Your Employee’s Phone Is Fair Game at the U.S. Border—Is Your Company Ready for Device Searches?

Device Searches

A Canadian employee arrives at the airport for what should be a routine business trip to the United States. The employee has the right passport. The meetings are scheduled. The return flight is booked.

Then the U.S. Customs and Border Protection officer asks a question the company never anticipated: “Can you unlock your phone?”

That phone may contain emails with U.S. customers, messages about upcoming projects, internal organizational charts, employment documents, financial projections, confidential contracts and discussions about what the employee plans to do while in the United States.

Suddenly, the border inspection is no longer only about the employee’s passport or stated purpose of travel. It is also about the company’s data and whether the contents of the employee’s phone or laptop support the explanation being given to the officer.

For Canadian employers that regularly send employees across the border, device searches should be treated as both an immigration issue and a business-risk issue.

Can CBP Search an Employee’s Phone or Laptop?

Yes.

U.S. Customs and Border Protection has broad authority to inspect travelers and their belongings at U.S. ports of entry. That authority can extend to electronic devices such as:

  • Mobile phones
  • Laptops
  • Tablets
  • Cameras
  • External hard drives
  • USB drives
  • SIM cards
  • Other devices capable of storing digital information

This authority may be exercised at airports, land-border crossings, seaports and U.S. preclearance locations in Canada.

CBP’s current policy is set out in its Border Search of Electronic Devices Directive, which became effective on January 1, 2026. The directive establishes procedures for searching, reviewing, retaining and sharing information found on electronic devices.

Device searches are uncommon compared with the total number of travelers entering the United States. But “uncommon” does not mean irrelevant especially when one inspection can expose sensitive business information or undermine an employee’s request for admission. CBP reported more than 55,000 electronic-device searches during fiscal year 2025, although those searches still represented less than 0.01 percent of arriving travelers.

The operational question for employers is not whether every employee’s phone will be searched. It is whether the company is prepared if device searches occur.

CBP Conducts Two Types of Device Searches

CBP policy distinguishes between basic and advanced device searches.1

Basic Device Searches

During a basic search, an officer may manually review information available through the device’s operating system or applications. The officer might scroll through emails, messages, photographs, files, contacts or other locally stored information.

Under CBP’s January 2026 directive, an officer may conduct a basic search with or without suspicion.

That means an employee should not assume that CBP must first establish probable cause, obtain a warrant or identify evidence of wrongdoing before examining a device.

Basic devices searches can become especially important during an immigration inspection because the device may contain information relevant to the employee’s eligibility to enter the United States. For example, an officer assessing whether a Canadian employee is entering as a legitimate business visitor may find:

  • Messages describing the trip as “working in the U.S.”
  • A calendar filled with operational assignments
  • Instructions to supervise U.S. employees
  • Emails assigning deliverables to be completed while in the United States
  • A proposal identifying the traveler as the person responsible for implementation
  • Messages suggesting the employee intends to remain in the United States indefinitely
  • Information inconsistent with the employee’s answers during inspection

Even casual language can create questions when viewed without the context understood by the employer and employee.

Advanced Device Searches

An advanced search generally involves connecting external equipment to the device to copy, extract or analyze its contents. CBP policy permits an advanced search when there is reasonable suspicion of activity violating a law enforced or administered by CBP or when there is a national-security concern. Senior management approval is also required.

Advanced device searches can expose substantially more information than a quick manual review. They can also result in longer delays and, in some situations, detention of the device for further examination.

Can CBP Search Information Stored in the Cloud?

CBP’s directive limits border device searches to information resident on the device and accessible through its operating system, software, tools or applications.

Officers are not supposed to intentionally use the device to retrieve information stored solely in a remote location. To avoid accessing remote information, the officer may request that connectivity be disabled or take steps to prevent the device from communicating with a network.

However, the distinction between local and cloud-based data is not always obvious.

A cloud-based email, file or message may already be cached or downloaded to the device. An application may remain logged in. A document that appears to be stored remotely may also have an offline copy.

Employers should therefore avoid assuming that moving files to the cloud eliminates the risk of device searches. A stronger approach is to determine what information the employee genuinely needs to carry or access during the trip.

