Most people in this situation are not thinking about their employment contract. They are thinking about their VPN settings.
That is the wrong priority. The VPN is a secondary concern. What actually matters is what happens inside your company in the 72 hours after someone in IT, HR, or your manager realizes you are in another country. That sequence has a predictable structure, and understanding it changes what you should do right now.
In Short: When an employer discovers an employee is working from another country without authorization, HR initiates an immediate three-step audit: duration assessment, legal and tax exposure review, and a decision framework based on risk. Short stays in low-risk countries typically result in a warning and forced return. Extended stays or stays in countries with complex tax treaties typically result in termination. The discovery method matters less than how long you have been there.
What HR Does in the First 72 Hours After Discovery
Step 1: The Duration Question
The first thing HR wants to know is not whether you violated policy. They already know you did. The first question is: how long have you been there?
Duration determines the company's legal exposure. An employee who spent two weeks in Portugal while on an approved vacation and kept working informally is a different problem than an employee who has been operating out of Thailand for four months without disclosure.
At the two-week end of the spectrum, the legal and tax risk to the company is usually manageable. Most countries do not trigger tax residency or employment law obligations for stays under 30 days, though there are exceptions. HR's risk calculation starts at "reprimand and policy reminder."
At the four-month end, the company may have inadvertently created what tax law calls a permanent establishment in the country where you were working. That means potential corporate tax liability, back payroll obligations, and in some cases registration requirements with local labor authorities. HR's calculation now starts at "consult legal immediately."
Step 2: The Legal and Tax Assessment
HR does not make this decision alone. In every situation I have seen handled at the enterprise level, the discovery triggers an immediate consultation with legal counsel and, in regulated industries, compliance officers.
They are assessing four specific risks:
Permanent establishment risk: If your work activity constitutes substantive business operations in a foreign country, the company may be deemed to have a permanent establishment there. This can expose the company to corporate income tax on revenue attributed to that jurisdiction. For a company that has never operated in Thailand or Portugal or wherever you were working, this is a serious problem.
Payroll and social security obligations: Many countries require employer payroll registration and social security contributions for anyone performing work on their soil, regardless of where the employer is based. Your unauthorized stay may have created retroactive payroll obligations that the company now has to resolve.
Immigration and visa status: Working on a tourist visa is illegal in virtually every country. You may have violated local immigration law. The company may have facilitated that violation, which creates its own liability. Some jurisdictions can pursue the employer for enabling illegal work even when the employer was unaware of it.
Data protection and security compliance: If your company holds data subject to GDPR, HIPAA, CCPA, or any industry-specific regulation, accessing that data from an unauthorized jurisdiction may be a reportable compliance incident. In financial services and healthcare, this can trigger mandatory disclosure to regulators.
Step 3: The Decision Framework
After the legal assessment, HR and legal make a joint recommendation to your manager and their director. The decision typically falls into one of three categories:
Option A: Warn and return. Used when the stay was short, the legal exposure is low, and the employee's performance and standing are strong. You get a formal written warning, the policy is clearly explained, and you are expected back in your authorized work location within a defined window (often 30 days).
Option B: Terminate for cause. Used when the stay was extended, the legal exposure is significant, or when the company's remote work policy explicitly prohibits international work without approval. Termination for cause affects your severance eligibility, and depending on your employment contract, may invoke a clawback clause on signing bonuses or equity that was not fully vested.
Option C: Transition to contractor. Occasionally, companies that want to retain the employee but cannot support the compliance burden of employing them in their new location will offer a transition to an independent contractor arrangement through an Employer of Record (EOR) in that country. This solves the legal problem but means you lose employee benefits, and your tax and insurance situation changes significantly.
How They Actually Find Out (And It Is Usually Not IT)
The way most people expect to get caught: IT notices a foreign IP address in the VPN logs, generates an alert, and escalates to HR.
The way most people actually get caught: something happens in their real life that forces a location disclosure.
In my experience working inside hiring and HR pipelines, the detection patterns break down like this:
IT security alerts: Genuine real-time detection through Zero Trust or impossible travel monitoring. Common at financial services firms, defense contractors, and companies with SOC 2 compliance. At most mid-size tech companies, IT is not actively running location queries against individual employees.
Life events that reveal location: This catches far more people than IT surveillance. A medical emergency that requires local insurance documentation. A device failure that requires IT remote support, triggering a location check when they connect. A package delivery to a foreign address entered into a company expense system. A background noise on a video call (foreign-language TV, a street announcement) that prompts a question from a manager.
Administrative disclosures: Your Slack profile time zone updates automatically. Your calendar blocks show meetings scheduled in a time zone that does not match your registered location. You accidentally join a call at 3am your registered-time and someone notices.
Offboarding and audits: Companies discovered during layoffs or restructuring that employees were working from unauthorized locations when they had to collect equipment or close out payroll. The equipment collection request reveals the address immediately.
The common thread: most people are caught by their own digital footprint, not by a dedicated IT surveillance operation.
What a VPN Actually Protects Against (And What It Does Not)
A VPN routes your internet traffic through an exit node in another location, masking your real IP address from your employer's network logs.
What this addresses: the IP address your employer sees when you connect to their systems or internal tools.
What this does not address:
Wi-Fi network scanning: Company laptops running MDM software (Microsoft Intune, Jamf, or similar) can scan nearby Wi-Fi networks and cross-reference their MAC addresses against geolocation databases to determine your approximate physical location, independent of your network connection. You do not need to be connected to those networks for this to work.
