What to Do With Your Phone Before You Cross a Border
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Travelling changes your risk profile in specific, predictable ways: you carry everything you own digitally into places with different laws, use networks you do not control, and are more likely to have hardware lost or stolen.
Most of this is handled by preparation before you leave rather than caution while away.
Before you go
Update everything and back up. Both for the obvious reason and because a device lost abroad is much less painful when a current backup exists at home.
Turn on full-disk encryption if it is not already. Phones do this by default; laptops often do not. Without it, a stolen laptop is an open filing cabinet.
Check what is actually on the device. Old tax documents, client files, saved passwords in a browser. Travel is a good prompt to remove what does not need to travel with you.
Know your recovery path. If your phone is stolen on day one, can you still reach your accounts? Two-factor codes on a stolen phone, with no backup codes, leave you locked out of everything at the worst possible moment. Print backup codes and carry them separately from the device.
Border inspections
Many countries assert the right to inspect electronic devices at the border, and the rules differ sharply — including on whether you can be compelled to provide a password, and what happens if you decline.
The honest position is that this is jurisdiction-specific and consequential. Refusing can mean denial of entry for a visitor, device seizure, or in some places arrest. If you are travelling somewhere this genuinely concerns you, look up that country's current rules rather than relying on general advice, and understand that your rights differ substantially depending on your citizenship.
Two things are broadly true and worth knowing:
- Biometrics and passcodes are treated differently in some legal systems. In several jurisdictions compelling a fingerprint or face has been treated differently from compelling a memorised passcode. Powering a device fully off before a border generally means a passcode is required on next unlock rather than biometrics.
- A travel device is the robust answer. If your work involves confidential material and you cross borders where inspection is likely, a clean device carrying only what the trip needs solves the problem without any legal argument. Employers with genuine exposure often mandate exactly this.
For most leisure travellers this is not a realistic concern and the preparation above is sufficient.
While you are there
Hotel and café Wi-Fi is fine for ordinary browsing. Nearly everything uses HTTPS, so the old advice about open networks is largely obsolete. A VPN adds a worthwhile layer where the network operator is unknown, and it helps with services that behave oddly abroad.
Be wary of the network name. The realistic Wi-Fi attack is a fake hotspot named plausibly for the venue. Ask staff for the actual network name rather than picking whichever one looks right.
Avoid public USB charging points, or use a charge-only cable or a power bank. The risk is low and the mitigation costs nothing.
Turn off automatic connection to open networks, so your phone stops silently joining anything with a familiar name.
If a device is lost or stolen
Act in this order:
- Remotely lock and locate it through your platform's find-my-device service. Do not erase immediately if there is a realistic chance of recovery — locate first, erase if it is clearly gone.
- Change your email password from another device, then anything financial.
- Contact your mobile provider to suspend the SIM, which prevents both call charges and a SIM-swap follow-up.
- Report it locally. A police report is usually required for insurance and useful if the device resurfaces.
- Then erase it remotely once recovery looks unlikely.
Coming home
Change passwords you typed on networks you did not control if anything felt off, check your accounts for unfamiliar sessions, and revoke access for any device you no longer have.
If you set up a temporary travel device, wipe it before storing it rather than leaving a configured device with saved sessions sitting in a drawer.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.