What Happens If an Employee Refuses to Unlock a Device?

CBP may request a passcode or other assistance necessary to examine a device.

According to CBP, travelers are expected to present devices in a condition that permits inspection. When a device cannot be inspected because of a passcode, encryption or another security mechanism, it may be detained for further examination.

The immigration consequences of refusing to cooperate can vary based on the traveler’s status.

A U.S. citizen cannot simply be denied entry to the United States. However, the person may experience delays, additional questioning or detention of the device.

A Canadian citizen applying for admission as a visitor, business visitor or temporary worker is in a different position. Admission is not automatic. The traveler must satisfy the officer that they are eligible to enter in the requested classification.

Refusing to unlock a device does not automatically establish inadmissibility. But it can complicate the inspection, lengthen the delay and affect the officer’s ability to verify the employee’s explanation.

That creates a difficult real-time decision for an employee who may be carrying both personal information and confidential company data. The border inspection line is not the place for the employee to encounter that dilemma for the first time.

Confidential Business Information Is Not Automatically Invisible

Company-owned devices may contain:

  • Customer lists
  • Pricing information
  • Product-development plans
  • Acquisition discussions
  • Financial projections
  • Employee records
  • Intellectual property
  • Internal investigations
  • Contracts and proposals
  • Communications with legal counsel

CBP policy includes procedures for handling business-confidential information and other sensitive material. That does not mean the information cannot be encountered during an inspection. It means special handling rules may apply after the material is identified.

Employees should be trained to clearly identify sensitive information when appropriate. For example, an employee carrying attorney-client communications should not silently assume that the privileged nature of the material will be obvious to the inspecting officer.

More importantly, employers should reduce unnecessary exposure before travel rather than relying entirely on confidentiality protections after device searches begins.

Device Searches Can Reveal an Immigration Problem the Employer Never Identified

The biggest risk may not be the search itself. It may be what the search reveals about the employee’s planned U.S. activities.

Canadian companies sometimes treat short trips as automatically permissible because the employee will remain on Canadian payroll, spend only a few days in the United States or attend meetings at a U.S. affiliate.

Those facts may be relevant, but none of them independently determines whether the employee is authorized to perform the planned activities. Business visitors may generally participate in limited activities such as meetings, consultations, negotiations, conferences and certain other temporary business functions. They generally cannot enter the United States to fill a U.S. position or perform hands-on productive work that requires employment authorization.

The problem often appears in the gap between the official travel description and the operational reality.

The travel request may say:

Meetings with the U.S. team.

The employee’s messages may say:

Flying down to finish the installation and train the new hires.

The itinerary may say:

Customer visit.

The employee’s calendar may include:

On-site implementation, troubleshooting and project delivery.

The border officer is not required to accept the label placed on the trip by the employer. The officer can assess the underlying activities and surrounding evidence.

When the information found during device searches conflicts with the employee’s answers, the result may include extended questioning, withdrawal of the application for admission, refusal of entry or scrutiny during future travel.

Personal Phones Can Create Company Risk Too

A company may issue carefully managed laptops while allowing employees to use personal phones for business communications. That arrangement can create a significant blind spot. The employee’s personal phone may contain:

  • Workplace messaging applications
  • Screenshots of internal documents
  • Emails forwarded from a company account
  • Informal instructions from a manager
  • Client communications
  • Discussions about future U.S. hiring or relocation
  • Messages using inaccurate shorthand to describe the trip

Personal ownership does not exempt a phone from device searches. Employers should therefore consider both corporate and personal devices when developing a cross-border travel policy.

This does not require an employer to inspect an employee’s private communications. It does require clear rules regarding how company information is accessed, stored and discussed on devices used during international travel.

How Canadian Employers Should Prepare for Device Searches

Preparing for possible device searches requires coordination between immigration, HR, operations, privacy and cybersecurity personnel.

