Phone SeizedCompare jurisdictionsWhat can they actually get?
What can they actually get?
What can they actually get?
England & Wales
They canIn England and Wales, the ICO’s own 2020 review found that police data extraction practices often pull excessive amounts of personal data, without a clear basis in data protection law.
ICO, Mobile phone data extraction by police forces in England and Wales (June 2020)
“police data extraction practices vary across the country, with excessive amounts of personal data often being extracted, stored, and made available to others, without an appropriate basis in existing data protection law.”
Read it at ico.org.ukquote checked 2026-09-08
Scotland
A limit appliesIn Scotland, Police Scotland says it will only examine a digital device where there is a legal basis and doing so is necessary, justified and proportionate to the investigation.
Police Scotland, "Cyber kiosks" — legal basis
“We will only examine a digital device where there is a legal basis and where it is necessary, justified and proportionate to the incident or crime under investigation.”
Read it at scotland.police.ukquote checked 2026-09-08
Australia
They canIn Australia, once a document is examined under the Customs Act, an officer may make a copy of it or take an extract.
Customs Act 1901 (Cth), s.186A(1) — power to copy documents and data (Compilation No. 192, 5 Sep 2026)
“a document is examined under section 186 or 186AA; and—the officer of Customs may make a copy of, or take an extract from, the document, or arrange for another officer of Customs or other person having the necessary experience, to make such a copy or take such an extract.”
Read it at legislation.gov.auquote checked 2026-09-08
United States
They canIn the United States, research by Upturn found more than 2,000 state and local law enforcement agencies across all 50 states had purchased mobile phone extraction tools.
Upturn, "Mass Extraction", October 2020
“Based on 110 public records requests to state and local law enforcement agencies across the country, our research documents more than 2,000 agencies that have purchased these tools, in all 50 states and the District of Columbia.”
Read it at upturn.orgquote checked 2026-09-08
How far can they actually get in
What the vendor documentation says is reachable in each device state — not what any tool can do.
Off / before first unlock
On an iPhone, the decryption key for Apple’s strongest data-protection class is discarded shortly after the device locks — so a phone in a Before First Unlock state cannot have that class of data read out without the passcode.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .”
Read it at support.apple.comquote checked 2026-09-08
After first unlock
On Android, most app data lives in Credential Encrypted storage, which is only available after the phone has been unlocked at least once since starting up — the After First Unlock state extraction tools rely on.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
Unlocked
Once a phone is unlocked, it can be connected to an accessory or another computer for examination — Apple’s own security guidance ties that connection capability directly to the device being unlocked.
Apple, "About Lockdown Mode" (support.apple.com/en-gb/105120), as fetched 2026-09-08
“Device connections: to connect your iPhone or iPad to an accessory or another computer, the device needs to be unlocked.”
Read it at support.apple.comquote checked 2026-09-08
Cloud & carrier
If Advanced Data Protection is turned on, Apple does not hold the encryption keys for the iCloud data categories it covers, and cannot recover or hand over that data even if access to the account is lost.
Apple, "iCloud data security overview" (support.apple.com/en-gb/102651), as fetched 2026-09-08
“Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account.”
Read it at support.apple.comquote checked 2026-09-08
The short answer, country by country
In England & Wales, the Information Commissioner’s Office’s own 2020 review found that police data extraction practices often pull excessive amounts of personal data, without a clear basis in data protection law.
In Scotland, Police Scotland says it will only examine a digital device where there is a legal basis and doing so is necessary, justified and proportionate to the investigation.
In Australia, once a document is examined under the Customs Act, an officer may make a copy of it or take an extract.
In the United States, research by Upturn found more than 2,000 state and local law enforcement agencies across all 50 states had purchased mobile phone extraction tools.
What actually limits the reach — regardless of country
The law in each country sets who may extract data and on what basis. What that extraction can technically reach is a separate, largely law-independent question, driven by the phone’s own lock state:
- Off / Before First Unlock: Apple’s strongest data-protection class has its decryption key discarded shortly after the device locks, so a phone that has not been unlocked since it started up cannot have that class of data read out without the passcode.
- After First Unlock: on Android, most app data lives in storage that becomes available once the phone has been unlocked at least once since starting up — which is why a phone in this state is more exposed than one that has never been unlocked.
- Unlocked: once a phone is unlocked, it can be connected to an accessory or another computer for examination.
- Cloud: if Advanced Data Protection is turned on, Apple does not hold the encryption keys for the iCloud categories it covers, so a copy of the phone’s data sitting in iCloud can be out of reach even with a warrant.
That reach ladder is the same in all four countries — the law changes who can pull the trigger and on what authority, not what the trigger can technically reach.
Read further
Last reviewed 2026-09-08. Next review due 2026-12-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.