September 25, 2026
The Stern Report: The Case for a Digital Travel Security Standard
The border is the one place on earth where a government can read your phone without a warrant. Not just China. The United Kingdom. And, as of last week, the United States says so in writing.
On September 17, 2026, the U.S. Court of Appeals for the Second Circuit ruled in United States v. Alisigwe that border officers may manually search a traveler's phone with no warrant and no suspicion at all. The traveler was a lawful permanent resident returning through JFK. Officers asked him to unlock his phone, he did, and they scrolled.
Why does this matter? Your device is not protected by where you are from. It is governed by where you are standing. And every organization that sends people across borders with corporate data on their phones is making a privacy and data-sovereignty decision at every checkpoint, whether it knows it or not.
There is a standard for keeping travelers physically safe. There is no standard for keeping their data safe at the border. That gap is the subject of this article.
Three governments, one posture: the device is fair game
China gets the headlines. But on the narrow question of what a border officer can do to your phone, the gap between China, the UK, and the U.S. is smaller than most travelers assume.
United States: the circuit that mattered just closed the door
Alisigwe matters because of where it came from. Two federal trial courts in New York had gone the other way: United States v. Smith (S.D.N.Y. 2023) and United States v. Sultanov (E.D.N.Y. 2024) both held that CBP needed a warrant to search a phone. The Second Circuit covers JFK, one of the busiest international gateways in the country. That warrant requirement is now gone, and the court required no suspicion at all for a manual search. The opinion expressly left open whether forensic searches warrant different treatment.
The volume is not trivial. CBP searched 47,047 devices in FY2024, about 90% of them manual. The April to June 2025 quarter set a quarterly record of 14,899. CBP correctly notes that is a tiny share of 420 million arrivals. It is also not random, and the traveler carrying a program manager's inbox does not get to choose whether they are in that share.
One more case should end the "just wipe it" conversation. In January 2025, a U.S. citizen at Atlanta's Hartsfield-Jackson airport gave CBP a duress passcode that wiped his phone. He was indicted in November 2025 under 18 U.S.C. § 2232 for destroying property to prevent seizure. The government does not have to prove the wiped data was evidence of anything. Wiping at the checkpoint is not a control. It is a charge.
United Kingdom: no suspicion, no right to refuse
Schedule 7 lets examining officers stop, question, and search travelers at UK ports without any suspicion. Travelers must unlock devices on request, and officers may copy and retain the data. In 2017, the director of a UK advocacy group, Muhammad Rabbani, was convicted under Schedule 7 for refusing to hand over his phone and laptop passwords. He said the devices held confidential client material. Schedule 3 of the 2019 Act extends a similar no-suspicion power to questions of "hostile state activity."
The UK is a close ally with an independent judiciary and real oversight. It also has border device powers that, in practice, are comparable to China's. Both statements are true.
China: formalized, broad, and discretionary
China's Ministry of State Security issued two procedural rules in April 2024 that took effect July 1, 2024. They authorize state security officers to collect "electronic data" including messages, email, chats, documents, and app data. In emergencies, officers can inspect devices on the spot after presenting credentials. Chinese authorities have publicly pushed back on claims that every traveler's phone will be checked. That is probably accurate. It is also beside the point. The authority exists, the threshold is low, and the decision belongs to the officer.
The pattern: three very different governments, one shared legal posture. At the border, the device is fair game.
Privacy and data sovereignty: two failures, one checkpoint
A border device search is two violations at once. The traveler loses privacy. The organization loses sovereignty over its data. Neither is the smaller problem, and one phone carries both.
The privacy failure. The U.S. Supreme Court said it plainly in Riley v. California (2014): a modern phone holds "the privacies of life." Messages, photos, health and banking apps, location history, contacts. Riley requires a warrant to search a phone after an arrest. At the border, that protection does not apply, and the traveler has no say in who reads any of it. For a foreign national, the protections of their home country do not travel with them either.
The sovereignty failure. When an employee crosses a border, every byte on that device is exposed to the laws of the country they are entering. That includes data the organization is legally obligated to protect under a completely different set of laws:
- Customer and employee personal data governed by GDPR or other data-protection regimes, now reviewed by a foreign official with no lawful basis the data controller ever approved.
- Privileged and confidential material, including legal communications, M&A files, and board materials. Rabbani's conviction is the proof case: "it's confidential" is not a legal exemption at a UK port.
- Controlled Unclassified Information and export-controlled technical data held by Defense Industrial Base contractors. Where that data sits, and who can access it, is a compliance question before it is a travel question. DIB contractors should be asking their export and CUI counsel how a border search of a device holding that data fits their obligations.
- Intellectual property and source material whose value depends on who has seen it.
None of these obligations pause at the jet bridge. The organization still owns the data. It just no longer controls who reads it.
This is also a workforce-adoption problem that got ahead of the compliance model. Employees carry one phone. It holds their boarding pass, their family photos, and the company's email. Travel policy was written for laptops and printed itineraries. Mobile use at the border was never designed. It accumulated.
The standards gap: we protect the traveler's body, not their data
Organizations that take travel seriously already have a framework for it. ISO 31030:2021, Travel risk management: Guidance for organizations, gives them a duty-of-care model for assessing and treating risk to people who travel for work. The State Department's four-level travel advisory gives them a shared vocabulary for physical risk by country.
