Its two flavours
Real (two way) VPN - where you control both endpoints or where both endpoints are trusted.
Work ( worksite to worksite, work laptop to worksite)
Home ( home to home, laptop to home etc.)
In which case Wireguard is friggin fast.
Fake (one way) VPN - where you only control one endpoint and put your trust into a THIRD PARTY provider, with no ability to 100% know if your data is being mined. If I was within agencies, I would be sure to have backdoors to all 3 party providers in my country (by law or by force) or own them outright. So think carefully where your third party provider is located. It doesnt have to be govt, it can be criminal enterprises owning these sites and selling your information.
Just a theory, I have no proof, but am naturally skeptical.
I'd rather manage rats than software. Follow my advice at your own risk! (Sob & mkx forced me to write that!)
MTUNA Certified, by the Ascerbic Llama!