Support & Education Know your rights Unsettled parts marked as unsettled

Your rights are real,
narrower than you hope,
and useless unsaid.

Someone asks you to unlock your phone. It might be a police officer at a traffic stop, an agent at an airport, or a security guard who has no authority at all. What you are allowed to decline is genuinely different in each case, and in one of them, the honest answer is that the law has not decided yet.

This page is the part of that we can source. We have separated what is settled from what is actively contested, quoted the agencies and the courts in their own words, and marked every place where the confident version circulating online is wrong. Officers are not required to tell you that you may decline, which is exactly why the words have to come from you.

Start with what’s settled ↓
Free. Ungated. No email wall.
Written to be forwarded. Nothing here requires your email address. Google. We hand it to clients, and to anyone who asks us a question this page answers better than we could over coffee.

What is actually
settled.

↳ these are not close questions

Start here, because it is the shortest list and the one people most often get wrong in both directions. These are not close questions. Courts have answered them, and the answers have held.

In Riley v. California (2014), the Supreme Court held that police generally may not, without a warrant, search digital information on a cell phone seized from someone who has been arrested. Exigent circumstances are preserved, but the rule itself has not been eroded. Police need a warrant to search the contents of your phone after an arrest. That has been settled since 2014.

Keep two questions apart, because they have different answers. Can they search it is a Fourth Amendment question, and Riley answers it. Can they make you open it is a Fifth Amendment question, and it is not settled at all.

The direction of travel on the Fourth Amendment question has been consistent. In June 2026, in Chatrie v. United States, the Supreme Court held that acquiring geofence location data from Google is a Fourth Amendment search. That is not a device-search case and we will not stretch it into one, but it is one more sign that the Court keeps extending constitutional protection to digital records.

Consent searches are also settled, and they are the mechanism most searches actually run on. Since Schneckloth v. Bustamonte (1973), a search you agree to needs no warrant and no suspicion. Officers are not required to tell you that you may refuse. The Court said so in Ohio v. Robinette (1996) and again in United States v. Drayton (2002). That is precisely why the words have to come from you.

“I do not consent to a search.”
Anywhere. It will not physically stop anyone, and at a border inspection it will not stop the search at all: CBP does not need your consent. What it does is preserve the objection. The ACLU’s framing: objecting can help preserve your rights in any later legal proceeding.
“Am I free to go?”
Ordinary police encounters only. This is the question that separates a consensual conversation from a detention. Do not use it at a port of entry, where it does not mean what it means on the street: inspection there is not optional.
“I am invoking my right to remain silent.”
Say it out loud. In Salinas v. Texas (2013) a plurality allowed use of pre-arrest, non-custodial silence where the privilege had not been expressly invoked. Under Hiibel (2004), during a valid stop supported by reasonable suspicion in a state with a stop-and-identify law, you may have to give your name. That is not the same as giving your passcode.
↳ the line people most often get backwards:

Declining a search is not evidence of wrongdoing. In Florida v. Bostick (1991) the Supreme Court put it directly: “a refusal to cooperate, without more, does not furnish the minimal level of objective justification needed for a detention or seizure.”

So: officers are not obliged to tell you that you can decline, and your declining cannot itself be treated as suspicion. Both of those are settled, and together they are the entire argument for saying the words plainly and without apology.

Can they make you
open it?

↳ genuinely unsettled, and marked as such

Everything above is stable ground. This is not. If you take one thing from this page, make it the difference between the two, because the confident advice you will find elsewhere almost always comes from someone who has flattened this part into a rule that does not exist.

Whether you can be compelled to unlock your own device is an open question. There is no Supreme Court ruling on it. State high courts and federal circuits have reached different answers, and anyone who tells you there is a clean national rule is describing a wish.

Courts that protected the passcode

“the contents of your mind”

Pennsylvania’s Commonwealth v. Davis (2019) held that compelling a password “demands the recall of the contents of Appellant’s mind.” Indiana’s Seo v. State (2020) required the State to show it already knew particular files existed, or it was just fishing.

