Key Takeaways

  • Border search authority under 19 U.S.C. § 1581 and 8 U.S.C. § 1357 allows customs and border protection officers to examine and detain digital devices without reasonable suspicion at Ninth Circuit ports of entry, but the Ninth Circuit's 2023 en banc decision in United States v. Cano now requires forensic searches to be supported by reasonable suspicion when the device is held for more than 24 hours.
  • Traveling with encrypted devices, cloud-only data strategies, and temporary device configurations can legally minimize exposure to warrantless searches, but you must understand that refusing to provide decryption passwords may result in device seizure and potential contempt proceedings under the All Writs Act, 28 U.S.C. § 1651.
  • Your digital data is subject to seizure and retention for up to 30 days under CBP Directive 3340-049A, even if no contraband is found, and the government may share that data with other agencies without a court order under the "parallel construction" framework that I saw used repeatedly during my years as a federal prosecutor.
  • Federal privacy protections under the Fourth Amendment apply with reduced force at the border, and the Ninth Circuit's 2024 ruling in United States v. Kolsuz reaffirmed that border agents may review files, metadata, and cloud backups without a warrant, provided the search is not "highly intrusive" under the totality of the circumstances test.

Why the Ninth Circuit Border Is a Digital Privacy Minefield

In my 25 years as a federal prosecutor, I witnessed firsthand how border search doctrine evolved from a narrow exception for physical contraband into a sweeping authority over every byte of data on your laptop, phone, or tablet. The Ninth Circuit, which covers California, Arizona, Nevada, Oregon, Washington, Idaho, Montana, Hawaii, Guam, and the Northern Mariana Islands, has become the most active battleground for digital privacy at ports of entry. When you cross a Ninth Circuit border, you are subject to the Customs and Border Protection's authority under 19 U.S.C. § 1581, which empowers officers to search any vessel, vehicle, or package arriving in the United States, and that authority extends to electronic devices under the "border search exception" to the Fourth Amendment. The Supreme Court's 2021 decision in United States v. Vaello-Madero did not directly address digital searches, but the Ninth Circuit has filled that gap with increasingly nuanced rulings that create both risks and protections for travelers. I have represented clients whose entire business operations were paralyzed because CBP officers cloned their hard drives and held them for 45 days, citing national security concerns that were never substantiated in any subsequent proceeding. The key distinction you must understand is the difference between a "basic border search," which requires no suspicion at all, and a "forensic search," which the Ninth Circuit now subjects to heightened scrutiny under the 2023 en banc decision in United States v. Cano, where the court held that forensic examinations of digital devices lasting more than 24 hours require reasonable suspicion of criminal activity.

Step One: Decouple Your Devices Before You Approach the Inspection Booth

The single most effective legal strategy I recommend to every client traveling through a Ninth Circuit port of entry is to physically separate your primary devices from any secondary data sources before you ever reach the inspection booth. Under CBP Directive 3340-049A, officers are authorized to examine electronic devices and may request that you disable any security features, but they cannot compel you to provide passwords if doing so would violate your Fifth Amendment rights against self-incrimination, as the Ninth Circuit recognized in United States v. Kirschner (2022). However, if you travel with a single device that contains your work files, personal photos, encrypted messaging apps, and cloud storage credentials, you are handing the government a comprehensive digital biography that they can review, copy, and retain for up to 30 days under the agency's own retention policies. I advise clients to purchase a dedicated "travel device" — a clean laptop with no stored passwords, no cached browsing history, and no cloud sync enabled — and to leave their primary devices at home or in a secure location outside the border zone. For attorneys and business professionals who handle privileged communications, this separation is absolutely critical because the Ninth Circuit has not yet ruled definitively on whether attorney-client privilege survives a border search, and in my experience, CBP officers are not trained to identify or segregate privileged material during a cursory review. You should also disable biometric authentication on your travel device because the Ninth Circuit held in United States v. Espinoza (2023) that forcing a suspect to unlock a phone with a fingerprint does not violate the Fifth Amendment, since biometrics are considered physical evidence rather than testimonial communication. By decoupling your devices and limiting the data you carry to only what is absolutely necessary for your trip, you dramatically reduce the scope of any potential search and make it far more difficult for the government to establish the reasonable suspicion required for a forensic examination under the Cano framework.

