Skip to content
Phone SeizedThey have your phone?
Menu

Phone Seized

How this site is written

Source-first, never cite-after

Every page here is written in one direction: fetch the primary source — legislation, a court ruling, official guidance, or a device maker’s own published policy — read it, then write the claim constrained to what it actually says. The opposite order — write the claim, then hunt for a citation to hang on it — produces decorative references that look authoritative and support nothing. It is the most common failure mode in AI-written legal content, and the reason so much of it is confidently wrong.

Quotes are machine-checked

A script re-fetches every source this site relies on and confirms the quoted words are still present. It catches two different problems: a quote we transcribed wrongly, and a source amended since we read it. Some official sources are point-in-time, so a page can change while its URL keeps returning a perfectly healthy 200 — silent drift, not an error.

The build fails if any tactical claim lacks a quote, or if any page does not say which jurisdiction it applies to — every claim on every page is attributed this way. You can read every source.

A quote proves the words exist — an LLM judge asks whether they support the claim

Proving a quote is genuinely present at a source is a different question from proving it actually supports the claim it is attached to. That second question is put to an LLM judge, which reads every claim against its quote and records a verdict to a review table. It is report-only: it does not approve or publish anything itself. A claim it flags as unsupported, or only partly supported, gets repaired — the quote extended, or the claim narrowed — or removed, before the page ships. A separate adjudication trail exists to record a human decision on each claim. No human sign-off has been recorded yet: no lawyer has reviewed this site.

What this site does not claim

What we corrected from the original brief

This site was commissioned from a written brief, and parts of that brief turned out to be wrong when checked against the primary sources. Each was corrected before the page in question was written, so none of these errors has appeared on this site — but the owner requires the corrections published rather than absorbed silently, because a reader who arrives with the same assumptions should be able to see exactly where they fail. What follows is what the brief said, and what the primary source actually says.

The RIPA section numbers. The brief cited RIPA “s.43 / s.59” as the power behind a demand for a password. Neither section does that. The power to give a notice requiring disclosure sits in section 49 of the Regulation of Investigatory Powers Act 2000; the offence for knowingly failing to comply with a section 49 notice sits in section 53. Section 59 belongs to a different Act entirely — the Criminal Justice and Police Act 2001 — and lets a person with an interest in seized property apply for its return; it has nothing to do with passwords. See /uk/ripa-notice.

Regulation of Investigatory Powers Act 2000, s.49(1)(a) (legislation.gov.uk, checked 2026-09-08)
Read the quote
This section applies where any protected information— has come into the possession of any person by means of the exercise of a statutory power to seize, detain, inspect, search or otherwise to interfere with documents or other property
Regulation of Investigatory Powers Act 2000, s.53(1) (legislation.gov.uk, checked 2026-09-08)
Read the quote
A person to whom a section 49 notice has been given is guilty of an offence if he knowingly fails, in accordance with the notice, to make the disclosure required by virtue of the giving of the notice.
Criminal Justice and Police Act 2001, s.59(2) (legislation.gov.uk, checked 2026-09-08)
Read the quote
Any person with a relevant interest in the seized property may apply to the appropriate judicial authority, on one or more of the grounds mentioned in subsection (3), for the return of the whole or a part of the seized property.

“You have a right not to hand over your password.” That is what the brief said. Under Schedule 7 to the Terrorism Act 2000, at a UK port or border examination, that is not correct: the information an examining officer can request may include passwords to electronic devices, and a person questioned under Schedule 7 must provide access to any electronic device, including by unlocking it. Wilfully failing to comply with a duty imposed under the Schedule is itself a criminal offence. See /uk/ports-schedule-7.

Schedule 7 (Terrorism Act 2000) Code of Practice (Oct 2025), para 55 (assets.publishing.service.gov.uk, checked 2026-09-08)
Read the quote
Information requested by an examining officer under paragraph 5(a) may include passwords to electronic devices.
Schedule 7 (Terrorism Act 2000) Code of Practice (Oct 2025), para 61 (assets.publishing.service.gov.uk, checked 2026-09-08)
Read the quote
The person must provide access to any electronic device to allow for a search to be undertaken, including where access to a device requires the person to unlock a device through application of their thumb or finger, or any other form of access control
Terrorism Act 2000, Sch.7 para 18(1)(a) (legislation.gov.uk, checked 2026-09-08)
Read the quote
A person commits an offence if he— wilfully fails to comply with a duty imposed under or by virtue of this Schedule

“US police always need a warrant.” The brief cited Riley v. California for that as an absolute rule. Riley’s own opinion does not say that: it says other case-specific exceptions may still justify a warrantless search of a particular phone, where the exigencies of the situation make the needs of law enforcement so compelling that a warrantless search is objectively reasonable. At the US border, CBP policy lets an officer conduct a basic search of a device with or without suspicion. And in the Ninth Circuit, compelling someone to use a biometric to unlock a device has been held not testimonial, so it falls outside Fifth Amendment protection there. See /usa/riley-warrant, /usa/border-cbp, and /usa/passcode-vs-biometrics.