1. Confirm the Actual Purpose of the Trip

Do not stop at labels such as “business meeting,” “training” or “customer visit.” Identify:

  • What the employee will do each day
  • Who will direct the activities
  • Whether the employee will produce deliverables
  • Whether the employee will perform services for a U.S. customer
  • Whether the employee will supervise or manage U.S. operations
  • Whether the activities require work authorization
  • Whether the employee’s messages, calendar and documents accurately reflect the trip

The immigration analysis should be completed before the flight is booked—not while the employee is being questioned.

2. Apply a Data-Minimization Rule

Employees should travel with only the devices and information reasonably required for the trip. Depending on the company’s operations, this may involve:

  • Issuing a clean travel device
  • Removing unnecessary local files
  • Limiting offline access to sensitive folders
  • Logging out of applications that are not required
  • Disabling automatic downloads
  • Removing stored credentials that are unnecessary for travel
  • Restricting the transfer of highly confidential information
  • Backing up essential data before departure

The objective is lawful risk reduction—not concealment, deletion of evidence or interference with a government inspection.

3. Align the Employee’s Documents and Digital Record

The employee’s support letter, itinerary, calendar entries, emails and verbal explanation should describe the same legitimate activities. An employer letter stating that an employee will attend strategic meetings will have limited value if the employee’s calendar describes five days of operational work.

Consistency matters because officers evaluate the full circumstances of the trip.

4. Create a Device-Search Response Protocol

Employees should know whom to contact if a device is searched, detained or copied. The protocol should identify:

  • The company’s internal contact
  • Immigration counsel
  • Privacy or cybersecurity personnel
  • The process for reporting exposure of confidential information
  • The steps for changing potentially compromised credentials
  • The process for documenting what occurred
  • Whether the employee should request a receipt for a detained device

Employees should remain calm, truthful and respectful during inspection. They should not guess, delete information during questioning or misrepresent the contents of a device.

5. Address Privileged and Highly Sensitive Material

Employees carrying attorney-client communications, trade secrets, regulated information or sensitive personal data may require additional preparation.

Where appropriate, the employer should determine whether the information can be left behind, accessed through a controlled system or handled through a dedicated travel device.

The employee should also understand how to identify potentially privileged or protected material without making inaccurate claims about ordinary business communications.

6. Build Border Planning Into the Company’s Mobility Process

For companies sending employees to the United States regularly, every trip should not trigger a new emergency analysis. A scalable system should include:

  • Defined categories of permitted business travel
  • Escalation rules for higher-risk activities
  • Standardized support-document templates
  • Pre-travel employee briefings
  • Device and data-security procedures
  • Records of prior admissions and status expiration dates
  • A process for identifying when work authorization is required

This turns border compliance from an individual traveler problem into a manageable business process.

The Real Risk Is Entering the Border Unprepared

Most employees will cross the U.S. border without experiencing device searches of their phones or laptops. But employers cannot build a compliance system around the assumption that no officer will look deeper.

A device may tell the story of the trip more clearly than the support letter does.

When that story involves unauthorized work, inconsistent explanations or confidential information that should never have travelled, the consequences can extend beyond one delayed employee.

They can affect a project, a customer relationship, the employee’s future travel and the company’s broader U.S. expansion plans.

Build a Cross-Border Travel System Before the Next Employee Flies

Canadian companies with growing U.S. operations need more than one-off answers each time an employee travels. They need a repeatable framework for determining:

  • Who may travel as a business visitor
  • Who requires work authorization
  • What supporting documentation should be carried
  • How phones, laptops and confidential data should be handled
  • When a trip should be escalated for legal review

Salvador Global works with Canadian companies managing recurring U.S. business travel, employee transfers and cross-border workforce growth. Salvador Global works with Canadian companies managing recurring U.S. business travel, employee transfers and cross-border workforce growth.

Contact Salvador Global to discuss a cross-border travel and workforce strategy designed around the company’s actual U.S. operations.


Disclaimer: The information provided in this blog post is for general informational purposes only and does not constitute legal advice. While efforts are made to ensure the content is accurate and up to date at the time of publication, laws and regulations may change, and the information may no longer be current. You should consult a qualified legal professional for advice specific to your situation.

  1. Border Search FAQs: What type of border searches does CBP conduct https://www.cbp.gov/travel/cbp-search-authority/border-search-electronic-devices?utm_source=chatgpt.com ↩︎