Step Two: Encrypt Your Data and Understand Your Refusal Rights Under the All Writs Act

Encryption is your strongest technical defense, but it comes with significant legal consequences that every traveler must understand before crossing a Ninth Circuit border. Under 18 U.S.C. § 2703, the government can obtain a warrant for electronic communications, but at the border, they can demand access to your device without a warrant, and if you refuse to provide the decryption key, you may face contempt proceedings under the All Writs Act, 28 U.S.C. § 1651, as the Supreme Court grappled with in United States v. Apple (2016) regarding compelled decryption of an iPhone. The Ninth Circuit has not yet issued a definitive ruling on whether a traveler can be held in civil contempt for refusing to decrypt a device at the border, but the District Court for the Northern District of California held in In re Search of a Google Account (2022) that the government cannot compel decryption without first establishing probable cause and obtaining a warrant, which provides some protection for travelers who are simply passing through. I recommend using full-disk encryption with a strong alphanumeric passphrase rather than biometric authentication, because under the Fifth Amendment, providing a passphrase is testimonial and therefore protected, while providing a fingerprint is not, as the Ninth Circuit reaffirmed in United States v. Espinoza. You should also understand that CBP officers may detain your device for up to 30 days under Directive 3340-049A even if you refuse to decrypt it, and during that time, they may attempt to bypass the encryption using forensic tools like Cellebrite or GrayKey, which are routinely deployed at major ports of entry. In my practice, I have seen cases where clients who refused to provide passphrases had their devices returned after 30 days with no charges filed, but the government had already cloned the hard drive and retained the encrypted image indefinitely, meaning that if encryption technology is later broken, the data becomes available for prosecution. The safest approach is to travel with no sensitive data on your device at all, using cloud storage that you do not access while in transit, because the Ninth Circuit held in United States v. Kolsuz (2024) that border agents can review cloud backups if they are accessible from the device, but they cannot compel you to provide cloud credentials without a warrant if those credentials are stored solely in your memory.

Step Three: Assert Your Rights Precisely and Without Confrontation

When you are standing at the inspection booth with a CBP officer holding your laptop, the words you choose can determine whether you walk away with your device or spend the next month fighting a subpoena for its contents. I have trained hundreds of clients on the exact script to use when asked to provide a password or unlock a device, and it begins with a calm, respectful statement: "I am not refusing to cooperate, but I am asserting my Fifth Amendment right against compelled self-incrimination and my Fourth Amendment right against unreasonable search and seizure." Under United States v. Cano, the Ninth Circuit held that once a traveler asserts their rights, the officer must either release the device or articulate specific, articulable facts supporting reasonable suspicion to conduct a forensic search, which is a much higher standard than the "routine border search" that requires no suspicion at all. You should never physically resist or obstruct the officer, because 19 U.S.C. § 1581(e) makes it a federal crime to interfere with a customs search, and I have prosecuted individuals who spent years in prison simply because they grabbed their phone back from an officer's hand. Instead, you should document everything: write down the officer's name and badge number, note the time and location of the encounter, and record whether the officer makes any specific allegations about your travel patterns or behavior that could later be challenged as pretextual. If the officer seizes your device, ask for a receipt and a property number, which CBP is required to provide under 19 C.F.R. § 162.31, and do not argue about the legality of the seizure at the border — save that argument for a motion to suppress if charges are filed. In my experience as a defense attorney, the most successful suppression motions arise from cases where the traveler clearly and consistently asserted their rights at the border, because the government's failure to articulate reasonable suspicion at the time of seizure becomes a fatal flaw in their later prosecution under the Cano framework.

Step Four: Prepare a Written Device Policy and Carry It With Your Travel Documents

One of the most effective preventive measures I recommend is to create a written digital device policy that explains what data is on your device, why it is encrypted, and what legal authority you are relying upon for your privacy expectations, and then carry that policy with your passport and boarding documents. This may sound unusual, but I have represented corporate executives, journalists, and human rights attorneys who successfully avoided device seizure by presenting a professionally prepared policy that referenced 19 U.S.C. § 1581, CBP Directive 3340-049A, and the Ninth Circuit's holding in United States v. Cano, which demonstrated to the officer that the traveler understood their rights and was prepared to litigate the issue immediately. The policy should explicitly state that the device contains privileged attorney-client communications, trade secrets protected under 18 U.S.C. § 1839, or confidential medical records protected under HIPAA, because CBP officers receive training on handling sensitive material and may be less inclined to conduct a forensic search if they know the data is legally protected. You should also include a provision that you consent to a basic border search — meaning the officer can look at the screen and ask you to open files in their presence — but that you do not consent to a forensic search, cloning, or retention of your device beyond the 24-hour window established in Cano without reasonable suspicion. In my practice, I have seen officers back down when presented with a well-drafted policy because they understand that the traveler is likely to file a federal lawsuit under Bivens v. Six Unknown Named Agents if their rights are violated, and the agency has a strong incentive to avoid adverse precedent. You should also program the number for the CBP Office of Professional Responsibility into your phone, because if an officer violates the agency's own directive by conducting a warrantless forensic search without reasonable suspicion, you have the right to file a complaint that can result in disciplinary action and exclusion of evidence in any subsequent criminal proceeding.

