What this protects, and what it doesn't
Protects
- Against losing your data when a device is lost, stolen, broken or kept at a border.
- Against a thief or finder reading a powered-off, encrypted device.
- Against exposing years of messages, photos and work files when you only needed a few of them on the trip.
- Against hotel, airport and café networks reading or changing your traffic.
Does not protect
- It does not give you a right to refuse a border inspection. Border officers have legal powers to examine devices, and refusing to unlock one can have consequences (see the step on border inspections).
- It does not protect a device that is unlocked and in someone else's hands, or one that was tampered with while out of your sight.
- It does not hide data stored online: your accounts still exist, and you can be asked about them.
- It is not legal advice. Rules differ by country and by your citizenship or residence status.
Prerequisites
- A recent backup of every device you take, stored somewhere other than in your luggage.
- Full disk encryption turned on (see the full disk encryption guide).
- Your passwords in a password manager, so that you can sign out of accounts and sign back in later.
Step by step
-
Decide what the trip needs
Before packing, ask: which devices and which data do I actually need on this trip? Your answer depends on your threat model: where you go, your nationality or residence status, your job (for example confidential client or source material), and how bad it would be if someone copied the device.
EFF's guide to the US border makes the same point: the simplest and most reliable precaution is to carry less data.
-
Back up, and keep the backup apart from the device
Back up each device before you leave. Do not carry the backup drive in the same bag as the laptop: if both are lost or kept together, the backup is gone too. An encrypted cloud backup or a drive left at home both work. The secure backups guide shows how.
-
Carry less data
- Leave at home the devices you do not need on the trip.
- Consider a separate travel laptop or phone that holds only what the trip requires, and restore it from a backup when you return.
- Move files you do not need off the device. Dragging files to the bin does not erase them; delete them for good, or reset the device and restore only what you need.
Never hide data in a way that is meant to mislead officials. EFF advises against it, and against lying to border officers.
-
Encrypt, and use a passcode rather than a fingerprint
- Turn on full disk encryption on every laptop. Phones are encrypted by default once they have a passcode. See Encrypt your whole disk.
- Use a long passphrase or passcode, not a short PIN.
- EFF advises not to rely only on fingerprint or face unlock: they are weaker than a passcode, both technically and legally. Many phones let you require the passcode on the next unlock; on iPhone, pressing and holding the side button with a volume button until the power-off screen appears does this.
-
Sign out of what you do not need
A device can show cloud data through the apps and browsers that are signed in. Before you travel, sign out of email, cloud storage and social media apps you will not use on the trip, and remove saved passwords from the browser. Your password manager lets you sign back in afterwards.
In the US, CBP says its officers may not use a device to access information that is stored only remotely, and that they disable network connections before a search. Signing out still limits what the device itself shows, and protects you if the device is lost or stolen.
-
Power off before checkpoints
Turn devices fully off, not just to sleep, before you reach security or a border, and when you leave them anywhere. EFF notes that a powered-off encrypted device resists attacks that only work while it is running.
-
Know what can happen at a border inspection
Using the United States as an example, CBP's published policy (CBP Directive 3340-049B) says:
- Officers can search electronic devices at the border. A basic search is a manual review. An advanced search, which connects external equipment to copy or analyse the content, requires reasonable suspicion or a national security concern and a senior manager's approval.
- Travellers must present devices in a condition that allows inspection. A device that cannot be inspected because of a passcode or encryption may be detained.
- A US citizen will not be refused entry for refusing to unlock a device, but the device may still be detained. For a foreign national, refusal can be taken into account in the decision to admit them.
Other countries have their own rules; check the official site of the border authority of the country you visit. Stay calm and courteous, do not lie, and do not physically interfere with a search. If you carry confidential professional material (for example as a lawyer, doctor or journalist), ask your professional body before the trip.
-
Treat hotel and public Wi-Fi as untrusted
- Use your phone's mobile data or tethering when you can.
- On public Wi-Fi, rely on HTTPS-only browsing (see Always use HTTPS), and use a VPN if you need to protect your traffic from the local network (see untrusted public Wi-Fi).
- Do not charge from unknown USB ports or cables; use your own charger in a wall socket.
- Do not plug in USB drives you are given.
-
After the trip
- If a device was taken out of your sight (kept at a border, left in a hotel room), consider it possibly tampered with. For high-risk travel, reset it and restore from your backup.
- If you gave a password to anyone, change it.
- Sign back in to your accounts and check their sign-in history for unknown devices.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Carrying the only backup in the same bag as the laptop.
- Putting a laptop to sleep instead of shutting it down before a checkpoint.
- Relying on fingerprint or face unlock alone when a device may be taken from you.
- Deleting files by dragging them to the bin and assuming they are gone.
- Trying to deceive a border officer about what a device holds.
- Plugging a phone into an unknown USB charging port.
Going further
For a high-risk trip, a separate travel phone with a fresh account and only the apps you need limits what can be copied. Before a journey, remove metadata from documents and photos you plan to share with the metadata cleaner, and make sure two-factor sign-in still works without your home number: see Defend against SIM swaps and number theft.