Introduction: the border, the blind spot in your digital hygiene
You may have spent months cleaning up your online presence: encrypted messaging, compartmentalized accounts, a hardened browser, systematic refusal of advertising cookies. Then you board a plane, and that patiently built edifice fits inside a 180-gram object sitting in a plastic tray on a conveyor belt.
The border is the one place in the world where ordinary law dissolves. The usual safeguards — the need for a warrant, proportionality, judicial oversight — are relaxed everywhere, in Europe as elsewhere. An officer can ask you to unlock your device in a context where refusal carries an immediate cost: delay, questioning, denial of boarding, or even denial of entry for a non-national. This isn't a movie plot: it's an administrative practice documented for more than a decade.

The problem isn't just the inspection itself. It's that the modern smartphone is a condensed biography: ten years of photos, your travel history, your professional contacts, your family conversations, your medical searches, your banking credentials. No other piece of luggage holds as much. So the right question isn't "how do I refuse a search?" but "how do I make sure a search reveals almost nothing?".
What French and European law actually says
Let's start by clearing up the rumours, in both directions.
The French customs code
In France, the customs code grants officers the right to inspect goods, means of transport and persons. Case law has gradually extended this notion to digital media: a phone, a hard drive or a USB stick can be treated as media likely to contain intangible goods or elements relating to a customs offence.
An important point: the Cour de cassation and the Conseil constitutionnel have, on several occasions, tightened the conditions under which these powers may be exercised, particularly regarding customs detention and access to data. The Conseil constitutionnel has also enshrined the protection of the secrecy of correspondence and of privacy as components of individual liberty. The framework is therefore not a blank cheque, but it remains markedly more permissive than an ordinary police check in a public place.
Article 434-15-2: the question of the unlock code
This is the most widely misunderstood point. Article 434-15-2 of the French penal code punishes the refusal to hand over a secret decryption key to the judicial authority, where that key may have been used to prepare or commit a crime or an offence. In 2022, the Cour de cassation, sitting in plenary assembly, confirmed that a phone's unlock code can constitute such a key.
But this obligation sits within a specific framework: a proper formal request, within judicial proceedings, concerning a device that may have been used in an offence. A routine check at a border post is not automatically that framework. In practice, the line between "an officer's insistent request" and "a legally grounded formal request" is blurred, and it is precisely this grey zone that weighs on the traveller.
Outside the European Union
In the United States, the border search exception doctrine allows CBP officers to inspect electronic devices without a warrant, with a distinction between a "basic" (manual) search and an "advanced" one (extraction using a forensic tool). The United Kingdom has Schedule 7 of the Terrorism Act 2000, which permits detention and examination without prior suspicion, and where refusing to cooperate is itself an offence. Every jurisdiction has its own rules; assuming yours are universal is the first mistake.
Basic rule: data you don't carry can't be searched. Any serious strategy starts with reducing volume, not with concealment.
The cardinal principle: minimization before concealment
A phone bristling with encrypted apps, hidden containers and exotic messaging services attracts attention. A nearly empty phone tells no story. When discretion is the goal, the second is almost always better than the first.
The dedicated travel device
The most robust solution is to travel with a device separate from your main phone. This isn't paranoia: it's the same reasoning that makes you leave important papers in the hotel safe rather than in your pocket.
An entry-level Android smartphone, bought new, set up with an account created for the occasion, containing only what you need on site — tickets, offline maps, a few contacts — does the job perfectly. You don't need an expensive model: austerity is a feature here.
What this phone should contain:
- Offline navigation (maps downloaded in advance)
- Your travel tickets and bookings, ideally in paper form too
- The numbers of three or four essential contacts, noted separately
- A banking app only if it's indispensable, otherwise nothing
What it should not contain: your photo library, your message history, your work accounts, your main password manager, your personal documents.
The pre-departure purge
If you're travelling with your everyday device, set aside an hour of calm preparation a few days before departure. First back everything up to a medium you leave at home — an encrypted external hard drive does the job nicely and costs about as much as a restaurant meal. Then delete: old conversations, photos, unused apps, secondary email accounts.
Log out of the accounts you won't be using. An open session is direct access to years of content stored on servers, far beyond what the device physically holds. This is the point travellers underestimate most: searching a connected phone isn't searching an object, it's searching a cloud.
Encryption, locking and biometrics: the settings that matter

