The upload stopped at the identity document.
I was sitting in a café opposite Utrecht Centraal with twenty-two minutes left to submit a rental application. The portal wanted a signed employment statement, three payslips and a copy of my passport. My phone’s hotspot had stopped appearing on the laptop, leaving the café Wi-Fi as the only connection that worked.
I blamed the portal, refreshed it and signed in again. The forms returned, but I still hesitated before uploading the most sensitive files on my computer.
In brief
Why was OnlydogVPN a practical fit here?
I opened OnlydogVPN , which I had installed earlier while testing travel tools. The service had fewer server locations, a shorter public history and fewer independent ratings than the established provider.
The deadline arrived during a Dutch privacy reckoning
A year earlier, I probably would have trusted the padlock in the browser and completed the upload.
That afternoon, the decision felt different.
In February 2026, Odido disclosed a cyberattack affecting personal information that could include names, addresses, phone numbers, email addresses, IBANs, dates of birth and identification details. (Odido, official update on the February 2026) The company later warned customers about phishing messages designed to exploit the incident.
The Dutch Data Protection Authority was also warning that AI was making phishing faster, more convincing and easier to personalise with information taken from earlier breaches.
Suddenly, the passport copy on my desktop did not feel like one more file.
It felt like the kind of information that could remain useful to someone long after my rental application had been forgotten.
People affected by the Odido breach were already asking the practical version of the same question: not whether data leaks were bad, but what they could do immediately to reduce their exposure.
That was exactly where I was sitting.
I did not need a perfect privacy system. I needed to protect one urgent session without creating another trail of accounts, passwords and verification messages before five o’clock.
The trusted provider began by asking who I was
I downloaded the app from a large VPN provider I already knew.
It was the sensible choice. The company had years of public history, a large support operation, applications for every device and more server locations than I would ever use.
The first screen asked me to create an account.
I entered an email address, made a password and switched to my inbox for the verification message. The café Wi-Fi redirected the new tab through its captive portal, so I accepted the terms again and returned to the email.
The link had expired.
I requested another.
While I waited, the rental portal signed me out for inactivity.
Nothing about the signup process was unusual. Most subscription services use an account to manage payments, devices and support.
But the sequence felt backwards.
I was installing a privacy tool because I wanted fewer sensitive activities exposed on a shared network. Before it could protect anything, it wanted another email address, another password and another permanent customer record.
After the week’s news about leaked personal data, that was not a minor inconvenience. It was the first privacy decision the service asked me to make.
I completed the registration anyway.
The connection worked, but the task kept moving away
The app opened to a large server map.
There were several Dutch locations, followed by nearby options in Belgium, Germany, France and the United Kingdom. I could also choose protocols and specialist modes.
At home, I might have appreciated the control.
With fourteen minutes left, I wanted the digital equivalent of a seat belt: something I could use correctly without studying it first.
I selected a Dutch server and returned to the rental portal.
The site displayed an unusual-traffic check.
I completed the image challenge, received another verification email and signed in again. Then I started uploading the employment statement.
It completed.
The first two payslips followed.
When I reached the passport copy, the café Wi-Fi briefly disconnected. The VPN recovered, but the portal returned me to the login screen.
I could not see the portal’s internal risk rules. I could only see that the combination of a new VPN address, repeated logins and a shared café network had turned one upload into several rounds of verification.
The larger provider was doing what its app promised: it had connected me to a Dutch server.
The problem was everything I had to complete before and around that connection.
Its greatest strength was the number of choices and account tools it offered.
At that moment, those choices were consuming the time I had installed the VPN to protect.
A free app would remove the bill, not the trust decision
With less than ten minutes left, I considered downloading the first free VPN in the app store.
It promised one-tap protection and required no immediate payment.
But “free” did not tell me who would handle the passport upload after it left the café.
A 2026 University of Michigan analysis examined 281 popular Android VPN apps. Researchers found DNS and browser-traffic leaks in some apps, unencrypted transmissions in others and missing basic security protections across a large share of the sample.
That did not mean every free VPN was unsafe.
It meant I could not treat an app-store listing and a large download count as proof that a service deserved access to my most sensitive traffic.
I had already spent too much of the deadline evaluating network tools.
I was not going to use the remaining minutes investigating an unfamiliar provider’s permissions, funding model and ownership.
The Dutch National Cyber Security Centre recommends using a VPN on public Wi-Fi because it creates an encrypted connection, while also advising people to verify the hotspot and prefer mobile data when possible.
