Phone SeizedProtect yourselfPreparing a phone before a border crossing
Preparing a phone before a border crossing
What you must do, what you can refuse, and what they can do
Every claim below links to the law it comes from, with the wording quoted so you can check it yourself.
You must
Refusing is a criminal offence.
At a UK port or airport, a person questioned under Schedule 7 must give the examining officer any information in their possession that the officer requests.
Terrorism Act 2000, Sch.7 para 5(a)
“A person who is questioned under paragraph 2 or 3 must— give the examining officer any information in his possession which the officer requests”
Read it at legislation.gov.ukquote checked 2026-09-08
The Schedule 7 Code of Practice states that the duty to provide access to an electronic device includes unlocking it, including by thumb or finger or any other form of access control, where access requires that.
Schedule 7 (Terrorism Act 2000) Code of Practice (Oct 2025), para 61
“The person must provide access to any electronic device to allow for a search to be undertaken, including where access to a device requires the person to unlock a device through application of their thumb or finger, or any other form of access control”
Read it at assets.publishing.service.gov.ukquote checked 2026-09-08
Wilfully failing to comply with a duty imposed under Schedule 7 of the Terrorism Act 2000 is a criminal offence.
Terrorism Act 2000, Sch.7 para 18(1)(a)
“A person commits an offence if he— wilfully fails to comply with a duty imposed under or by virtue of this Schedule”
Read it at legislation.gov.ukquote checked 2026-09-08
You can refuse
No penalty for saying no.
There is no legal compulsion for a traveller to provide a password or passcode, or to provide assistance to access an electronic device, at the Australian border.
Senate Legal and Constitutional Affairs Legislation Committee, Additional Estimates, ABF answer AE22-050 (14 Feb 2022) — no legal compulsion
“There is no legal compulsion for a traveller to provide a password/passcode or provide assistance to an electronic device at the border.”
Read it at aph.gov.auquote checked 2026-09-08
Lawful to refuse — but it costs you
Not an offence, but it carries a penalty or an inference.
If a traveller refuses to provide a password or assistance for an examination of their electronic device at the Australian border, and an ABF officer considers there to be a risk to the border, the officer is authorised to seize the device for further examination before it is returned.
Senate Legal and Constitutional Affairs Legislation Committee, Additional Estimates, ABF answer AE22-050 (14 Feb 2022) — consequence of refusal
“If an individual refuses to comply with a request or provide a password for an examination of their electronic device, and an ABF officer considers there to be a risk to the border, the ABF officer is authorised to seize that device for further examination prior to being returned.”
Read it at aph.gov.auquote checked 2026-09-08
US Customs and Border Protection's own directive states that travellers are obligated to present electronic devices, and the information on them, in a condition that allows inspection.
CBP Directive No. 3340-049B §5.3.1 (eff. 1 Jan 2026)
“Travelers are obligated to present electronic devices and the information contained therein in a condition that allows inspection of the device and its contents.”
Read it at cbp.govquote checked 2026-09-08
US Customs and Border Protection's own directive states that if an officer is unable to complete an inspection because a device is protected by a passcode or encryption, the officer may detain the device pending a decision on its admissibility or other disposition.
CBP Directive No. 3340-049B §5.3.3 (eff. 1 Jan 2026)
“If an officer is unable to complete an inspection of an electronic device because it is protected by a passcode or encryption, the officer may, in accordance with section 5.4 below, detain the device pending a determination as to its admissibility, exclusion, or other disposition.”
Read it at cbp.govquote checked 2026-09-08
Apple's own documentation lists entering the passcode, or unlocking with Optic ID, Face ID or Touch ID, as the alternative ways to unlock a device once its most-protected data class has locked.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .”
Read it at support.apple.comquote checked 2026-09-08
Android's file-based encryption documentation states that Credential Encrypted storage, the default location for app data, is only available after the device has been unlocked.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
Apple states it does not hold the encryption keys for Advanced Data Protection categories and cannot help recover that data if the account holder loses access.
Apple, "iCloud data security overview" (support.apple.com/en-gb/102651), as fetched 2026-09-08
“Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account.”
Read it at support.apple.comquote checked 2026-09-08
Read this before you read anything else on this page
This page does not advise refusing a lawful demand at a border. At a UK port or airport, wilfully failing to comply with a Schedule 7 duty — which includes providing access to an electronic device — is a criminal offence. At a US border, Customs and Border Protection’s own directive allows an officer to detain a device it cannot inspect because of a passcode or encryption. In Australia, there is no legal compulsion to provide a password, but Border Force can seize the device instead. Three different legal positions, three different consequences — what follows states each of them, and only then turns to device-side steps that do not involve refusing anything.
What the UK Schedule 7 Code says about passwords and biometrics
A person questioned under Schedule 7 of the Terrorism Act 2000 “must—give the examining officer any information in his possession which the officer requests.” The Schedule 7 Code of Practice states that this duty to provide access to a device “includes where access to a device requires the person to unlock a device through application of their thumb or finger, or any other form of access control.” Wilfully failing to comply with a duty imposed under Schedule 7 is a criminal offence. See Extraction after seizure for what happens to a device once it has been examined.
What Australian Border Force says
The ABF has told a Senate Estimates committee: “There is no legal compulsion for a traveller to provide a password/passcode or provide assistance to an electronic device at the border.” It also told the same committee what follows a refusal: “If an individual refuses to comply with a request or provide a password for an examination of their electronic device, and an ABF officer considers there to be a risk to the border, the ABF officer is authorised to seize that device for further examination prior to being returned.” See Border: ABF for the rest of that policy, including retention timeframes.
What the US CBP directive says
CBP’s own directive states: “Travelers are obligated to present electronic devices and the information contained therein in a condition that allows inspection of the device and its contents.” It also states what happens if that is not possible: “If an officer is unable to complete an inspection of an electronic device because it is protected by a passcode or encryption, the officer may…detain the device pending a determination as to its admissibility, exclusion, or other disposition.” See Passcode vs biometrics for the rest of that directive.
Device-side steps, each grounded in a vendor's own documentation
None of the following is advice to refuse a lawful demand. Each is a state a device can be put into before travelling, described in the vendor’s own words:
- Turning off biometric unlock leaves the passcode as the way in. Apple’s own documentation lists entering the passcode, or unlocking with Optic ID, Face ID or Touch ID, as the alternatives once its most-protected data class has locked — so with biometric unlock switched off, the passcode is the one that remains.
- Powering a device off returns app data to a locked state. Android’s file-based encryption documentation states that Credential Encrypted storage, the default location for app data, is only available after the device has been unlocked — which a power cycle undoes.
- Advanced Data Protection changes what Apple itself can access in the account. Apple states it does not hold the encryption keys for Advanced Data Protection categories and cannot help recover that data if the account holder loses access — the same limit described on Cloud and carrier.
See the border-prep tool and the rights card for a step-by-step version of the legal position stated above.
Last reviewed 2026-09-08. Next review due 2026-12-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.