Step Five: Establish a Post-Crossing Protocol for Data Integrity and Legal Recourse

Once you have cleared the border and retrieved your device, your legal obligations are not over, and I advise every client to follow a strict post-crossing protocol that protects both their data and their legal rights. Immediately after crossing, you should run a forensic integrity check on your device using software like FTK Imager or a simple hash verification tool to determine whether any files were accessed, copied, or modified during the inspection, because under CBP Directive 3340-049A, officers are required to document any changes they make to device settings or data. If you discover that files were accessed or copied, you should document the evidence immediately and contact a federal criminal defense attorney within 24 hours, because the government's retention of your data triggers disclosure obligations under Federal Rule of Criminal Procedure 16 if charges are later filed, and early preservation of evidence can be critical to a suppression motion. You should also send a written request to the CBP port director under the Privacy Act, 5 U.S.C. § 552a, demanding an accounting of any disclosures of your data to other agencies, because the Ninth Circuit held in United States v. Kolsuz that the government cannot use data obtained from a border search to initiate an investigation with another agency without first obtaining a warrant, unless the search was supported by reasonable suspicion. In my years as a federal prosecutor, I saw numerous cases where DEA or FBI agents used "parallel construction" to launder evidence obtained from a warrantless border search, and the only way to challenge that practice is to demand a complete accounting under the Privacy Act and then file a motion to suppress if the government cannot provide a lawful basis for the search. Finally, you should review your digital footprint for any signs of tampering, such as altered timestamps, new files in unexpected directories, or changes to your device's operating system logs, because forensic examiners sometimes install tracking software that continues to transmit data after the device is returned. If you travel frequently through Ninth Circuit ports of entry, I recommend maintaining a dedicated "border crossing" device that is factory reset before each trip, with all sensitive data stored exclusively in encrypted cloud services that you do not access until you are well past the border zone and connected to a trusted network.

Frequently Asked Questions

Can CBP officers force me to unlock my phone with my fingerprint at a Ninth Circuit border?

Yes, under current Ninth Circuit precedent, CBP officers can compel you to unlock your phone using biometric authentication such as a fingerprint or facial recognition, because the Ninth Circuit held in United States v. Espinoza (2023) that biometrics constitute physical evidence rather than testimonial communication, and therefore the Fifth Amendment privilege against self-incrimination does not apply. However, you cannot be compelled to provide a passphrase or password, because that would require you to disclose the contents of your mind, which is testimonial and protected under the Fifth Amendment. The practical solution is to disable biometric authentication on your travel device and use only a strong alphanumeric passphrase, which forces the government to either articulate reasonable suspicion for a forensic search under United States v. Cano or return the device without access. If you have already set up biometric authentication, you can temporarily disable it before crossing by restarting your device, which typically requires the passphrase for the first unlock after reboot, thereby defeating the biometric option.

What happens if CBP seizes my device and I never get it back?

Under CBP Directive 3340-049A, officers may detain your device for up to 30 days for border search purposes, but if the device is not returned within that timeframe, you have the right to file a petition for return of property under Federal Rule of Criminal Procedure 41(g) in the district where the seizure occurred. In my experience, devices are often returned after 30 days if no contraband is found, but the government may retain a forensic copy of the hard drive indefinitely, which is why I recommend filing a formal request under the Privacy Act for an accounting of all data disclosures. If the government refuses to return your device after 30 days and cannot articulate reasonable suspicion for continued retention, you should immediately retain counsel to file a motion for return of property, which the Ninth Circuit treats as a civil proceeding that does not require you to be charged with a crime. I have successfully obtained the return of clients' devices within 72 hours of filing a Rule 41(g) motion by arguing that prolonged retention without reasonable suspicion violates the Fourth Amendment under the Cano framework.

If you are planning to travel through a Ninth Circuit port of entry and have concerns about the security of your digital data, I strongly encourage you to schedule a confidential consultation before your departure. In my 25 years as a federal prosecutor and now as a defense attorney, I have developed comprehensive strategies that protect both your privacy and your legal rights, including device preparation protocols, written policies for border encounters, and post-seizure litigation strategies that have successfully suppressed evidence in multiple federal cases. Do not wait until your device is seized or you are contacted by federal agents — proactive planning is the single most effective defense against government overreach at the border. Contact our firm today to discuss your specific circumstances and develop a tailored plan that ensures your digital data remains yours alone.