Skip to content

Device minimization and border crossings in Asia

Carrying your everyday phone and laptop across a border is fine almost everywhere, almost always. The risk lives in the small set of crossings where it isn't: a destination where customs can inspect your device, where a chat history or a single app is enough to start an investigation, or where your account stays signed in and an officer scrolls through it while you stand at the desk. For journalists, human-rights defenders, NGO staff, researchers, LGBTQ+ travelers, and anyone returning to a less open jurisdiction, the safest device is the one that holds almost nothing when it crosses the line.

This page is built in two halves. The first is general device-minimization OPSEC that applies to any border. The second is Asia-specific border-search context, jurisdiction by jurisdiction, because the rules differ sharply and the wrong assumption is dangerous here.

Why this page exists

EFF's Things to Consider When Crossing the U.S. Border is the gold standard for this topic, and we send you there for the US. The problem: it is structurally US-law-only, and even the Thai, Vietnamese, and Burmese translations still describe US law, which misleads travelers crossing borders in Asia. anoni.net is a volunteer community in the Sinophone Asia-Pacific, so this page keeps the general OPSEC that transfers everywhere and adds the regional border context that the canonical guide does not cover.

General framing, not legal advice

Border-search law changes fast and varies by checkpoint, officer, and your nationality. The per-jurisdiction notes below are a starting point for your own research, not legal advice. Verify the current rules against official sources and, for real exposure, consult a lawyer or an organization on the ground before you travel.

Why minimize before you travel

The principle underneath everything on this page: an officer, a thief, or a malware-laden public network can only reach what is actually on the device. Encryption, strong passcodes, and careful conduct at the desk all matter, but the single most reliable control is having less to find.

A normal phone is a poor travel device for a sensitive trip. It holds years of messages, a logged-in social-media graph, photo metadata pinning where you live and who you see, saved passwords, and cloud sync that quietly pulls everything else back down. None of that needs to cross the border for the trip to work. The sections below are roughly ordered by how much they reduce, from a quick pre-trip cleanup to carrying a separate clean device.

This is one half of threat modeling: before you decide how far to go, name the adversary (customs? a hostile destination? a colleague who borrows your laptop?), what they can reach, and the consequence if they reach it. A short threat model per trip fits on one sheet of paper and reliably catches preparation gaps.

Back up before you go, and watch the cloud double-edge

Reducing what's on your device only works if you can get it back. Make a full backup before you strip anything down, ideally an encrypted local backup to a drive you leave at home rather than a cloud backup you can reach from the road.

Cloud backups are a genuine double-edge for travel:

  • They speed recovery if a device is lost or seized, which is the reason most people leave them on.
  • They also mean that signing into your account from any device, including under pressure at a border, can pull down everything the cloud holds: messages, photos, full chat history. A wiped phone with live cloud sync is not actually minimized.

Practical handling:

  • Take the backup first, verify you can restore from it, then delete the sensitive material off the travel device.
  • Pause cloud backup before you travel, resume after. On iPhone, audit Settings → Apple ID → iCloud for which apps sync; on Android, WhatsApp's Google Drive backup is a common surprise (WhatsApp → Settings → Chats → Chat Backup).
  • Signal's messages don't reach Apple iCloud, but an iOS device backup includes Signal's data folder if device backup is on. Signal also shipped its own end-to-end-encrypted Secure Backups (v8.0, February 2026) stored on Signal's servers; whether to opt in depends on your threat model1.
  • If you're worried about device loss en route, a local encrypted backup before leaving beats relying on a cloud you'd have to sign into from the road.

The clean-device strategy

For the highest-risk trips (a destination that criminalizes your work or identity, sensitive reporting, returning to a jurisdiction with hostile inspection powers), the most reliable approach is to not bring your real device at all.

  • Carry a separate travel device: a cheap secondhand Android, factory-reset, signed into a fresh account that isn't tied to your real email.
  • Install only what the trip needs (maps, translation, hotel booking, the one messenger you'll actually use).
  • Leave your main phone at home and sync back after the trip.

The cost is real (a second device, the setup time), but it's more dependable than wiping and rebuilding your main phone before and after every crossing, where one forgotten app or cached login defeats the whole exercise.

If a clean device isn't practical, the fallback is a thorough pre-trip cleanup of your main device:

  • Uninstall sensitive apps rather than hiding the icon. Dating apps, community apps, anything tied to work that shouldn't travel.
  • Sign out of all accounts, including alt accounts on Instagram, Threads, Bluesky, and the like. Officers commonly look at what's currently signed in, which is far easier than searching a wiped device.
  • Clear browser history, bookmarks, and cookies across every browser on the device.
  • Back up and delete sensitive conversations (Signal, Telegram, LINE, WeChat) to your home backup first, then remove them from the travel device.
  • Audit the camera roll and cloud photo libraries: Sensitive images can be moved to encrypted storage and re-downloaded after the trip.
  • Check the small stuff: email signatures, wallet/loyalty cards, lock-screen wallpaper. Identity leaks through details.