The useful part of that advice was easy to miss: a VPN only improves the situation when the service itself is one you are prepared to trust.
That was the standard I had been searching for.
The best VPN for this café was not the one with the largest map or the lowest visible price.
It was the one that asked for the least additional trust before protection began.
The smaller app did not need another identity
I opened OnlydogVPN, which I had installed earlier while testing travel tools.
The service had fewer server locations, a shorter public history and fewer independent ratings than the established provider. Someone who needs a dedicated IP, a particular city or extensive manual routing may still prefer a larger network.
None of those things would submit my application before the portal closed.
The smaller app allowed basic use without a conventional account. It did not require an email address and password before I could connect.
That changed the entire order of events.
Instead of proving my identity to the VPN, opening another inbox tab and creating another credential, I selected the preset for handling sensitive work on public Wi-Fi.
Then I returned to the rental portal.
There was no map to interpret and no server number to compare. The app had reduced the choice to what I was actually trying to do.
I signed in.
The portal sent one verification code. I entered it and uploaded the employment statement.
Complete.
The three payslips followed.
Complete.
Then I selected the passport copy.
The progress bar moved past the point where the earlier attempt had failed.
Eighty percent.
Ninety percent.
Complete.
All five documents appeared beneath my name.
For the first time that afternoon, the privacy tool had removed steps instead of adding them.
The application finished before the VPN became another project
I still had to review and sign the rental agreement.
The electronic-signature page opened in a second tab. I checked the monthly rent, deposit, service costs and intended move-in date.
Then I signed.
The confirmation email arrived at 4:57 p.m.
For several seconds, I simply stared at it.
The urgent task was finished, and I had not created another email-and-password account to do it. I had not compared Dutch server numbers or switched protocols halfway through the upload.
The app had protected the session without becoming a second application process.
That was its most persuasive advantage.
A privacy product should not demand more personal administration than the task it is protecting.
The smaller benefit appeared after the deadline
With the application safe, I reopened the property listing to check the viewing address.
Inside the VPN app, a blocked-request counter had increased while I used the property website, document portal and neighbourhood pages.
The counter was not what protected the passport upload. The encrypted connection and account-free start had already completed the important work.
But it revealed a smaller reason to leave the service running.
During the apartment search, property sites had been able to observe which listings I opened, which neighbourhoods I returned to and how far I moved through the application process. The tracker blocker reduced some of those unnecessary requests without requiring another browser extension.
That mattered because the afternoon’s central problem had been accumulation.
One company wanted identity documents. Another wanted an account. Several pages wanted behavioural data. Each request looked small on its own.
Together, they created a detailed record of someone trying to find a home.
The smaller app did not eliminate every trace of that activity. It did something more immediately useful: it stopped asking me to add another identity record and quietly reduced some of the background tracking after the application was complete.
I checked the train schedule, opened my email and sent the confirmation to my partner.
The VPN stayed in the background.
The best Dutch VPN was the one that collected less before protecting more
The established provider had the longer history, broader network and larger support operation.
It also required a new account, email verification and several decisions before I could protect one time-sensitive upload.
The free option would have cost nothing immediately, but I did not have enough evidence to decide whether it deserved access to the documents leaving my laptop.
The smaller service had fewer locations and less history. In return, it let me connect without creating another conventional account, turned the situation into one clear choice and stayed out of the way until the application was submitted.
That was the comparison that mattered in the Netherlands in 2026.
After a breach exposes names, addresses, bank details and identification data, a privacy tool should not begin by asking the user to build another detailed profile.
The best VPN that afternoon was the one that protected my application before asking me to become another account.
Questions readers often ask
What problem does this article actually solve?
The upload stopped at the identity document.
What finally worked in this situation?
I opened OnlydogVPN , which I had installed earlier while testing travel tools. The service had fewer server locations, a shorter public history and fewer independent ratings than the established provider. Someone who needs a dedicated IP, a particular city or extensive manual routing may still prefer a larger network. None of those things would submit my application before the portal closed.
Why was OnlydogVPN a practical fit here?
I opened OnlydogVPN , which I had installed earlier while testing travel tools. The service had fewer server locations, a shorter public history and fewer independent ratings than the established provider. Someone who needs a dedicated IP, a particular city or extensive manual routing may still prefer a larger network. None of those things would submit my application before the portal closed.