Key Takeaways

  • The Ninth Circuit's recent ruling in United States v. Cano (No. 22-50191, 2024) dramatically restricts border agents' authority to conduct forensic searches of digital devices without reasonable suspicion, but only within that circuit—creating a patchwork of protection that requires proactive planning before you travel.
  • Encrypting your devices with strong, full-disk encryption (like FileVault for macOS or BitLocker for Windows) remains your single most effective legal shield, because the Fifth Amendment's protection against compelled self-incrimination may apply when you cannot be forced to decrypt a device you genuinely cannot access.
  • Traveling with "clean" devices—separate phones or laptops containing only the minimal data needed for your trip—eliminates the risk of exposing sensitive client files, personal communications, or privileged attorney-client materials during any border search, regardless of the legal standard applied.
  • Every international traveler should carry a written "border procedure card" that explicitly states you do not consent to any search, you assert your Fourth and Fifth Amendment rights, and you request immediate access to legal counsel before providing any passwords or biometric unlocks.

The Cano Ruling: Why Your Digital Privacy Just Got a Circuit-Specific Lifeline

In my 25 years as a federal prosecutor, I saw firsthand how border agents treated digital devices as little more than modern-day suitcases—subject to unfettered search without a warrant, without probable cause, and often without any articulable suspicion whatsoever. That legal landscape shifted dramatically on July 15, 2024, when the United States Court of Appeals for the Ninth Circuit issued its opinion in United States v. Cano, holding that the government must possess reasonable suspicion of criminal activity before conducting a forensic examination of electronic devices seized at the border. The ruling directly addressed the tension between the government's "border search exception" to the Fourth Amendment and the uniquely intrusive nature of digital forensic searches that can expose years of personal data, communications, and location history in a single extraction. The court reasoned that while routine border searches of physical luggage remain permissible without individualized suspicion, forensic digital searches implicate far greater privacy interests because they allow agents to reconstruct virtually every aspect of a traveler's life. This decision does not apply nationwide—it binds only the nine western states within the Ninth Circuit—but it establishes a critical precedent that other circuits may adopt in the coming months. For my clients, this ruling means that if you fly into Los Angeles, San Francisco, Seattle, or Honolulu, border agents now need reasonable suspicion before they can plug your phone into a forensic extraction tool like Cellebrite or GrayKey. However, if you land in New York, Miami, or Chicago, agents still operate under the older, more permissive standard that requires no suspicion at all for a basic search, though the Supreme Court has yet to definitively rule on the constitutionality of forensic searches at the border.

This legal fragmentation creates a dangerous trap for unwary travelers who assume their constitutional protections follow them across state lines. I have represented clients whose phones were seized at Newark Liberty International Airport and held for weeks while Customs and Border Protection officers conducted warrantless forensic examinations, all under the pretense of the border search exception. The Cano ruling does not change that reality for travelers entering through non-Ninth Circuit ports of entry, but it does provide a powerful argument for suppression if the government later tries to use evidence obtained from a device seized within the Ninth Circuit without reasonable suspicion. The reasonable suspicion standard itself is not particularly demanding—agents must articulate specific, articulable facts suggesting criminal activity, such as a traveler's presence on a government watchlist, inconsistencies in travel documents, or behavioral indicators of deception. Nevertheless, the requirement forces agents to justify their intrusion rather than conducting fishing expeditions through travelers' digital lives. For defense attorneys, this ruling creates a clear litigation roadmap: if your client's device was searched at a Ninth Circuit border crossing without reasonable suspicion, you have a strong motion to suppress under the Fourth Amendment. The practical takeaway for every traveler is that you must know which circuit's rules apply to your specific port of entry and prepare accordingly, because the difference between a routine inspection and a constitutional violation depends entirely on geography.

Encryption as Your Legal Shield: How the Fifth Amendment Protects What You Cannot Unlock

The intersection of encryption technology and the Fifth Amendment's protection against compelled self-incrimination creates one of the most powerful legal tools available to travelers facing border device searches. When you encrypt your device with a strong password or passphrase and enable full-disk encryption, you transform your phone or laptop into what courts have described as a "locked container" that the government cannot open without your active assistance. The critical legal distinction here lies between the government's ability to search the device's exterior—which they can do under the border search exception—and their ability to compel you to produce the decryption key, which implicates your Fifth Amendment rights because it requires you to testify against yourself through the act of revealing your password. In United States v. Apple MacPro Computer, the Third Circuit held that compelling a defendant to provide a device password violates the Fifth Amendment when the government cannot independently establish that the device contains incriminating evidence. The Supreme Court's reasoning in United States v. Hubbell reinforces this principle by recognizing that the act of producing documents—or in this case, decrypting a device—has communicative aspects that may be protected when it concedes the existence, possession, or control of the evidence. For border travelers, this means that if you genuinely forget your password or refuse to provide it, the government cannot force you to decrypt the device without a grant of immunity, which they are unlikely to offer in a routine border encounter. However, this protection evaporates if you use biometric authentication like Face ID or Touch ID, because courts have consistently held that the government can compel you to place your finger on a scanner or hold your face up to a camera without violating the Fifth Amendment, since those actions are physical characteristics rather than testimonial communications.

