EFF filed an amicus brief arguing that searches of electronic devices at the US border require a warrant. The legal battle is ongoing. For SaaS founders, the question is operational regardless of how courts rule: what do your employees carry across borders, and what customer data is exposed?
The current legal posture (US border, 2026)
- Customs and Border Protection (CBP) can search any device at the border without a warrant under current case law
- Two tiers: basic searches (manual look-through) and advanced searches (forensic copy) - the advanced tier requires reasonable suspicion in some circuits
- EFF's argument: even basic searches now require warrants given the volume of personal and corporate data on modern devices
What your SaaS should know about employee travel
1. Map the data on employee laptops
Customer PII, source code, financial records, strategic documents. Each category has different exposure if a device is seized.
2. Minimize what crosses borders
Cloud-stored data accessed via thin client (no local copy) reduces exposure dramatically. If the laptop is wiped before travel and reinstalled at destination via your IT, even less.
3. Document the policy
Travel policy that addresses: pre-trip device prep, what to do if asked to unlock, who to call, post-trip device reset.
| Data type | Travel risk | Mitigation |
|---|---|---|
| Source code | High (IP) | Cloud-only access, no local clone |
| Customer PII | Very high (GDPR) | No local copies; access via VPN |
| Internal financials | High (deal sensitivity) | Encrypted vault, password required |
| Strategic docs | Medium | Standard encryption |
What to add to your privacy policy
If your SaaS handles customer data and employees travel:
- Document that customer data does not travel on personal devices
- State which jurisdictions employees are not authorized to travel to with corporate devices
- Reference your security policy in the privacy policy for transparency
EFF's broader point applies beyond US borders: device searches at international borders are increasingly common in multiple jurisdictions. The mitigation is the same: don't carry what you don't need.
Conclusion
Border device searches are a slow-burning concern that becomes acute the moment one of your employees is asked to unlock. A pre-emptive travel policy and a thin-client architecture are the cheap mitigations. Both also pay off for general security posture.
To document your data residency and employee data handling in your privacy policy, try Termerly free.
