I used to run a VPN service in the US. Unless you give each client their own unique IP address there's simply no way to figure out which customer downloaded/uploaded any given file at any given time. Unless you record every packet it just isn't possible.
I got loads of DMCA takedown notices and I had a form-based reply for every one of them: This is a VPN service, Bittorrent traffic is transient (therefore there's nothing to "take down"), and I couldn't identify the infringer even if I wanted to.
After operating like that for two years I never once had anything come of it. I never got so much as a reply from the lawyers that sent out these notices. I even put my phone number in the form letter if they wanted to discuss it!
The closest thing I ever got to, "you must identify who did this" was the CTO (or was it CSO?) of Level 3 demanding that I tell them who was busting out of their intranet and how to block my service (it worked over all ports--take your pick, UDP and TCP and also through proxies!). I basically told that I would not betray the privacy of my customers and that even if I did have the technical capability to do such a thing (which I didn't). I also told him that when any of my customers got blocked I would simply get some new IP addresses on completely different networks/providers (I had it all automated).