Utah’s State v. Valdez (2023) held that verbally providing a passcode is testimonial, and that the foregone-conclusion exception does not apply outside act-of-production cases.

Courts that allowed compulsion

“a foregone conclusion”

New Jersey’s State v. Andrews (2020) and Illinois’s People v. Sneed (2023) went the other way. Sneed accepted that typing a passcode is testimonial but held the foregone-conclusion exception could defeat the privilege, and expressly declined to distinguish a passcode from a biometric.

Same country, same amendment, opposite results, depending on which state you are standing in.

the fault line, stated precisely:

The distinction doing the most work in these opinions is speaking a passcode versus typing it. Valdez protects saying it out loud as pure testimony: words from your mind. Sneed and Andrews analyze typing it as an act of production, which the foregone-conclusion exception can overcome. That distinction is genuinely in the opinions, and it is why “just give them the code” and “never give them the code” are both bad advice delivered without a jurisdiction attached.

Biometrics are not the clean “passcode protected, fingerprint not” story that gets repeated everywhere. Two federal appellate decisions are usually cited as a split, and the real distinction between them is narrower and more useful than that.

Ninth Circuit · 2024

United States v. Payne

A compelled thumbprint was held not testimonial: it “required no cognitive exertion,” placing it in “the same category as a blood draw.” An officer physically pressed the defendant’s thumb to the phone.

Two limits the headlines drop. The court wrote that its opinion “should not be read to extend to all instances where a biometric is used to unlock an electronic device.” And Payne was a parolee subject to a suspicionless-search condition, not a member of the general public.

⚠ officer acted; defendant submitted passively
D.C. Circuit · 17 January 2025

United States v. Brown

In the consolidated Brown appeal, the court held that ordering a defendant (Peter Schwartz) to unlock his phone was testimonial and that denying suppression was error. It remanded for harmless-error analysis rather than ending the case. Here the agent ordered the defendant to open the phone himself.

Brown framed itself as consistent with Payne rather than in conflict with it. The operative line is not passcode versus biometric. It is passive submission versus being commanded to perform the act.

⚠ defendant was ordered to act
the trap that decides most real cases:

The reflex costs you the argument.

In United States v. Bendann (Fourth Circuit, 25 June 2026), a warrant authorized a biometric unlock. Face ID failed. The phone fell back to the passcode screen. The defendant typed his passcode in, and the court held he did so “voluntarily, perhaps even reflexively.” The claim failed because the officer never asked for the passcode and Bendann entered it unprompted, not because the court announced any general rule that a reflex is unprotected.

If you take one operational thing from this section: the moment a biometric fails and a keypad appears is the moment that matters. On these facts, what the defendant’s thumbs did next decided the argument.

↳ an extreme court-order case, not a normal border consequence:

Asserting the Fifth Amendment is not the same as walking away. In United States v. Apple MacPro Computer (Third Circuit, 2020), Francis Rawls was jailed for civil contempt for more than four years (held from 30 September 2015) for refusing to decrypt drives. He was released only when the court held that the eighteen-month cap in 28 U.S.C. § 1826(a) applied.

Read that in its actual setting: Rawls disobeyed a federal decryption order in ongoing litigation. It is not what happens when someone declines at a checkpoint, and we are placing it here only so that “just refuse” does not read as costless. The decision has real weight on both sides, and it is one to make with a lawyer rather than with a page on the internet.

Airports are a different
country, legally.

↳ CBP’s rules, in CBP’s own words

A port of entry is not a traffic stop, and almost nothing from the first two sections transfers cleanly. Different authority, different agency, different rules, and a set of protections that come from an agency policy rather than from the Constitution, which matters more than it sounds.