For LGBTQ+ travelers specifically, the border section of our LGBTQ+ guide covers the same cleanup with attention to dating apps, community-app traces, and destinations that criminalize same-sex conduct.

At the border: conduct and device state

How you carry the device through the checkpoint matters as much as what's on it. A few habits, none of which require special tools:

  • Use a strong passcode, not biometrics, at the border: A 6-or-more-digit PIN (better, an alphanumeric passphrase) is what protects the device. Turn off Face ID and fingerprint before you reach the checkpoint. A face or finger can be applied to a phone in seconds, sometimes without your active cooperation; a passcode you have to type is harder to compel and, in some jurisdictions, better protected legally2.
  • Power the device fully off before arrival: A phone that has been unlocked since boot sits in an "after first unlock" state, where much of its data is decrypted in memory and far easier for forensic tools to extract. A full power-off returns it to the "before first unlock" state, where file-based encryption keeps data locked until the passcode is entered, and clears any in-memory unlock state3. Powering off also disables biometrics on both iOS and Android until the next PIN entry.
  • Stay calm and don't volunteer: Don't offer to unlock, don't narrate what's on the device, don't hand over passwords unasked. Comply only with an explicit, lawful request, and know that the consequence of refusing varies enormously by jurisdiction (see below).
  • Know the trade-off of refusing: In some places refusal means denied entry; in others, device seizure; in a growing number, a criminal charge. Decide your line before you're at the desk, not in the moment.
  • Have a fallback contact: If a device is seized or you're detained, you want a way to reach a colleague, a lawyer, or a helpline. The Access Now Digital Security Helpline is 24/7 and multilingual; contact them before travel if you expect real exposure.

SIM, eSIM, and the history that travels with you

The SIM in your phone carries a record, and the question is who holds it and whether the destination's authorities can tie it directly to you. Three options, three different exposures:

  • Local real-name SIM bought on arrival: your passport (and, in a growing number of places, your face) is bound to a local number that sits in the local carrier's and often the government's database. Local law enforcement can query it on the spot, and the record is frequently retained long-term.
  • Home-number roaming: the carrier that holds your identity is back home. The destination sees a foreign roaming connection and its locations, but tying that to you usually requires a cross-border legal request.
  • Data-only eSIM with no local number: there's no local-SIM layer at all; your identity mostly lives with the eSIM provider and your payment record.

For the threat of destination surveillance, roaming and data-only eSIMs keep the identity mapping outside the destination, which makes on-the-spot attribution harder. A long-term personal SIM crossing into a hostile jurisdiction is the opposite: it carries your telco history and prior locations with it. Buy a local real-name SIM only when you genuinely need a local number (for example to receive a verification code), and weigh that against the on-arrival registration it triggers. One caveat to the eSIM advantage: real-name registration is spreading even to data-only eSIMs in some places, so verify the destination's current rule rather than assuming an eSIM is anonymous.

Buying a burner abroad, and taking it home

Two questions come up often enough to answer directly: can you buy an anonymous phone or SIM while traveling, and what changes when you bring it back.

Separate the handset from the number: "Burner" collapses two things with different exposures. The handset carries an IMEI, a hardware identifier the network sees no matter which SIM is in it. The SIM carries the registration that binds a number to a legal identity. Once you separate them, the answer for most trips is a reusable clean device plus whatever number the destination requires, rather than discarding both after every crossing.

Buying abroad is not buying anonymity: Across this region, a SIM bought on arrival is registered to your passport in almost every jurisdiction, and in mainland China and Thailand to your face as well — Thailand has required biometric liveness checks for SIM registration since August 2025. Tourist SIMs also expire quickly, often in 30 to 60 days. If the threat you're managing is destination surveillance, the move is the one already covered in the SIM section above: keep the identity mapping outside the country with roaming or a data-only eSIM. Buying locally does not buy anonymity.

What changes when you take it home

  • A foreign number roaming at home reports your location to the foreign carrier, so attribution generally requires a cross-border request. The trade-off is that a foreign roaming number sitting near your home address for months is itself a pattern.
  • Prepaid validity runs out. A 30-day tourist SIM is not a long-term second line.
  • Swapping in a domestic SIM binds that handset to your local identity, which is exactly what the clean device was avoiding.
  • The IMEI links both numbers: One handset that carried a foreign SIM and then a domestic one shows the carrier a single device with two numbers under it.
  • Customs: Carrying more than one phone is not itself unlawful in most of the region, but it invites questions. A plain reason (a work phone and a personal one) travels better than concealment.

