
A banking application might also know information about the device, previous sessions or other authentication signals.
A VPN can change one indicator.
It does not necessarily recreate our entire home environment.
Will a VPN Slow Down Your Internet?
Usually, at least slightly.
Without a VPN, our traffic takes a relatively direct route from our device toward its destination.
With a VPN, traffic must first travel to the VPN server.
It also needs to be encrypted and decrypted.
That adds overhead.
On a fast modern connection with a nearby high-quality VPN server, the difference may barely be noticeable.
But imagine we are working from Kazakhstan and choose a VPN server in New York.
Our traffic now has to travel an enormous physical distance before continuing toward its destination.
Latency will increase.
Video calls may feel less responsive.
Downloads may slow.
The VPN server itself might also be busy.
This is particularly relevant to remote workers because latency can matter considerably more than raw bandwidth during Zoom or Teams calls.
We covered the difference between download speed, upload speed, latency, jitter and packet loss in our guide to How Much Internet Speed Do You Actually Need to Work Remotely? How Much Internet Speed Do You Actually Need to Work Remotely?
If we use a VPN every day for remote work, it is worth testing the connection both with and without it.
Choose a VPN Server Close to You When Possible
If privacy and connection security are our main objectives, there is usually little reason to send our traffic halfway around the planet.
Suppose we are in Italy.
Connecting to a server in Italy, Switzerland, Austria or another nearby country will normally produce lower latency than routing everything through California.
The exception is when we specifically need an IP address in another country.
Otherwise, choosing a nearby server generally provides the best balance between privacy and performance.
Many modern VPN applications automatically recommend a fast server.
For everyday work, that is often the best option.
What About Video Calls Through a VPN?
Zoom, Teams and Google Meet can all work through VPN connections.
The problem is not usually bandwidth.
Modern video calls need surprisingly little.
The bigger issue can be the route.
Suppose two colleagues are both in Singapore, but one person’s VPN routes all their traffic through London.
Their video data may take a needlessly long journey.
That additional latency can create conversational delays.
Some corporate networks therefore configure specific high-bandwidth applications differently, but employees should not change corporate VPN settings themselves unless authorised to do so.
If our own consumer VPN noticeably damages video-call quality, switching to a geographically closer server may solve the problem.
VPN vs Mobile Hotspot: Which Is Safer While Traveling?
There is another option remote workers sometimes overlook.
Mobile data.
Instead of connecting a laptop to airport or café Wi-Fi, we can tether it to our phone.
For many travelers, an eSIM makes this particularly easy.
From a practical security perspective, using our own cellular connection reduces our dependence on an unknown public Wi-Fi network altogether.
That does not mean mobile networks are invulnerable.
But it removes some common public-network uncertainties.
This is why our travel setup often includes both options:
a VPN for unfamiliar networks and mobile connectivity as a backup.
They solve slightly different problems.
And if hotel Wi-Fi becomes unreliable five minutes before an important meeting, mobile data can be much more valuable than another cybersecurity application.
Beware of Fake Wi-Fi Networks
One practical risk remains particularly relevant while traveling.
Imagine arriving at an airport and seeing these networks:
Airport_Free_WiFi
Airport_WiFi
Airport_Guest
Free_Airport_Internet
Which one is legitimate?
A malicious network can deliberately use a name that looks believable.
This is sometimes referred to as an “evil twin” attack.
Before connecting in airports, hotels or coworking spaces, it can be worth confirming the correct network name with staff.
A VPN provides useful protection once connected, but the better habit is still to avoid connecting to suspicious networks in the first place.
We should also disable automatic Wi-Fi connection features if our devices repeatedly join unknown networks without asking.
Should You Leave Your VPN On All the Time?
There is no universal answer.
Some travelers do.
If the VPN is fast, reliable and does not interfere with services, leaving it connected can be convenient.
We do not need to decide repeatedly whether a particular network is trustworthy.
Other people prefer to activate it only when:
using public Wi-Fi;
working with sensitive business information;
accessing services abroad;
or wanting greater network privacy.
There is nothing inherently wrong with either approach.
The important thing is understanding when the VPN is actually adding value.
If permanently enabling it significantly reduces internet performance or repeatedly triggers security checks from financial services, using it more selectively may be more practical.
What Is a VPN Kill Switch?
A useful feature found in many VPN applications is a kill switch.
Normally, if the VPN connection unexpectedly drops, our device may simply return to the normal internet connection.
That means traffic that was previously going through the encrypted VPN tunnel could temporarily travel outside it.
A kill switch prevents this by blocking internet access when the VPN disconnects.
For most casual travelers, this may not be essential.
For people handling sensitive business information or deliberately requiring all traffic to pass through the VPN, it can be valuable.
The UK’s National Cyber Security Centre similarly notes that only traffic routed through a VPN receives the VPN’s protection and discusses configurations that force traffic through the tunnel.
Does a VPN Protect Your Laptop If It Gets Stolen?
No.
