Devices face different risks when travelling. They are more likely to be lost or stolen, they connect to networks you do not control, and in some circumstances they may be inspected at a border.
The measure that helps most is not a setting. It is deciding what to carry at all.
What changed in 2026
- Border device inspection stayed a live issue. Practices and legal authority continued to vary substantially by country.
- Cloud-first workflows made travelling light easier. Accessing data on arrival rather than carrying it became more practical.
- Biometric and passcode legal distinctions persisted. Different treatment in many jurisdictions continued to matter.
- eSIM adoption changed the connectivity picture. Local data became easier to obtain without a physical SIM.
Reduce what travels
The most effective step and the one people skip.
A laptop containing years of files, a phone with every account signed in, and an archive of messages represents a great deal of exposure in a bag that may be stolen.
Practical reductions: travel with a device holding only what you need for the trip, sign out of accounts you will not use, remove offline copies of files you can access remotely, and clear message archives you do not need — see disappearing messages explained for reducing accumulation generally.
For high-sensitivity travel, some organisations issue clean devices carrying nothing, with data accessed remotely and the device wiped on return. That is proportionate for specific situations and excessive for a holiday.
The honest threat assessment matters here. Most travellers face theft, not inspection. A stolen bag is the realistic risk, and it is addressed by encryption, backups, and carrying less.
At borders
Where inspection is a realistic concern, a few things matter.
Power devices down completely rather than sleeping them. A sleeping device holds encryption keys in memory and is closer to unlocked than to off. A fully powered-down encrypted device requires the passcode to access anything — see device encryption explained.
Understand the biometric distinction. In many jurisdictions, compelling someone to provide a fingerprint or face is treated differently from compelling a passcode. Where that distinction exists, disabling biometrics before a border crossing and relying on the passcode is a meaningful difference. This is a legal question that varies considerably, and it is worth knowing the position for where you are travelling.
Know your position. Rights regarding device searches at borders differ substantially between countries and between citizens and visitors. Refusing may have consequences ranging from delay to denial of entry.
Assume anything inspected is copied. If a device is taken out of your sight, treat its contents as disclosed and its integrity as uncertain.
On arrival and in transit
Hostile networks are less of a concern than they were, since nearly all traffic is encrypted — see public Wi-Fi safety. Avoid captive portals asking to install anything, and never dismiss a certificate warning.
Physical security is the bigger issue. Devices left in hotel rooms, bags left briefly unattended, and phones used openly in unfamiliar places.
Account access deserves attention before you leave: ensure your recovery methods work from abroad. A recovery path depending on a phone number that will not receive messages internationally is a problem discovered at the worst time — see account recovery planning.
Back up before departing. A lost device is an inconvenience if everything is backed up and a disaster if it is not.
Common mistakes
- Travelling with everything. Unnecessary exposure.
- Sleeping rather than powering down at borders. Keys in memory.
- Not knowing the biometric position. A meaningful legal distinction in many places.
- Recovery methods that do not work abroad. Discovered when locked out.
- No backup before departure. Loss becomes disaster.
- Elaborate measures for ordinary trips. Effort against a threat you do not face.
- Installing anything a hotel network offers. Never necessary.
FAQ
Should I take a separate travel device?
For high-sensitivity travel or countries where inspection is likely, yes. For ordinary travel, reducing what is on your usual device is proportionate and much simpler.
What if I am asked to unlock a device?
Depends entirely on jurisdiction and your status there. Knowing the position in advance is the only useful preparation, and legal advice is warranted where the stakes are high.
Is a VPN necessary abroad?
For accessing services restricted by location, or where the local network is genuinely untrusted, it has uses. It is not the general protection it is marketed as — see public Wi-Fi safety.
What about eSIMs?
Convenient for local data without swapping cards, and they carry the same carrier-account considerations as any mobile service — see SIM swap protection.
Where to go next
For the encryption travel security depends on, read device encryption explained. For network risk in transit, public Wi-Fi safety, and for recovery paths that work abroad, account recovery planning.
This is general information, not legal advice. Border search authority varies substantially by country.