Returning to mainland China inverts several of these

A foreign roaming number is not discreet there; it stands out and sits inside the same monitoring scope, and the cross-border-request threshold is not protection. The device itself may be inspected on entry, since state-security officers have had explicit authority to check personal electronic devices since July 2024, and the jurisdiction sits at the top tier of the border-inspection column in the table above. Swapping in a local SIM means real-name registration with a face check. Only the short prepaid validity carries over unchanged. Full context is in posting on mainland Chinese platforms and the mainland China entry in the per-jurisdiction section below.

The practical shape: Keep the device and reuse it, resetting before each trip and not using it for daily life in between. Don't mix foreign and domestic SIMs in one handset. Get a domestic second line domestically if you need one, accepting that registration applies there too. Physical destruction is for a device that genuinely took on risk, and our activists' guide covers that end of the lifecycle.

What a burner does not fix: Signing into your everyday email, social, or cloud accounts on the clean device defeats it entirely. So does contacting the same people, keeping the same hours, and appearing in the same places. Carrying both phones powered on at once lets cell-tower records pair them. The device is one layer; the account layer is in maintaining multiple online identities.

Per-jurisdiction border context (Asia)

The notes below cover border device-search powers specifically, with two reference points (US and UK) that many travelers already half-know but routinely misapply to Asia. This is general framing as of mid-2026, not legal advice. Verify against official sources before you travel; these powers are exactly where wrong specifics are dangerous.

United States and United Kingdom (the rules people already know)

Most travelers' mental model of "what happens at the border" comes from the US and UK. It does not transfer to Asia, so it's worth stating plainly and then setting aside.

  • United States: Customs and Border Protection can search phones and laptops at the border without a warrant and can request that you unlock them. US citizens can refuse and cannot be denied entry for refusing, but the device may be seized and held for days to weeks; non-citizens who refuse may be denied entry4. CBP reported searching over 47,000 devices in 20245. For anything US-specific, use EFF's crossing-the-US-border guide, which is the authority on this and which we don't try to reproduce.
  • United Kingdom: Under Schedule 7 of the Terrorism Act 2000, examining officers at ports and airports can stop and question travelers without suspicion, examine devices, and require passwords; refusal is itself a criminal offence, and people have been prosecuted for it6. This is a sharper power than the US one, and it surprises travelers who assume the UK is "like home."

Hong Kong

The most significant recent change in the region, and the one most likely to catch travelers who assume Hong Kong is low-risk. A National Security Law amendment (Legal Notice 27 of 2026), effective 23 March 2026, makes it a criminal offence for a person under a national-security investigation, or anyone designated as knowing a seized device's password or decryption method, to refuse to provide it — a designation broad enough that legal analysts read it as potentially reaching a spouse or household member. The maximum penalty for an individual is one year's imprisonment and a HK$100,000 fine; knowingly giving false information carries up to three years and HK$500,000. US State Department guidance states that the change applies to everyone in Hong Kong, including travelers merely transiting Hong Kong International Airport who clear immigration7.

The trigger is a national-security investigation rather than a blanket border-search power, so an ordinary crossing is unlikely to produce an unlock demand by itself. What makes it consequential anyway is how broadly national-security matters are defined, how much discretion sits with the authorities, and the fact that refusing is itself an offence — there is no "decline and accept a refused entry" option of the milder kind available at some other borders. A widely repeated claim that a second, separate instrument effective 30 March 2026 gives immigration officers a suspicionless device-unlock power does not hold up: it appears only in travel-advice aggregator sites that contradict each other on both the effective date and the penalty, and it is absent from the Government Gazette, from Department of Justice materials, and from first-tier reporting. We do not rely on it here, and we'd suggest checking official notices before acting on it elsewhere.

This still removes the old assumption that passing through Hong Kong is low-risk. For anyone moving between Hong Kong, Macau, mainland China, and Taiwan, the working assumption at every leg is that your device may lawfully be searched under national-security authority, so run the pre-departure audit each time.

Mainland China

Treat device inspection as a baseline assumption. Procedures issued by the Ministry of State Security, effective 1 July 2024, give state-security officers broad authority to inspect electronic devices (phones, tablets, laptops) and gather "electronic data" including messages, emails, chats, documents, images, and app records, at borders, in transit, and inside the country. Routine inspections are framed as targeted at counter-espionage subjects rather than every traveler, and require internal approval, but emergency provisions allow warrantless checks, and the practical reality reported by travelers is that spot checks of phones and laptops do happen at some ports8. Combined with mandatory real-name-plus-face SIM registration, the working assumption for sensitive travel is that everything on a connected device is reachable. A clean device is the safest answer here.