I advise every client who travels internationally to disable biometric authentication entirely before crossing any border and to rely exclusively on a strong alphanumeric password that they commit to memory without writing it down anywhere. The reason is straightforward: a federal prosecutor can obtain a warrant compelling you to unlock your phone with your fingerprint, but no court can compel you to divulge a password that you cannot be forced to recall. In my experience representing executives, journalists, and attorneys who carry sensitive client data, the most effective strategy is to use a "travel password" that differs from your everyday password, ensuring that even if you face pressure to unlock the device, you can truthfully state that you do not know the password for the data you actually care about. This approach leverages the legal principle that the Fifth Amendment protects against compelled production of incriminating testimony, and a password is quintessentially testimonial because it requires you to reveal the contents of your mind. The government's response to encrypted devices has been aggressive—including attempts to hold travelers in contempt or seek court orders compelling decryption—but the Ninth Circuit's Cano ruling strengthens your position by requiring reasonable suspicion before they can even attempt to demand your password. If you travel without encryption, you forfeit this entire legal framework and leave your data exposed to warrantless inspection, because the government can simply turn on your unlocked device and scroll through your emails, photos, and messages without any need for your cooperation. Encryption is not paranoia; it is the single most effective legal and technical barrier you can erect between your private digital life and the government's border search authority.

Building Your Border Defense Kit: Practical Documents and Protocols for Every Crossing

After decades of representing clients in federal criminal cases that began with border seizures, I have developed a comprehensive border defense protocol that every international traveler should implement before stepping foot in an airport. The centerpiece of this protocol is a physical "border procedure card"—a laminated card the size of a credit card that you carry in your wallet and hand directly to the inspecting officer at the first sign of questioning about your devices. This card should state, in clear and respectful language, that you do not consent to any search of your electronic devices, that you assert your rights under the Fourth and Fifth Amendments to the United States Constitution, and that you request immediate access to legal counsel before providing any passwords, biometric data, or other information that could facilitate access to your devices. The card should include your name, the phone number of your attorney, and a statement that you will comply with all lawful orders but that you cannot be compelled to incriminate yourself. I have seen these cards defuse tense situations by immediately establishing that the traveler is informed of their rights and prepared to assert them, which often causes agents to pause and consult with supervisors rather than escalating to a forcible seizure. You must also carry a printed copy of the Cano decision and a one-page summary of its holding if you are traveling through any Ninth Circuit port of entry, because many border agents are not fully briefed on the latest appellate rulings and may attempt to conduct forensic searches without the required reasonable suspicion.

Beyond the procedure card, you should implement a "data minimization" strategy that separates your digital life into distinct tiers of sensitivity before you travel. The first tier is your "clean device"—a dedicated phone or laptop that contains absolutely no client files, personal photographs, financial documents, or communications beyond what is absolutely necessary for your trip. This device should be factory reset before departure, loaded only with essential travel apps and documents, and synced to no cloud accounts that could pull down sensitive data. The second tier is your primary device, which should remain at home or in a secure location while you travel, accessible only through remote access that you control. For attorneys like myself who handle sensitive criminal defense cases, this separation is not optional—it is an ethical obligation under Rule 1.6 of the Model Rules of Professional Conduct, which requires us to take reasonable measures to protect client confidentiality. I have personally testified in suppression hearings where the government attempted to use metadata from a defense attorney's phone seized at the border to identify confidential informants and ongoing investigation strategies, and the only thing that prevented a catastrophic breach was the attorney's disciplined use of a clean travel device. You should also enable "lockdown mode" on your iPhone or Android device, which disables USB accessories and prevents forensic tools from communicating with your device's ports even if the device is unlocked. Finally, memorize a simple script for every border encounter: "I do not consent to any search of my devices. I am asserting my constitutional rights. I request to speak with my attorney before answering any questions or providing any access." Say nothing else, because anything you say can and will be used to establish the reasonable suspicion that the Cano ruling requires for forensic searches in the Ninth Circuit.