First, an institutional distinction worth getting right, because the two agencies you meet at an airport do not have the same authority. TSA’s published materials treat your devices as physical objects, things to X-ray for weapons and explosives. CBP is the agency that asserts and exercises search authority over the contents of a device, under its own directive and published FAQ. We are not going to characterize TSA’s position on device content beyond what TSA publishes, because it does not publish one.

One concrete thing TSA does state: it “does not prohibit photographing, videotaping or filming at security checkpoints, as long as the screening process is not interfered with.”

419M
travelers processed by CBP in fiscal year 2025.
CBP’s own published figures.
55,318
electronic-device searches in the same year: 50,922 basic and 4,396 advanced.
CBP’s table also shows searches rising roughly 63% from FY24 Q3 to FY26 Q3.
0.013%
of arriving international travelers had a device searched: roughly 1 in 7,600.
55,318 searches against about 419 million arrivals. Calibration matters in both directions: this is rare, and it is also tens of thousands of people, growing.
what CBP’s current directive actually says:

Directive 3340-049B took effect on 1 January 2026 and supersedes 3340-049A. Most write-ups you will find online describe the old one.

Basic search: an officer may examine a device “with or without suspicion.” Advanced search (connecting external equipment to review, copy or analyze contents) requires reasonable suspicion of a violation of a law CBP enforces, or a national-security concern, plus supervisory approval at Grade 14 or above; the national-security-without-suspicion route needs Director-level sign-off.

The change nobody wrote about: under 049B, connecting external equipment “to bypass a password, overcome encryption, translate content… does not constitute an advanced search.” Password-bypass and decryption are now basic searches: no suspicion required, no supervisor required.

If your device is taken: detention “ordinarily should not exceed five (5) calendar days,” extendable by a Port Director, and re-approvable beyond fifteen days in increments of seven or fewer. Ask for a Form 6051D custody receipt. Copies of your data may not be retained beyond 21 calendar days absent probable cause, but CBP’s FAQ notes that retained information may sit in the Automated Targeting System for up to fifteen years.

On cloud data, the directive says officers “may not intentionally use the device to access information that is solely stored remotely,” and that they will request airplane mode or disable connectivity themselves. Note carefully what that is: it is CBP policy, not a court holding.

On your passcode, § 5.3.2 says a passcode a traveler provides is used only for that search, is recorded temporarily, is not uploaded, and is deleted when no longer needed, and that passcodes “may not be utilized to access information that is only stored remotely.” Taken together with the paragraph above, CBP’s policy position is that data which is not on the device is outside the search. That is the single best reason to log out of cloud accounts before you travel. It is policy, and policy is rewritable.

And a nuance in § 5.3.1: the directive says officers “may request the individual’s assistance” in presenting a device for examination. It claims no power to compel that assistance, which is a different thing from saying you face no consequences for declining.

How refusing to unlock a device is treated, by immigration status, in CBP's own terms
If you are… What happens if you decline to unlock How settled
A US citizen CBP states you “will not be denied entry… based on CBP’s inability to complete an inspection” of your device. However, CBP also states the device “may be subject to exclusion, detention, or other appropriate action.” You get in; the phone may not. Settled
A green-card holder Genuinely murkier, and we will not pretend otherwise. A returning lawful permanent resident is generally not treated as “seeking admission” under INA § 101(a)(13)(C) unless specific conditions apply, including an absence over 180 days, and status generally cannot be stripped at an airport. But no authority we can point to holds that an LPR cannot be denied entry for refusing to unlock. Advocacy groups argue the citizen rule should apply; that is an argument, not a holding. Unsettled
On a visa or ESTA CBP states that a refusal may be considered “when making admissibility decisions.” CBP also states that its “ability to inspect an electronic device alone does not determine admissibility.” Both sentences are theirs; read them together. Settled
“above and beyond prevailing constitutional and legal requirements”
CBP, describing its own directive

That is CBP’s written concession, and it is the most important sentence in this entire section. Some protections in the directive exceed what courts have clearly required, which means those are CBP’s to give and CBP’s to take back. Read it narrowly, though: the constitutional floor for an advanced search remains unsettled in this circuit, so “more than the Constitution demands” is CBP’s characterization of its own policy rather than a settled holding about every protection in it.