Device time zone metadata: Your operating system, your calendar, your Zoom client, and your browser all report time zone data. If your computer's time zone setting does not match your registered location, that metadata is embedded in file timestamps, meeting invitations, and system logs.
Personal device leakage: If you access Slack, email, or Microsoft Teams on your personal phone without routing through a VPN, your phone's GPS and cell tower data reports your real location. Many corporate communication platforms log device-level connection data separately from network-level data.
DNS and WebRTC leaks: Imperfectly configured VPNs can leak DNS queries and WebRTC connections that reveal your real IP and approximate location even while the VPN is active.
A VPN is not a comprehensive location-masking solution. It addresses one signal out of several.
The Situations Where the Outcome Is Almost Always Termination
Not every unauthorized international stay ends the same way. Here are the specific factors that shift the outcome toward termination rather than a warning:
Stays exceeding 90 days: Most countries' tax residency thresholds sit between 90 and 183 days. Crossing 90 days in many jurisdictions triggers payroll and social security obligations that are difficult to unwind retroactively.
High-compliance industries: Financial services, healthcare, government contracting, and defense. These companies face regulatory scrutiny that makes unauthorized international work an audit risk, not just an HR policy issue.
Countries with complex labor protections: Germany, France, Italy, and most of the EU have strong employee protections that can apply to anyone performing work on their soil regardless of their employment contract's jurisdiction. An employee working from Germany for three months may have inadvertently acquired statutory rights under German labor law that the company cannot simply ignore.
Prior warnings or policy acknowledgments: If your company issued a remote work policy update that you signed acknowledging the prohibition on international work without approval, working abroad afterward is treated as a willful policy violation rather than an oversight.
Data access from restricted jurisdictions: If your role involves access to regulated data (patient records, financial data, classified government information) and you accessed it from a country on your company's restricted list, this elevates the incident from HR policy violation to potential legal and regulatory matter.
What to Do If You Are Currently in This Situation
If you are reading this because you are already working from another country without authorization and have not been caught yet, the decision you are making is between a controlled disclosure and an uncontrolled discovery.
Controlled disclosure: you go to your manager or HR, acknowledge the situation, propose a timeline for return or a formal accommodation request, and take responsibility for the policy gap. The outcome is likely a written warning. Depending on your company's remote work policy, there may be a path to a formal international work authorization that gets the situation into compliance.
Uncontrolled discovery: the company finds out through IT, a life event, or an administrative audit. At that point, the framing shifts from "employee who made a judgment call" to "employee who was hiding something." That shift changes how HR characterizes the incident in the decision framework, which changes the recommendation they make to leadership.
The risk calculation is the same as it was in the state relocation scenario: a controlled disclosure that results in a "no" leaves you in control of your next step. An uncontrolled discovery that results in termination for cause affects your severance, your unemployment insurance eligibility, and potentially the narrative you carry into your next job search.
FAQ: Working From Another Country Without Telling Your Employer
What happens if my employer finds out I was working from another country? HR initiates a three-stage process: duration assessment, legal and tax exposure review, and a decision on disciplinary action. Short stays in low-risk countries typically result in a formal warning and required return to your authorized work location. Extended stays or stays that triggered tax and compliance obligations typically result in termination for cause.
Can I be fired for working abroad without permission? Yes. Most employment contracts include a work location clause, and working from an unauthorized country is a policy violation that can constitute grounds for termination. In high-compliance industries (finance, healthcare, defense), the legal exposure created by the unauthorized stay makes termination more likely because the company needs to demonstrate it took corrective action to limit liability.
Does a VPN prevent my employer from finding out I am working from another country? A VPN masks your IP address from network logs, but it does not address other detection vectors: device MDM software that scans nearby Wi-Fi networks, time zone metadata in your operating system and apps, personal device location data from Slack or Teams, or administrative disclosures through expense reports, equipment support, or life events.
What is permanent establishment risk and why does it matter? Permanent establishment (PE) is a legal concept in international tax law that determines when a company has sufficient presence in a foreign country to be subject to that country's corporate taxes. An employee performing substantive work in a foreign country can trigger PE for their employer, meaning the company becomes liable for corporate income tax and payroll obligations in that jurisdiction. This is one of the main reasons companies react strongly to unauthorized international work.
What is the shortest amount of time I can work from another country without creating legal risk? There is no universal answer because it depends on the country, your industry, and what work you are doing. Most countries do not trigger tax residency for stays under 30 days, but some data protection frameworks apply from day one of access. The safest approach is to get explicit approval before the stay, regardless of duration, and to check whether your company's remote work policy has approved country lists or day limits.
Is it illegal to work from another country on a tourist visa? In most countries, yes. Tourist visas do not authorize the performance of work, including remote work for a foreign employer. Working on a tourist visa can result in fines, deportation, and entry bans for the employee, and in some jurisdictions, liability for the employer that allowed or enabled it.
What should I do if I am currently working from another country without authorization? Make a controlled disclosure before you are discovered. Go to your manager or HR, acknowledge the situation, and propose a timeline for return or a formal authorization process. Proactive disclosure is treated differently than being discovered through an audit or IT alert. A controlled disclosure puts you in a position to influence the outcome. An uncontrolled discovery puts HR in a position to characterize it as concealment, which typically worsens the disciplinary outcome.
What is an Employer of Record (EOR) and can it solve this problem? An Employer of Record is a third-party company that employs workers on behalf of another company in jurisdictions where the company is not registered. Some companies use EOR arrangements to legitimize employees working from countries where the company cannot or does not want to establish a direct payroll presence. If your company offers this as an option, it typically means transitioning from full-time employee status to a contractor arrangement, which changes your benefits, taxes, and employment protections.

