Introduction: 128 gigabytes in your pocket, and an officer in front of you
Airport, 6:40 a.m. The queue inches forward. You hand over your passport, the officer scans it, looks up, and asks a perfectly ordinary question: "Could you unlock your phone, please?"
At that precise moment, it isn't an object you're handing over. It's seven years of conversations, a minute-by-minute record of your movements, your family photos, your work emails, your banking apps, your health notes, your exchanges with a lawyer or a doctor, your entire contact list and the drafts you never sent. A modern phone holds more personal information than a full search of your home would have turned up in the 1990s.

And yet the border is one of the few places in the world where the usual safeguards — a warrant, a judge, a stated reason — collapse. Not everywhere in the same way, not to the same degree, but enough that the topic deserves better than forum rumours. This guide sets out what the authorities can genuinely demand, what French and European law actually says, and how to prepare your devices before you leave — without paranoia and without making your trip harder than it needs to be.
Why the border is a legal world of its own
A customs check is not a criminal investigation
In most democracies, searching someone's home or phone requires a procedure: suspicion, authorisation, oversight by a magistrate. At the border, the logic is different. The state exercises a power to control the movement of people and goods, and that power has historically come with broad prerogatives: opening a bag, patting down clothing, prising apart a lining.
The problem is that the phone has been filed under the same heading as the suitcase. But a smartphone isn't a physical container: it's a doorway to data that isn't even stored on the device, but on remote servers. Opening your messaging app isn't rummaging through your pockets — it's reading three years of your correspondence.
What French law says
In France, Article 60 of the Customs Code allows officers to inspect goods, means of transport and persons. The question of digital devices has been clarified by case law and by successive reforms of the Code, following several rulings by the Conseil constitutionnel — notably the decision of 22 September 2022, which struck down the previous wording of Article 60 as a disproportionate interference with privacy, forcing lawmakers to set limits on the right of inspection (the law of 18 July 2023).
Two points are worth remembering:
- Refusing to hand over a decryption key (PIN code, password, pattern) can carry criminal penalties under Article 434-15-2 of the Penal Code, but that provision applies within a specific judicial framework, on the formal requisition of an authorised authority, and in relation to a means of encryption "liable to have been used to prepare, facilitate or commit a felony or misdemeanour". In 2022, the Cour de cassation confirmed that the unlock code of an encrypted phone could fall within that scope.
- An informal request at the desk is not a judicial requisition. You are entitled to ask politely on what legal basis the request is being made, and what kind of check this is.
The right instinct isn't to dig in with a blanket refusal, but to know how to tell a simple request apart from a formalised procedure — and to ask, calmly, for the latter to be spelled out.
And outside Europe?
This is where the gaps become striking. In the United States, Customs and Border Protection publishes its own directives: it distinguishes a "basic" search (the officer handles the device) from an "advanced" search (connection to an extraction tool), the latter requiring reasonable suspicion and a supervisor's approval. The statistics CBP publishes each year show tens of thousands of searches annually out of hundreds of millions of entries: rare, but far from theoretical. The United Kingdom, through Schedule 7 of the Terrorism Act 2000, allows suspicionless stops in port and airport areas. Other countries, notably in Central Asia and the Middle East, inspect apps or photo galleries with no publicly documented legal basis.
The mental rule to hold on to: your rights don't travel with you. The GDPR protects how your data is processed by entities subject to European law; it carries no weight with a border guard 9,000 kilometres away.
The principle that changes everything: minimise before you leave
You can only truly protect what you didn't bring
All the serious literature on the subject — from the Electronic Frontier Foundation, from security guides written for journalists, or from ANSSI's recommendations for business travel abroad — converges on one simple idea: the best protection isn't the longest password, it's the absence of data.
ANSSI has in fact published a "travellers' advice passport" for years, aimed at professionals on the move. Its central recommendation is unambiguous: travel with dedicated equipment containing only the data strictly necessary for the trip.
For a private individual, the reasonable version boils down to three questions:
| Question to ask yourself | What it means in practice |
|---|---|
| What do I actually need once I'm there? | Tickets, maps, emergency contacts, payment methods, translation |
| What do I not want exposed? | Work messaging, intimate photos, medical documents, financial archives |
| What can I retrieve remotely after the check? | Anything synced that can be reinstalled in five minutes |
The travel phone: the most effective solution
For sensitive destinations, the best answer is still a separate device. A budget Android phone, bought new, holding nothing but a travel messaging app, offline navigation and your bookings, often costs less than one night in a hotel. It unlocks without stress, reveals nothing, and losing it is no disaster.
The same logic applies to computers: if you have to work, a refurbished laptop kept clean, with a dedicated user account and an empty workspace, saves you from carrying ten years of professional life in your cabin bag.