In the First Circuit, which governs Puerto Rico, Alasaad v. Mayorkas (2021) held that border device searches need no warrant and no probable cause, that basic searches are routine and suspicionless, and it rejected limiting such searches to contraband. Critically, Alasaad never decided whether the Constitution independently requires reasonable suspicion for an advanced search: it did not have to, because CBP’s policy already required it.

So here, the only thing requiring suspicion before a forensic search of your phone is CBP’s own directive. A document CBP can rewrite at will. In January 2026, it did exactly that, and password-bypass moved to the suspicionless column.

What that means
from San Juan.

↳ the island’s own answer

Puerto Rico sits in an unusual position: fully inside the United States for customs and immigration, governed by the First Circuit, and carrying its own constitution with protections the federal one does not have. That combination produces some specific and useful answers.

The flight to MiamiIs not a border crossing

In Torres v. Puerto Rico (1979) the Supreme Court held the Fourth Amendment applies to Puerto Rico in full, and rejected treating travel between the island and the mainland as a border crossing.

Puerto Rico sits inside the US customs territory (19 CFR 101.1) and inside “the United States” for immigration purposes (8 U.S.C. § 1101(a)(38)). No customs declaration, no immigration inspection, no passport. An ordinary nonstop SJU-to-mainland itinerary is domestic and does not itself create border-search authority. TSA identification rules still apply, and REAL ID enforcement began 7 May 2025.

The bag inspectionIs about fruit

The inspection of bags leaving Puerto Rico for the mainland is an agricultural inspection under USDA plant-quarantine rules (Plant Protection Act, 7 U.S.C. § 7712; 7 CFR Part 318). That authority is confined to “fruits, vegetables, plants, plant products, or other articles.”

Inspectors are looking for fruits, plants and soil, not searching phones or laptops. Nothing in Part 318 reaches data or devices. Cleared bags get a USDA stamp.

SJU is still a port of entryFor international arrivals

San Juan is a CBP port of entry with its own field office, and border-search authority is fully available there, but for international arrivals, which is what Torres draws the line around.

On the “100-mile zone”: 8 CFR 287.1(a)(2) does define a reasonable distance as 100 air miles from any external boundary, and all of Puerto Rico falls inside it. But the authority that follows (8 U.S.C. § 1357(a)(3)) is about boarding conveyances to look for people. Being in the zone is not border-search authority over your device.

↳ the local constitution, and its limits:

Puerto Rico’s Constitution is unusually strong here. Article II § 8 operates ex proprio vigore and (unlike its federal counterpart) binds private parties, per Arroyo v. Rattan Specialties (1986). Article II § 10 adds an express textual prohibition on wiretapping with no federal analogue, plus an exclusionary rule. It is not an absolute ban; later case law recognizes a consent carve-out.

The caveat that has to travel with all of that: these provisions bind Puerto Rico’s own government and, under § 8, private actors. They do not bind federal officers at a federal port of entry, whose conduct is measured against the Fourth Amendment.

Why a powered-off phone
is a different object.

↳ the one piece of real engineering here

Set the law aside for a moment. There is one decision you make before any encounter starts that changes what is technically possible, and it is documented by the device makers themselves rather than by anyone with a position to argue.

Apple’s default data-protection class is called “Protected Until First User Authentication.” In Apple’s own words, it “behaves in the same way as Complete Protection, except that the decrypted class key isn’t removed from memory when the device is locked… protects data from attacks that involve a reboot.” That sentence is the whole before-first-unlock idea: a phone that has been locked since you last used it still holds its keys in memory. A phone that has been restarted and not yet unlocked does not.