This sounds obvious, but physical security becomes much more important while traveling.
A laptop can disappear:
from a café;
from an airport security tray;
from a hotel room;
from a train;
or from luggage.
A VPN does essentially nothing at that point.
Device encryption, strong login credentials, remote management capabilities, backups and fast account-response procedures become much more relevant.
This illustrates why VPNs should be viewed as one small component of travel cybersecurity rather than the centre of it.
Can You Use a VPN Everywhere in the World?
Travelers should not assume that the same rules apply in every country.
VPN regulations vary.
Some governments restrict certain services or regulate how VPN technology may be used.
Before traveling somewhere with tighter internet controls, it is sensible to check the current local regulations and whether the VPN provider we intend to use works reliably there.
We should also install any necessary software before arriving rather than assuming every VPN website or app store listing will remain accessible after we enter the country.
The objective is not to circumvent local law.
It is simply to understand the environment before relying on a particular piece of technology.
Free VPN vs Paid VPN
For someone who travels once per year and wants a VPN for an afternoon at the airport, a reputable limited free plan may be sufficient.
For a remote worker who spends months abroad, paying for a good VPN generally makes more sense.
We are using it as infrastructure.
A paid service can offer:
more servers;
more locations;
better performance;
higher or unlimited data allowances;
support for multiple devices;
and additional features.
But price alone does not guarantee quality.
We would look primarily for a provider with a long-standing reputation, clear ownership, transparent privacy practices, modern encryption protocols and good performance.
Features such as 97 countries and 12,000 servers are impressive marketing numbers.
Reliability matters more.
Should Digital Nomads Use a VPN?
For digital nomads and frequent remote workers, we think the answer is generally yes.
Not because traveling without one is inherently dangerous.
And not because VPNs make us invisible.
Rather because our lifestyle exposes us to a greater variety of networks than the average person.
During one month, we may connect from:
an Airbnb;
a coworking space;
two airports;
a hotel;
three cafés;
our phone hotspot;
and perhaps a train.
We have very little control over most of that infrastructure.
Using a reputable VPN adds consistency.
No matter which local network we happen to be using, our traffic can still first pass through the encrypted VPN connection.
For someone who works from the same trusted home fibre connection every day, that benefit may be less important.
For someone constantly moving between networks, it becomes more compelling.
Is a VPN Worth Paying For When Traveling?
For frequent travelers, usually yes.
A VPN subscription often costs less than a few coffees per month.
If we travel regularly, work remotely, use unfamiliar Wi-Fi networks and value privacy, that is a relatively modest cost for another layer of protection.
But we should buy it for the right reasons.
A VPN is worth considering if we want to:
- create an encrypted connection while using unfamiliar networks;
- reduce what the local Wi-Fi operator can observe;
- prevent websites from seeing our normal public IP address;
- connect through a server in another location;
- add another security layer while working remotely;
- or maintain a more consistent networking setup while moving between countries.
It is not worth buying because we believe it will:
- make us completely anonymous;
- stop all hacking;
- protect us from phishing;
- remove malware;
- make every website trust us;
- hide international remote work reliably from an employer;
- replace strong passwords and two-factor authentication;
- or magically make public Wi-Fi safe regardless of everything else we do.
Those claims give VPNs far too much credit.
The Best Travel Security Setup Is Layered
The broader lesson goes beyond VPNs.
There is rarely one application that makes traveling with technology completely secure.
Good travel cybersecurity comes from several relatively boring habits working together.
We update our devices.
We use strong unique passwords.
We enable two-factor authentication.
We encrypt our laptop.
We maintain backups.
We verify public Wi-Fi network names.
We carry mobile data as a backup.
We avoid suspicious links.
And, when appropriate, we use a VPN.
None of these measures is perfect.
Together, they dramatically reduce unnecessary risk.
So, Is a VPN Worth It When Traveling?
For most frequent travelers and remote workers, we would say yes — but probably not for the reasons advertised most aggressively by VPN companies.
Modern HTTPS encryption means public Wi-Fi is safer than it was in the early days of the internet. A VPN therefore is not the only thing standing between us and someone stealing every password we type.
Its value is more measured.
It creates a secure connection through networks we do not control.
It limits what those networks can see.
It masks our normal public IP address from websites.
It gives us more control over where our internet connection appears to originate.
And it creates a consistent security layer when we move between airports, hotels, Airbnbs, coworking spaces and cafés.
That is useful.
But we should also understand what remains visible.
Our Google account still knows who we are.
Our employer may still determine that we are working abroad.
Our VPN provider becomes another party we must trust.
Malware remains malware.
Phishing remains phishing.
And if our laptop disappears from a café table, the encrypted network tunnel will not bring it back.
The best way to think about a VPN is therefore not as an invisibility cloak.
It is more like locking the door.
A lock does not make a building impossible to enter.
It does not protect us from every possible threat.
But when we spend our lives moving between unfamiliar places, having that extra layer of protection generally makes sense.