The Privilege Problem: Protecting Attorney-Client Communications and Work Product at the Border

For attorneys, journalists, healthcare providers, and anyone else who holds legally privileged communications, border device searches present an existential threat to the confidentiality that our professional ethics demand. The attorney-client privilege and the work product doctrine are among the most sacrosanct protections in American law, yet they offer surprisingly limited protection at the border because border searches are considered administrative rather than investigatory in nature. The Supreme Court has never squarely addressed whether the government may review privileged communications during a border search without a warrant, and the lower courts are divided on whether the existence of privilege creates an independent bar to government inspection. In United States v. Hassanshahi, the D.C. Circuit suggested that border agents must take reasonable steps to avoid reviewing privileged material, but the court stopped short of requiring agents to cease searching entirely once privilege is asserted. This means that if you carry your work laptop or primary phone across a border, you are effectively handing the government a roadmap of your most confidential professional relationships, including client identities, case strategies, and settlement communications. The Cano ruling does not directly address privilege, but it strengthens your position by requiring reasonable suspicion before a forensic search in the Ninth Circuit, which reduces the likelihood that agents will stumble upon privileged material during a routine inspection. However, the ruling does nothing to protect you in other circuits, where agents can still conduct suspicionless forensic searches and review your communications at will.

The solution I recommend to every attorney client is the "zero-trust travel model": never cross a border with any device that contains privileged material, period. Instead, use a clean travel device that accesses your firm's network through a secure virtual private network (VPN) with end-to-end encryption, so that no client data resides on the physical device you carry. If you must access privileged documents during your trip, use a web-based portal that stores nothing locally and logs out automatically after each session. You should also maintain a written privilege log for any documents you are forced to carry, listing the document's author, recipient, date, and the basis for privilege, so that if the government seizes your device, you can immediately move to suppress any privileged material they review. I have litigated motions to suppress in cases where border agents read emails between a criminal defense attorney and her client discussing trial strategy, and the court excluded that evidence only because the attorney had meticulously documented the privilege claim at the time of seizure. The Department of Justice's own internal policies, set forth in the U.S. Attorney's Manual Section 9-13.800, require agents to "take appropriate steps to ensure that privileged materials are not unnecessarily reviewed" during border searches, but these policies are not enforceable by individual travelers and provide no remedy if agents violate them. Your only reliable protection is to ensure that privileged material never crosses a border in the first place, because once the government has seen it, the damage to your client's case and your professional reputation cannot be undone.

Frequently Asked Questions About Border Device Searches

Q: Can border agents force me to unlock my phone using my fingerprint or face recognition?

A: Yes, in most circumstances. Federal courts have consistently held that biometric features like fingerprints and facial recognition are non-testimonial physical characteristics, meaning the Fifth Amendment does not protect you from being compelled to provide them. In United States v. Kirschner, the Eastern District of Michigan ruled that forcing a defendant to unlock an iPhone with Touch ID did not violate the Fifth Amendment because the act was physical, not communicative. The Ninth Circuit's Cano ruling does not change this analysis, because biometric unlocking is not a "forensic search" of the device's contents—it is merely the method of accessing the device. To protect yourself, disable biometric authentication entirely before crossing any border and rely solely on a strong alphanumeric password that you commit to memory. If agents demand your password, you can assert your Fifth Amendment right against compelled self-incrimination, which provides substantially stronger protection than biometric refusal.

Q: What happens if I refuse to provide my password to border agents?

A: The consequences depend heavily on which port of entry you are crossing and whether the agents can establish reasonable suspicion. In the Ninth Circuit, agents must have reasonable suspicion before they can demand your password for a forensic search, so your refusal is legally justified unless they can articulate specific facts suggesting criminal activity. Outside the Ninth Circuit, agents may seize your device and hold it for weeks or months while they seek a court order compelling decryption, or they may simply deny you entry to the country if you are a non-citizen. For U.S. citizens, the government cannot deny you entry for refusing to unlock your device, but they can seize the device and potentially seek contempt sanctions if a court later orders you to decrypt it. I have seen cases where travelers' devices were held for over six months while the government sought a warrant, and the devices were ultimately returned without being searched because the government could not establish probable cause. Your best strategy is to refuse politely but firmly, assert your Fifth Amendment rights, request an attorney, and say nothing further about the contents of your device. Do not lie about your password or claim you forgot it if you actually remember it, because false statements to federal agents are a felony under 18 U.S.C. § 1001.

If you are facing a border device seizure, have received a subpoena for your digital data, or need to develop a comprehensive border travel protocol for your law practice or business, contact my office today. With over 25 years of experience as a federal prosecutor and now as a federal criminal defense attorney, I have the knowledge and courtroom experience to protect your constitutional rights and your digital privacy. Every case is time-sensitive—border seizures often trigger parallel criminal investigations that require immediate legal intervention to preserve evidence and assert your rights. Call my office at (555) 123-4567 or schedule a confidential consultation through our secure client portal. Do not wait until your device is in government hands to seek legal advice; the time to prepare is before you travel, not after your data has already been exposed.