Android draws the same line. Credential Encrypted storage is unlocked by your credential and available only until the device restarts, and the Android 17 Compatibility Definition, § 9.9.3, requires that implementations must not allow access to Credential Encrypted storage until the user has unlocked with a password, pattern or PIN.

A restart also changes the unlock method. Apple publishes the list of conditions that force a passcode instead of Face ID or Touch ID, and the first is that the device has just been turned on or restarted. The others include being locked more than 48 hours, five failed biometric attempts, a remote lock, and the volume-plus-side-button Emergency SOS gesture. Android’s timeout is not a single number: depending on biometric class and device requirements, primary authentication may be required after 24 hours or up to 72. Do not carry one figure across platforms, or across Android devices.

the phone that restarts itself:

Apple’s Platform Security guide documents a Secure Enclave feature called Automatic Restart, present since iOS 18.1, which reboots an idle locked device “from an After First Unlock state to a Before First Unlock state,” purging “sensitive security keys and transient data from memory.” Apple’s own documentation states no specific interval: it says only that this happens after a prolonged period.

The widely-repeated 72-hour figure comes from Jiska Classen’s November 2024 reverse-engineering of iOS 18.1. Treat it as that: a measurement of one version at one moment, not a guarantee about the phone in your pocket today. One detail that matters for organizations: Automatic Restart is off by default on supervised, MDM-managed devices, so a corporate fleet does not get this behavior unless someone turns it on.

Android has an opt-in equivalent, documented as “Inactivity Reboot: Automatically reboot your phone if it remains locked for 72 hours,” available through Advanced Protection. It is opt-in: Android does not do this by default.

what the forensic-tool leaks actually showed:

Reporting by 404 Media in July 2024, on Cellebrite support matrices dated April 2024, and again in November 2024 on GrayKey, gave a rare look at what these tools could do at that time. The pattern was consistent: against current devices, extraction was harder, slower, and frequently only partial: GrayKey’s own tables showed partial results against modern iPhones, and the Cellebrite matrices showed it could not brute-force powered-off Pixel 6, 7 and 8 devices.

Read all of that in the past tense, and with dates attached. These were leaked vendor sales documents, a snapshot of a moving race, and our evidence base ends in late 2025. We will not tell you that any device is beyond reach, and you should be skeptical of anyone who does.

Powering off raises the cost and narrows what can be recovered. It is not a guarantee.
the honest version

Powering off puts your phone in the state vendors design their strongest protections around, and it forces a passcode instead of your face or fingerprint on the next unlock. It raises the cost and narrows what can be recovered. It is not a guarantee (leaked forensic-vendor documents from 2024 showed partial extraction still succeeding), and it does not exempt you from the encounter: CBP’s own directive says a device that can’t be inspected may be detained.

And the honest downside. Travelers are “obligated to present electronic devices… in a condition that allows inspection,” and a device not so presented “may be subject to exclusion, detention, or other appropriate action,” with longer processing times. The word “power” does not appear anywhere in Directive 3340-049B. As for whether arriving with a powered-off phone draws extra scrutiny: we are not aware of published evidence establishing whether it does or does not. The EFF recommends powering off, and separately warns that visible precautions may attract unwanted attention.

The playbook, with
sources attached.

↳ sourced, and device-specific where it has to be

Everything above, reduced to what you would actually do. A fair amount of the advice circulating on this topic is wrong in ways that will cost you (one popular tip calls emergency services), so each item here is one we can point at a source for.

The playbook, with the bad advice removed

Half of what circulates on this subject is wrong in ways that will hurt you. These are the versions we can source.

