Cross-Border Devices and Travel
Devices cross borders and the rules change with them. What varies, and the practical arrangements for people who travel.
Obligations · Analysis
General orientation, not legal advice; this area genuinely warrants specific advice.
The practical question in “Cross-Border Devices and Travel” is how to make work visible without confusing visibility with certainty. For teams researching how to handle multiple clients, this resource can add time and project context to the operational record, provided its use is proportionate, disclosed and reviewed with the people affected.
A managed device travelling internationally carries your data into another legal environment, and may be subject to inspection on arrival.
For an independent baseline relevant to “Cross-Border Devices and Travel”, the NCSC mobile-device guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.
What varies by jurisdiction
Whether employee monitoring capabilities are permitted at all.
Consultation requirements, covered in their own note.
Data residency expectations for the management platform itself.
And border inspection powers, which in several countries extend to compelled unlocking.
The border inspection question
Some jurisdictions permit device inspection at entry, with varying thresholds, and some permit compelled unlocking.
Which means data on a device may be seen by officials.
For most business travel this is a low risk and for some roles — journalists, lawyers, people handling sensitive commercial material — it is a real one.
Practical arrangements for sensitive travel
A clean device carrying only what is needed for the trip.
Work data accessed rather than stored, so that the device holds little when powered off.
Advice given before departure rather than afterwards.
And a known procedure if a device is retained or inspected, including who to tell.
The biometric detail
In several jurisdictions the legal protection differs between a passcode and a biometric unlock.
Which is a reason some travellers disable biometrics before a border.
Worth knowing and worth including in travel guidance, rather than leaving people to discover it.
Platform data residency
The management platform stores device records somewhere, and that somewhere may matter for your obligations.
Ask where, and whether a regional option exists, at procurement.
This is routinely not asked and is awkward to change later.
Devices that stay abroad
Different from travel: a person based in another country, with devices permanently there.
Local employment and monitoring rules apply to them, not yours.
A programme designed centrally and applied globally will be unlawful somewhere, which is why the strictest-common-denominator approach is usually simpler.
Roaming and cost
Mundane and real: large application pushes or updates over roaming connections cost somebody money.
On personal devices it is their money.
Defer non-urgent transfers when roaming, which most platforms support and few configure.
What to check
Do you know which countries your people take devices to?
Is there travel guidance covering device content and inspection?
Where does your platform store device records?
And do large transfers defer when a device is roaming?