For the VPN example, this isn’t an example of shifting trust. Privacy Guides require VPN provider to not log queries (verified with open source client and audited servets) , have good security policy and allow anonymous account creation. This is precisely, as stated by Privacy Guides so you don’t have to shift trust, since the trust isn’t needed as it is guaranteed by technogical means.