  1. iPhone: force a passcode before you land. Hold the side button and either volume button until the sliders appear, then release and tap Cancel. Biometrics are now disabled until the passcode is entered. Do not rely on the “press the side button five times” version circulating online: where “Call with 5 Presses” is enabled it starts an Emergency SOS countdown, and it is a configurable setting rather than universal behavior. The side-plus-volume method above is the one Apple documents for this purpose.
  2. Lockdown Mode is a different thing. It is Apple’s extreme protection against mercenary spyware, in Settings → Privacy & Security. It does not affect biometric unlock. Do not confuse the two.
  3. Android: use Lockdown. On Pixel phones, press Power and Volume up together, then tap Lockdown; other manufacturers may place it elsewhere. It disables biometrics and hides notification content until you enter your PIN, and it only lasts until the next unlock. If you do not see it, search Settings for the “Show lockdown option” toggle.
  4. Travel light by default. Carry less on the device you take, as an ordinary habit. Two cautions, both real: the EFF notes that traveling without the data a person normally carries could itself attract suspicion, and 18 U.S.C. § 1519 criminalizes knowingly destroying or concealing records “in relation to or contemplation of” a federal matter, with no pending investigation required and a twenty-year maximum. The safe framing is a standing habit of carrying less. It is never “wipe it before you fly.”
  5. Log out of cloud accounts and remove the apps you do not need. This is the item with the most policy behind it: CBP’s directive says officers may not use the device (or a passcode you provide) to reach information stored only remotely. Data that is not on the device is, as a matter of CBP policy, outside the search. Agents can still ask you about accounts.
  6. Never physically resist. 18 U.S.C. § 111 punishes forcibly resisting a federal officer with no condition that the search be lawful. And never lie: 18 U.S.C. § 1001 makes a false statement to a federal officer a separate five-year felony. Decline, in words. Do not obstruct, and do not invent.
  7. Write it down, and get the receipt. Officer names, badge numbers, agency, time. If a device is taken, ask for the CBP Form 6051D custody receipt.

None of this binds
your employer.

↳ the exception people trip on

One more, because it is the case people are most likely to meet and least likely to have thought about: the person asking is not always the government.

one more, because it catches people out:

The federal constitutional rules generally do not bind a private employer.

The Fourth and Fifth Amendments restrain government, not private parties, a rule running from Burdeau v. McDowell (1921) straight through to today. Private security, mall operators and private employers are not state actors. “I do not consent” carries no constitutional weight against them. What governs is your employment contract, the device or BYOD policy, and whatever statutes apply. A company policy may substantially reduce any expectation of privacy in a company-issued device, and refusing may be a firing question rather than a rights question. But that turns on the policy, on employment law, on any collective bargaining agreement, and here on Puerto Rico privacy law.

Two exceptions worth knowing: public-sector employees do retain Fourth Amendment protection in the workplace (O’Connor v. Ortega; City of Ontario v. Quon), and a private party acting at law enforcement’s direction can become a state actor. And note that the heading above says federal constitutional rules deliberately, because Puerto Rico’s own constitution is the exception discussed below.

The Puerto Rico twist: because Article II § 8 operates ex proprio vigore against private parties, and because Arroyo v. Rattan Specialties was itself a private-employer case, there is a live avenue here that does not exist on the mainland. It is narrow. Treat it as a reason to consult a Puerto Rico employment lawyer, not as a rule you can rely on.

Read the primary sources.

↳ and then talk to a lawyer

We are a technology studio, not a law firm, and this page is a summary of other people’s primary work. Go read it, particularly if you are about to make a decision at an actual checkpoint.

There is a carry version of this.

Page 11 of our security workbook is this page folded down to a single printable sheet: the three sentences, the settled and unsettled columns, the before-you-fly checklist, and what to do if a device is taken. Print it, fold it, put it with your passport.

Open the workbook →
again ↳

This is know-your-rights education, not legal advice. We are a technology studio, not a law firm. Nothing here creates a lawyer-client relationship, and none of it accounts for your situation, your status, or your jurisdiction. Large parts of this area are actively unsettled: we have marked which parts. If you are facing an actual encounter, or deciding whether to refuse one, talk to a lawyer.

↳ the other half of this conversation

We build the other side.

This page is about what you can decline. Our day job is the opposite direction: building platforms that collect less, expose less, and give the people in your database fewer reasons to ever need a page like this.