Singapore

Day-to-day, mainstream services are reachable and most travelers clear immigration without a device search. The relevant exposure is the breadth of statutory search and arrest powers rather than a routine border-phone-search regime. Amendments to the Criminal Procedure Code in 2024 broadened powers to search items in a person's possession or control in connection with an arrest, and the legal threshold for various interventions is comparatively low, so don't treat "no routine search" as "no possible search." The larger practical risk in Singapore is what you publish, given POFMA (the online-falsehoods law), defamation, and foreign-interference legislation, more than what's on your phone at the desk. We could not verify a specific, current Singapore border device-search-and-compelled-unlock statute of the Hong Kong or UK kind, so we describe the powers generally rather than cite one; confirm with the Immigration & Checkpoints Authority before relying on any specific claim.

Malaysia

Customs and immigration powers center on declarations of goods, cash, and prohibited items rather than a publicized device-search-and-unlock regime. The practical risk for many travelers is content-based: material touching the monarchy, religion, race, or sedition can trigger follow-up, and for LGBTQ+ travelers, federal Section 377 plus state-level Islamic enforcement mean dating-app conversations or location data found on a device can become an investigative lead in enforcement actions9. Bring a minimized device and coarsen or remove location-revealing data. We could not verify a specific Malaysian border statute compelling device unlock, so treat content-based follow-up rather than routine forced unlock as the realistic threat, and verify current rules before travel.

Thailand

Routine immigration and customs checks are not deep device searches. Officers may ask to see proof of tourist intent (an itinerary, a hotel booking, sometimes a glance at messaging contacts), and can deny entry if unconvinced, but accessing the internal data on your phone generally requires a court process under Thailand's Computer Crime Act, and deep extraction happens in the context of a criminal investigation rather than a border line10. The disproportionate risk in Thailand is legal exposure from what you post or carry: lèse-majesté (criminal insult to the monarchy) carries 3 to 15 years per offence and has been applied to foreigners, and even a like or a share can attract liability. Never carry or post anything touching the royal family. The device threat here is downstream of a content offence, not the border check itself.

Macau, and the rest of the region

For Macau and several other Asian jurisdictions, public, verifiable information on border device-search powers specifically is thin. That absence of documented power is not the same as a guarantee, so apply the general OPSEC above: minimized device, strong passcode, biometrics off, powered down at arrival. For a country-by-country briefing tuned to your exact destination, dates, and role, our pre-departure AI briefing page gives you copy-paste prompts to run on your own AI without any query reaching us, and lists the primary sources (OONI, Freedom House, Access Now, your foreign ministry) to verify the answers against.

Where to go from here


  1. Signal — Secure Value Recovery and Secure Backups — Signal's end-to-end-encrypted backup feature, shipped in v8.0 (February 2026). 

  2. Fifth Amendment Does Not Protect Against Biometric Phone Unlock, Says 9th Circuit Appeals Court — ID Tech Wire, on the legal asymmetry (in the US) between compelling a passcode versus a fingerprint or face. The legal protection is US-specific; the practical point (biometrics are easier to compel physically) is general. 

  3. BFU and AFU Lock States — DigForCE Lab, Dakota State University, on why a powered-off "before first unlock" device resists forensic extraction far better than one that has been unlocked since boot. 

  4. Border Search of Electronic Devices at Ports of Entry — U.S. Customs and Border Protection, official statement of CBP's warrantless device-search authority. 

  5. What to Know About Airport Phone Searches at the US Border — KQED, citing the CBP figure of over 47,000 device searches in 2024 and the seizure-versus-denial distinction for citizens and non-citizens. 

  6. Examined under Schedule 7 of the Terrorism Act 2000: What are my rights? — Liberty, on the obligation to answer questions and supply passwords, and that refusal is a criminal offence. 

  7. Security Alert: Refusal to Give the Government Passwords to Personal Mobile Devices Criminalized in Hong Kong — U.S. Consulate General Hong Kong & Macau, 26 March 2026. The amendment itself is in the Government Gazette notice of 23 March 2026. Penalty figures follow Hong Kong Free Press (23 March 2026) and The Standard; for the scope of who can be designated to supply a password, see Hivos EU SEE's legal analysis, which also notes that the customs powers added at the same time cover seizure of seditious material rather than device decryption. 

  8. New rules let China's state security police check people's devices — Radio Free Asia, on the Ministry of State Security procedures effective 1 July 2024 governing inspection of personal electronic devices. 

  9. Malaysia: Country chapter — World Report 2024 — Human Rights Watch, on Section 377, state-level Islamic enforcement, and the use of app data in enforcement actions against LGBTQ+ people. 

  10. Can immigration check your phone when you arrive in Thailand? — The Thaiger, on the warrant requirement under the Computer Crime Act for accessing internal device data, and the separate, severe lèse-majesté exposure.