What happened

The US Court of Appeals for the Second Circuit held in United States v. Alisigwe that the border search exception allows officers to conduct suspicionless searches of a traveler's digital devices. Issued on September 17, the decision addresses manual searches, where an officer scrolls through a phone or laptop. The court expressly declined to decide whether more sophisticated forensic searches would also count as routine.

The court reasoned that a search of a traveler's property at the border, a cellphone included, is routine because it serves the government's interest in preventing the entry of unwanted persons and effects, and does not intrude on privacy in the way an invasive body search would. It rejected rulings by New York federal district courts that had required a warrant before officers could search a traveler's phone, even at the border.

The ruling widens an existing split between the circuits. The Seventh Circuit has allowed brief, suspicionless scrolling through a traveler's devices. The Ninth Circuit permits a warrantless search of a device only when officers are looking for contraband. The Eleventh Circuit has gone further than the Second, holding that officials need no reasonable suspicion even for forensic searches, however intrusive. The Supreme Court has not taken the question.

Customs and Border Protection has its own internal directives. An advanced search, which CBP defines as connecting equipment to copy or analyze the contents of a device, requires reasonable suspicion of certain unlawful activity unless a national security concern applies. Those directives do not create enforceable rights, so the protection a person actually has can depend on where they enter the country. The practical guidance for business travelers is to carry as little sensitive data as the trip allows and to expect a device may be seized, scrolled through or examined forensically.

Why this is a GRC story

Business travel is a data transfer route. Every laptop that crosses a border carries records, contracts, client data and credentials. Privacy and confidentiality commitments do not stop applying because the disclosure happens at a checkpoint rather than over a network.

Data minimisation has a physical dimension. Most teams treat minimisation as a database question. The same principle applies to what sits on a device and what can be pulled from it, and it is far cheaper before a trip than after.

Do not design controls around an unsettled rule. With circuit courts reaching different answers and the Supreme Court silent, any policy that depends on a specific level of legal protection at the border is built on sand.

It cuts into investigations and monitoring. The same reasoning will be cited in debates about device searches at work, so read this alongside your own monitoring and employee privacy positions.

What to watch

Watch whether the Supreme Court takes up the circuit split, since a national answer would settle a question that currently varies by airport. Watch too whether CBP's internal directives are ever given enforceable force, and whether the open question on forensic searches returns to a later case.

The practical takeaway is unglamorous: travel with light devices, keep sensitive records in systems that need a login rather than on a local disk, and give staff who handle regulated data a simple rule for what does not travel.

Attribution: Analysis based on JD Supra Privacy and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News