Riley v. California, 573 U.S. 373 (2014) (law.cornell.edu, checked 2026-09-08)
Read the quote
other case-specific exceptions may still justify a warrantless search of a particular phone—the exigencies of the situation—make the needs of law enforcement so compelling that [a] warrantless search is objectively reasonable under the Fourth Amendment—The critical point is that, unlike the search incident to arrest exception, the exigent circumstances exception requires a court to examine whether an emergency justified a warrantless search in each particular case.
CBP Directive No. 3340-049B §5.1.3 (eff. 1 Jan 2026) (cbp.gov, checked 2026-09-08)
Read the quote
An officer may conduct a basic search of an electronic device with or without suspicion, subject to the requirements and limitations provided herein and applicable law.
United States v. Payne, 99 F.4th 1145 (9th Cir. 2024) (cdn.ca9.uscourts.gov, checked 2026-09-08)
Read the quote
the compelled use of a biometric to unlock an electronic device was not testimonial because it required no cognitive exertion, placing it in the same category as a blood draw or a fingerprint taken at booking—merely provided the CHP with access to a source of potential information

“The UK has no deletion rules.” On paper it does, though neither rule sets a fixed number of days. Information extracted from a device and found not relevant to the investigation must be deleted unless there is a separate lawful basis to keep it, and personal data processed for law enforcement purposes generally must be kept for no longer than is necessary for the purpose it was processed for. See /uk/retention-and-deletion.

Extraction of Information from Electronic Devices: Code of Practice (Oct 2022), para 138 (assets.publishing.service.gov.uk, checked 2026-09-08)
Read the quote
Information which is extracted and deemed not relevant must be deleted unless there is a lawful basis to retain it.
Data Protection Act 2018, s.39(1) (legislation.gov.uk, checked 2026-09-08)
Read the quote
The fifth data protection principle is that personal data processed for any of the law enforcement purposes must be kept for no longer than is necessary for the purpose for which it is processed.

“Australian border officers can compel a passcode.” The brief assumed that. The Australian Border Force told a Senate estimates hearing there is no legal compulsion for a traveller to provide a password or passcode, or provide assistance, at the border — though current ABF policy is to retain a device held for examination for no longer than fourteen days, unless it is reasonable that the examination will take longer or the device becomes subject to seizure. A domestic order under section 3LA of the Crimes Act 1914 is a different matter: once a person is subject to such an order and capable of complying with it, omitting to do the required act is itself an offence. See /australia/border-abf and /australia/assistance-orders-3la.

Senate Legal and Constitutional Affairs Legislation Committee, Additional Estimates, ABF answer AE22-050 (14 Feb 2022) — no legal compulsion (aph.gov.au, checked 2026-09-08)
Read the quote
There is no legal compulsion for a traveller to provide a password/passcode or provide assistance to an electronic device at the border.
Senate Legal and Constitutional Affairs Legislation Committee, Additional Estimates, ABF answer AE22-050 (14 Feb 2022) — retention policy (aph.gov.au, checked 2026-09-08)
Read the quote
Current ABF policy is to retain electronic devices held for examination for no longer than 14 days, unless it is reasonable that the examination will take longer or content is located on the device that renders the device subject to seizure.
Crimes Act 1914 (Cth), s.3LA(5) — penalty tier one (Compilation No. 167, 27 Aug 2026) (legislation.gov.au, checked 2026-09-08)
Read the quote
A person commits an offence if:— the person is subject to an order under this section; and— the person is capable of complying with a requirement in the order; and— the person omits to do an act; and— the omission contravenes the requirement.—Penalty: Imprisonment for 5 years or 300 penalty units, or both.

“The law had already changed for online accounts.” The brief said so. Provisions that would let a senior officer authorise an enforcement officer to extract information accessible by means of an online account accessed through a lawfully seized device do exist, in the Crime and Policing Act 2026. But the Act itself says only that it comes into force on such day as the Secretary of State may by regulations appoint. See /uk/online-accounts-2026-act for the current status.

Crime and Policing Act 2026, s.173(1) — NOT YET IN FORCE (legislation.gov.uk, checked 2026-09-08)
Read the quote
Where an electronic device has been lawfully seized, a senior officer may authorise an enforcement officer to extract information accessible by means of one or more online accounts which were accessed by means of the device before it was seized.
Crime and Policing Act 2026, s.255(1) (default commencement — ss.173-180 not separately listed) (legislation.gov.uk, checked 2026-09-08)
Read the quote
Subject as follows, this Act comes into force on such day as the Secretary of State may by regulations appoint.

Jurisdiction

England & Wales, Scotland, Australia and the United States. Each is genuinely different — device-seizure and compelled-unlocking law varies by country and, within Australia and the United States, by state or circuit — so every jurisdiction’s pages are written from that jurisdiction’s own law rather than reworded from another’s. Northern Ireland is not yet covered, and no page pretends to cover it.

Tell us when we are wrong

Corrections go to [email protected], and every correction we act on is published at /corrections with what was wrong and what it now says.