VPN privacy is overrated. You're tunneling your private data over an insecure medium. And then you're trusting the VPN not to snoop on your data (or to keep IP logs on you). Most of your holdings should be in cold storage (VPN should be irrelevant). Even your spending wallet can be on an air-gapped computer, where you push only signed transactions from an online machine. You can use TOR to do so for privacy purposes.
Only for an online wallet or third party signing setup (as the title implies). In practice, I recommend against both. I much prefer an offline signing environment. Multisig can be used for additional security.