Neither was built to answer the question a CISO actually asks before a trip: what can the destination government do to this device, and what is on it?
Public descriptions of ISO 31030 focus on physical safety, security, health, and organizational process. We have not found device or data security treated as a distinct risk domain in them. The State Department's levels do not score border device authority at all. A country's advisory level tells you nothing about whether its border officers can compel a password.
The U.S. government's device guidance is real but fragmented. NCSC, FBI, CISA, and NSA each publish traveler tips. They are tactical: power down before the border, use a loaner, disable biometrics. The NIST publications that govern enterprise mobile security, such as SP 800-124 for mobile devices and SP 800-46 for telework, do not address the border as a threat condition. Universities have filled the gap with homegrown high-risk-country lists for faculty travel, sourced informally from State, OFAC, and FBI material.
The result is that every organization builds its own answer, at its own rigor, on its own update cycle. That is the definition of a problem that needs a standard.
What a digital travel security standard should contain
The fix is not another tip sheet. It is a sourced, scored, and governed classification that an enterprise security team, a procurement officer, or a journalist can cite and check. Five components get us there.
1. A familiar scale. Borrow the shape of the State Department's four levels so no one has to learn a new mental model. Apply it to a new dimension: device and data risk.
2. Independent, weighted factors. Score each country on state-linked targeting evidence, border device authority, telecom and network risk, cybercrime maturity, and legal data protection. No single factor should move a country more than one level. Movement should reflect convergence, not a headline.
3. Citable sources only. Primary U.S. government sources first (CISA, NSA, FBI, ODNI, State, OFAC, Commerce), then allied agencies (NCSC-UK, ACSC, CCCS, BSI), then institutional and industry reporting as corroboration. Every score carries its citations so a skeptical reader can verify it without taking anyone's word.
4. Predictable governance. Publish the scoring thresholds before scoring any country. Re-score quarterly, monitor monthly, and issue out-of-cycle patches only for major events, such as a new border search law or a joint advisory. Rare patches get read.
5. Controls mapped to levels. Tell organizations what to do, not just where it is dangerous. That includes what data may be resident on a device at each level, pre-travel and post-travel procedures, how to handle privileged material, and what not to do. Wiping at the checkpoint belongs on that list.
The border-authority factor is where this starts to bite. Under this model, the United States and the United Kingdom score higher on border device authority than many travelers would expect. That is not a political statement. It is what the law says.
The architectural answer: nothing on the device to search
No organization can change the border search exception. Every organization can change what the search finds.
That is the principle behind a remote workspace model like Hypori's. The enterprise workspace runs in a secured environment, and the device receives encrypted, encoded pixels. Mission application data, messages, and files are not stored on the phone. An officer who scrolls through the device sees the Hypori client, not the program files. A forensic image of the device captures no enterprise data at rest, because none is there to capture.
U.S. policy already recognizes that line. CBP Directive 3340-049A limits border searches to information resident on the device and directs officers not to intentionally access information stored solely remotely. Alisigwe confirms broad authority over the device. It does not change what is on it.
Let me be precise about the limits, because practitioners will ask:
- The search still happens. Remote architecture does not make a border search unlawful or stop an officer from conducting one. It changes the result.
- Access is controlled by the enterprise, not the traveler. An officer in a non-U.S. jurisdiction may press a traveler to authenticate to the workspace itself. Because access is governed server-side, the organization can set travel-based access policy before the trip rather than asking the traveler to make a legal judgment at the counter. Counsel should review any such policy for each jurisdiction.
- It is not a substitute for device hygiene. A device that has been out of the traveler's control at a Level 3 or Level 4 border should be treated as untrusted on return. Remote architecture limits what was on the device. It does not certify what may have been put on it.
- Personal data is still personal data. Photos, personal messages, and the traveler's own apps remain on the phone and remain searchable.
This is also the lawful alternative to the duress wipe. Destroying data at the checkpoint can be a federal crime. Never putting enterprise data on the device in the first place is architecture.
What comes next
This is the first in a series. In the coming months, Hypori will publish a draft Device Security Travel Advisory framework built on the model above: a four-level scale, published scoring criteria, and a citation trail for every country score. It is intended as an open reference, not a product brochure, and we will invite comment from security leaders, travel risk managers, and standards bodies, including NIST.
The border has always been where sovereignty is enforced. It is now where privacy and data sovereignty are lost. The question for every organization that sends people abroad is simple: when the officer asks for the phone, what will they find?
Recent articles

Mobile
September 17, 2026
You Can’t Read the Label from Inside the Jar
Intune's endpoint telemetry doubles as a license reconciliation tool. Here's why Microsoft's "free" security feature may be doing more accounting than protecting.
Mobile
September 10, 2026
The End of the Two-Phone Era: Real Security Without Employee Burnout
Locked-down work phones push employees to work around security instead of embracing it. See how Mobile Isolation delivers real protection without the two-device tax.
Security
September 8, 2026
The Stern Report: The Emperor's New Clothes
MDM reports on how a device secured itself, it doesn't secure your data. See why the industry's default mobile security answer is a compliance instrument wearing a security label, and what actually closes the gap.
