EFF filed an amicus brief arguing that searches of electronic devices at the US border require a warrant. The legal battle is ongoing. For SaaS founders, the question is operational regardless of how courts rule: what do your employees carry across borders, and what customer data is exposed?

  • Customs and Border Protection (CBP) can search any device at the border without a warrant under current case law
  • Two tiers: basic searches (manual look-through) and advanced searches (forensic copy) - the advanced tier requires reasonable suspicion in some circuits
  • EFF's argument: even basic searches now require warrants given the volume of personal and corporate data on modern devices

What your SaaS should know about employee travel

1. Map the data on employee laptops

Customer PII, source code, financial records, strategic documents. Each category has different exposure if a device is seized.

2. Minimize what crosses borders

Cloud-stored data accessed via thin client (no local copy) reduces exposure dramatically. If the laptop is wiped before travel and reinstalled at destination via your IT, even less.

3. Document the policy

Travel policy that addresses: pre-trip device prep, what to do if asked to unlock, who to call, post-trip device reset.

Data typeTravel riskMitigation
Source codeHigh (IP)Cloud-only access, no local clone
Customer PIIVery high (GDPR)No local copies; access via VPN
Internal financialsHigh (deal sensitivity)Encrypted vault, password required
Strategic docsMediumStandard encryption

What to add to your privacy policy

If your SaaS handles customer data and employees travel:

  • Document that customer data does not travel on personal devices
  • State which jurisdictions employees are not authorized to travel to with corporate devices
  • Reference your security policy in the privacy policy for transparency

EFF's broader point applies beyond US borders: device searches at international borders are increasingly common in multiple jurisdictions. The mitigation is the same: don't carry what you don't need.

Conclusion

Border device searches are a slow-burning concern that becomes acute the moment one of your employees is asked to unlock. A pre-emptive travel policy and a thin-client architecture are the cheap mitigations. Both also pay off for general security posture.

To document your data residency and employee data handling in your privacy policy, try Termerly free.