If you're travelling with your main phone
That will be the case for the vast majority of trips. A few steps, taken the night before, make a big difference:
- Power the device off before the check. A switched-off phone is in its strongest encryption state (the keys aren't in memory). A phone that's merely locked but powered on is, technically, far more vulnerable.
- Turn off biometric unlocking while you're going through border control. A face or a finger can be presented to the device without your active cooperation; a long alphanumeric passcode cannot.
- Log out of sensitive apps and clear session tokens: secondary messaging apps, cloud storage, professional social networks.
- Make a full backup before you leave, kept at home on an encrypted external hard drive that stays behind. If the device is held, wiped or lost, you lose nothing.
- Empty the photo gallery, or at the very least the albums you wouldn't want a stranger scrolling through.
During the check: your demeanour matters as much as the tech
Stay factual, cooperative, and keep a record
A border isn't a place for legal debate. The goal is to get through, not to win a point of law. A few principles drawn from travellers' accounts and from the advice of civil liberties organisations:
- Don't lie. A false statement turns a routine check into a formal procedure.
- Ask calm questions. "Am I free to go?", "Is this request mandatory?", "On what legal basis?" are legitimate questions, as long as they're asked without aggression.
- Write things down. Time, place, badge or office number, how long the device was held. A small hardcover travel notebook in the outer pocket of your bag is often more discreet and more reliable than a note taken on the very phone you've just been asked to hand over.
- Never try to delete data in front of the officer. That's the gesture that turns a check into outright suspicion.
If your device is taken away
Assume that any device out of your sight is compromised. That's not paranoia: it's the rule applied by organisations that send staff abroad.
When you get it back:
- Change the passwords of your main accounts from another device, not from the one you've just been handed back.
- Revoke active sessions in the security settings of your accounts.
- Factory-reset the device before using it seriously again.
- Check the authorised devices on your encrypted messaging apps: a second terminal linked to your account is the classic sign of interception.
The rest of the trip: the traces we forget
Border control is the dramatic part, but it accounts for only a fraction of the data you leave behind on a trip.
Open networks
Airport, hotel and station wifi often asks for an email address, a phone number, or a sign-up. These captive portals amount to time-stamped databases of who was where. A disposable email address kept for travel, and a number used only for that kind of sign-up, keep your main identity from being linked to every point you pass through.
For the connections themselves, tethering from a local prepaid SIM remains healthier than a shared public network. And if you travel often, a high-capacity power bank spares you the unfortunate reflex of plugging your phone into a public USB port you know nothing about.
Roaming and your SIM card
Your operator logs every attachment to a foreign network. That's technically unavoidable and legitimate. But it also means a simple roaming record traces your route country by country. For trips where you'd rather limit the correlation between your main line and your movements, a local SIM or a travel eSIM changes things — provided it isn't itself registered in your own name, which depends heavily on local regulations.

The objects that speak for you
A smartwatch records your heart rate, your sleep and your location. An item tracker slipped into your suitcase broadcasts its location — and therefore yours — to an entire network of third-party devices. Handy for finding lost luggage, less harmless than it looks in terms of the traces it leaves. Likewise, recent cameras embed GPS coordinates in every file: a compact camera without GPS, or simply turning off geolocation in the settings, stops you from publishing your exact itinerary along with your photos.
Finally, for documents you have to carry physically — passport copies, certificates, supporting paperwork — an RFID-blocking travel pouch limits remote reading of the contactless chips in your passports and bank cards. The real level of risk is debated, but the cost of the precaution is negligible.
Dashboard: three profiles, three levels of preparation
| Tourist trip within the EU | Non-EU trip, standard destination | Sensitive destination or business travel | |
|---|---|---|---|
| Device | Your usual phone | Your usual phone, gallery cleaned out | Dedicated, blank device |
| Lock | 6-digit passcode | Long passcode, biometrics off at the border | Long passcode, device powered off at checks |
| Backup | Recommended | Essential, left at home | Essential + written inventory of accounts |
| Accounts | No changes | Log out of sensitive services | Separate travel accounts |
| After you return | Nothing | Check active sessions | Full factory reset |
The key takeaways
The border isn't a legal vacuum, but it is a zone where the usual privacy protections are markedly weaker, and where the rules change every 500 kilometres. Three ideas are enough to prepare for it:
- The best-protected data is the data that never travelled. Everything else is damage control.
- A powered-off phone beats a locked phone, and a long passcode beats a fingerprint, at least for the few minutes the check lasts.
- Cooperating politely while knowing your rights is almost always more effective than a flat refusal — provided you prepared your devices before you reached the desk.
And for those situations where you need to let someone know you've arrived, that you're running late, or that something has happened, without tying that message to your personal line, a messaging channel that requires neither sign-up nor a verified number remains the simplest tool: it leaves no directory entry, no operator records, and no account to revoke when you get home.
Travelling while protecting your privacy isn't about hiding. It's simply about not carrying your entire existence in your pocket — and deciding for yourself what crosses the border.
Further reading
- ANSSI — "Passeport de conseils aux voyageurs", official recommendations for travel abroad.
- CNIL — practical fact sheets on securing mobile devices and managing personal data.
- Conseil constitutionnel — decision no. 2022-1010 QPC of 22 September 2022 on customs inspection powers.
- Electronic Frontier Foundation — "Digital Privacy at the U.S. Border", a detailed guide to device searches.



