What is visible, what is not – and what can be reconstructed?
Many users assume that a VPN makes them anonymous and completely hides their origin. This is incorrect.
A VPN can improve privacy and protect traffic between your device and the VPN endpoint, but it does not provide anonymity. It also does not prevent identification through accounts, authentication systems, device information, or other available logs.
This becomes particularly relevant when accessing corporate networks from abroad, for example from Thailand.
1. DOES A VPN MAKE YOU ANONYMOUS?
Clearly: No.
A VPN encrypts traffic between your device and the VPN endpoint. For an ordinary internet connection, this means your ISP normally cannot see the contents of the traffic inside the VPN tunnel.
However, the VPN provider becomes another party that must be trusted. Depending on the VPN technology, configuration, and logging policy, the provider may have access to connection information such as your source IP address, connection times, and the VPN endpoint used.
A VPN:
• Protects traffic against many forms of interception on untrusted networks
• Prevents your ISP from normally seeing the contents of traffic inside the VPN tunnel
• Does not replace your identity, login credentials, MFA, certificates, or device identity
• Does not make you invisible to the systems you access
A VPN improves privacy. It does not create anonymity.
2. WHO SEES WHAT WHEN USING A VPN?
Internet Service Provider (ISP) in Thailand
The ISP can generally see:
• Your real IP address or network connection
• That your device is communicating with a VPN endpoint
• Connection times and other network metadata
• The amount of traffic being transferred
The ISP normally cannot see through the VPN tunnel:
• The contents of the encrypted VPN traffic
• The specific internal resources accessed through an encrypted corporate VPN
• The contents of properly encrypted applications carried inside the tunnel
The ISP therefore sees a connection to the VPN endpoint rather than the complete activity taking place inside the VPN.
VPN Provider
Depending on the service and configuration, the VPN provider may have access to:
• Your source IP address
• The VPN IP address assigned to your connection
• Connection timestamps
• Traffic volume and other connection metadata
If the provider keeps appropriate logs, additional information may potentially be available.
However, this does not mean that every VPN provider can see everything you do. Encryption used by websites and applications, such as HTTPS, can remain in place beyond the VPN tunnel.
Whether relevant information is stored depends on the provider, its technical architecture, its logging practices, and the applicable legal framework.
Target System – For Example, a Corporate Network
The corporate network can potentially see:
• The VPN or gateway IP address from which the connection arrives
• Username and account information
• Certificates and MFA information
• Device information
• Operating system information
• Login times and access times
• Access behavior and usage patterns
A properly administered corporate environment may also detect:
• Unusual login times
• Unexpected geographic patterns or changes in normal access behavior
• Known VPN, hosting, or datacenter IP ranges
• Simultaneous or unusual sessions
• Changes in device or authentication characteristics
A VPN can hide the original network address from the target system, but it does not hide the identity used to authenticate to that system.
3. CAN IT BE DETERMINED THAT I AM ACCESSING A CORPORATE NETWORK FROM THAILAND VIA VPN?
Yes, it can be possible.
It is not necessarily possible in real time, and it is not guaranteed with every VPN configuration.
However, when relevant records from different systems exist and can legally and technically be correlated, they can potentially reconstruct where a connection originated.
A simplified reconstruction chain could look like this:
1 → ISP RECORD
A connection from Thailand establishes a connection to a VPN endpoint.
2 → VPN RECORD
The VPN provider has a record connecting that VPN session with a particular source connection or IP address.
3 → CORPORATE RECORD
The corporate system records that the VPN IP address accessed the system using user Y.
4 → CORRELATION
If the relevant records contain compatible timestamps and identifiers, the different records can potentially be correlated.
The important point is this: reconstruction depends on the existence, quality, retention, and lawful availability of the relevant records.
A VPN therefore does not make such reconstruction impossible.
4. LEGAL LOGGING OBLIGATIONS WORLDWIDE
Many countries have laws and regulations governing the retention or disclosure of certain telecommunications or computer traffic data.
The exact requirements vary considerably between countries, service providers, technologies, and circumstances.
Depending on the jurisdiction and service, records may include information such as:
• IP address assignments
• Connection timestamps
• Subscriber or account information
• Traffic or connection metadata
• Other information required by applicable law
This should not be confused with automatically recording the complete content of every communication.
Different laws apply to traffic data, subscriber information, and communication content.
5. SITUATION IN THAILAND
Thailand has legal requirements concerning the retention of computer traffic data by covered service providers.
The relevant regulations specify retention requirements for computer traffic data, with a standard minimum retention period of 90 days and provisions allowing longer retention in certain circumstances.
This does not mean that the Thai authorities continuously monitor the activity of every internet user.
It means that certain providers may have legally defined obligations to retain specified traffic information and may be required to provide information through the applicable legal process.
The exact obligations depend on the type of provider and the circumstances.
The important distinction is between continuous surveillance and the ability to reconstruct events from retained technical records.
6. COMMON MISCONCEPTIONS
A VPN does not mean anonymity.
A VPN does not prevent targeted investigations.
A VPN does not prevent tracking through logins, cookies, browser characteristics, device information, or authentication systems.
A VPN is not a legal shield.
A VPN does not erase the logs created by the systems you access.
7. WHEN A VPN MAKES SENSE
A VPN is useful for:
• Protecting traffic on public or untrusted Wi-Fi networks
• Preventing the local network from directly seeing the contents of VPN-protected traffic
• Reducing the amount of browsing information visible to the ISP
• Connecting securely to corporate or private networks
• Improving privacy in certain network environments
A VPN can therefore be an important security tool when it is configured and used correctly.
8. WHEN A VPN IS NOT SUFFICIENT
A VPN is not sufficient by itself:
• When accessing corporate systems that use authentication and logging
• When the destination system records account and device information
• When multiple systems can correlate connection records
• In governmental or legal investigations
• When legal or regulatory obligations apply
A VPN protects a network connection. It does not override the security, logging, authentication, or legal requirements of the systems involved.
9. CONCLUSION
A VPN:
• Shifts some trust from the ISP to the VPN provider
• Can hide your original IP address from the destination system
• Does not hide your authenticated identity from a corporate system
• Does not automatically prevent correlation of technical records
• Provides technical and privacy protection, not legal immunity
Anyone who believes they are “invisible” when using a VPN misunderstands the reality of modern networks and logging systems.
A VPN is a security and privacy tool, not a promise of anonymity or legal protection.