Power off, don't just lock
A phone that is switched on but locked is in a state where the encryption keys are partly held in memory (the "After First Unlock" state). A fully powered-off phone is in a far more resistant state: the data is encrypted and the key is only derived once the code is entered. Before any foreseeable check — customs, border control, boarding — switch the device off completely.
Give up biometrics for the duration of the trip
Fingerprints and facial recognition are conveniences, not security measures. They can be triggered without your active consent: it's enough to hold the device up to your face or press your finger onto it. A long alphanumeric code, by contrast, requires a deliberate act on your part, which shifts the question onto the legal ground of the right against self-incrimination.
For the duration of your trip, disable biometric unlocking and use a code of at least eight characters. The CNIL regularly points out that biometric data, because it cannot be revoked, warrants particular caution.
The table of reflexes
| Situation | Recommended reflex | Why |
|---|---|---|
| Before the border post | Device completely switched off | Encryption in its strongest state |
| During the flight | Airplane mode, Bluetooth off | No unintentional connection |
| Airport or hotel Wi-Fi | Avoid, or use a trusted VPN | Open and captive networks |
| After the check | Review installed applications | Detect unsolicited additions |
| Back from the trip | Factory reset before reuse | Breaking the chain |
VPNs: useful, but not magic
A VPN encrypts the traffic between your device and the provider's server. That's valuable on hotel or station Wi-Fi, where passive interception is trivial. It is not, however, an anonymity tool: your provider sees what your carrier used to see, and in several countries the use of unauthorized VPNs is itself restricted. Check local legislation before departure; install the VPN before you arrive, never from the destination country, where app stores may be filtered.
Communicating from abroad without rebuilding your profile
The roaming trap
The moment your French SIM card latches onto a foreign network, a precise trace is created: IMSI identifier, IMEI hardware identifier, serving cell, timestamp. This connection data is retained by carriers in accordance with French and European legal obligations. In other words, your itinerary can be reconstructed after the fact, with a granularity of a few hundred metres in urban areas.
If your aim is discretion about your movements, permanent airplane mode with exclusive use of Wi-Fi considerably reduces that footprint. A high-capacity power bank then becomes an accessory of confidentiality as much as of comfort: a phone that dies for lack of power pushes you into hurried choices and into charging at public USB stations, whose internals you can never verify.
Local SIM cards
Buying a prepaid SIM card on arrival is often presented as an anonymity solution. That's less and less true. The vast majority of European countries, along with many non-EU states, now require registration of the buyer's identity. A local SIM changes your network identifier, but doesn't make you anonymous: it simply makes you identifiable in a different register.
It remains useful for another reason: compartmentalization. The number you use abroad isn't the one tied to your accounts in France, which limits correlations and avoids exposing your main number to dubious local services.
Sending messages without exposing your number
There are situations while travelling where you need to pass on a short piece of information without revealing your number: flagging a problem to a local administration, contacting someone you met on site, notifying a relative from a line that isn't yours, or simply keeping a personal number out of an unknown address book.
This is the natural territory of online SMS gateways. The message leaves from the service's infrastructure, the recipient never sees your line, and you don't have to entrust your number to a third party whose retention practices you don't know. One caveat, though: anonymous to the recipient doesn't mean untraceable to everyone. The provider keeps technical logs and remains subject to judicial requests. It's a tool for social discretion, not for clandestinity — the distinction is essential, and it applies just as much in Lyon as in Bangkok.
The gear that genuinely makes a difference

A few inexpensive accessories clearly improve the situation, without requiring technical skills.
The first is the privacy screen filter. On a plane, on a train, in a waiting room, the person next to you reads your messages effortlessly. A polarizing film that blacks out the screen outside the viewing axis settles the matter for good and costs a few euros. It's the most cost-effective countermeasure in existence against shoulder surfing.
The second is the USB data blocker, sometimes called a "USB condom". It sits between your cable and a public charging point, letting power through while cutting the data pins. Authorities in several countries have warned about juice jacking, the technique of booby-trapping airport or station charging points. The best habit, though, remains charging from your own power bank.
The third, more radical, is the RFID-blocking Faraday pouch, which completely isolates the device from any signal. Useful when you want physical certainty — rather than a mere software setting — that nothing is transmitting or receiving. It also protects contactless bank cards and biometric passports from opportunistic reading.
Finally, two often-overlooked items: a hardware-encrypted USB key to carry the few documents you genuinely need, separately from your phone; and, for those who want to understand the fundamentals rather than follow recipes, a book on cybersecurity and privacy is worth more than ten contradictory tutorials found online. French-language introductory works on personal data protection have improved considerably in recent years.
What to do during and after a check
During
Stay courteous and factual. Aggression brings no benefit and turns a routine check into an incident. You can ask for the legal basis of the request, the officer's name or badge number, and whether the device will be examined out of your sight. Note the time, the place, the duration. If you're a journalist, lawyer or doctor, say immediately that the device contains data covered by professional confidentiality: several legal frameworks provide specific protections, but you still have to invoke them on the spot.
After
Consider that a device out of your sight for more than a few minutes is no longer trustworthy. That's not paranoia, it's hygiene: you don't know what was plugged into it.
The sensible procedure:
- Don't log back into any sensitive account from that device.
- Check the list of installed applications and the permissions granted.
- From another trusted device, change the passwords of the accounts that were logged in.
- On your return, fully reset the device before using it normally again.
- Review the login logs of your main accounts (Google, Apple, email) to spot any abnormal access.
Conclusion: travelling light, in the digital sense
Protecting your privacy on the move doesn't come down to a miracle piece of software or a hidden setting. It comes down to a decision made before departure: deciding what you take with you.
A phone containing three years of your existence is a risk that neither encryption, nor a VPN, nor any trick can offset. A phone containing your return ticket and two phone numbers is an object, not a biography. Between the two lies an hour of preparation and a few dozen euros of equipment.
This logic matches the one that governs good digital hygiene as a whole: don't produce data you don't need to produce, don't carry information you don't need to carry, and use communication tools that don't require revealing your identity in order to work. The border merely applies brutal pressure to a principle that holds true every day of the year.
To go further on your rights, the CNIL publishes practical fact sheets on personal data protection, and ANSSI issues freely available recommendations on IT hygiene, including a regularly updated advice passport for travellers. These are one-hour reads that spare you months of trouble.



