Travel privacy kit: protect your phone, accounts and identity on the road
Malware / security. Updated 2026-09-13. About 5 minutes to read.
Before you fly, move your important accounts from text message codes to an authenticator app or passkey, so losing your phone or SIM abroad does not lock you out.
Most travel privacy problems are ordinary: a phone stolen at a bar, a card skimmed at a kiosk, a fake booking message, or being locked out of your bank because the text code went to a SIM you left at home. Border device searches get the headlines, but they are rare. US Customs and Border Protection searched the devices of 55,318 travelers in fiscal year 2025, out of more than 419 million it processed.
This kit covers the 30-minute setup before you leave, what to expect at a border, how to choose between roaming, a local SIM and an eSIM, and the hotel and airport habits that prevent most losses.
Before you leave: a 30-minute device setup
Update your phone, laptop and apps, and back up both devices.
Use a six-digit or longer passcode, and hide message previews on the lock screen.
Turn on Find My on Apple devices or Find My Device on Android, and check you can sign in to it from another device.
Set up an authenticator app or passkeys for email, banking and your password manager. Save backup codes somewhere you can reach without your phone.
Add a port-out or SIM lock with your carrier so nobody can move your number while you are away.
On iPhone, turn on Stolen Device Protection, which adds a biometric check and delay for sensitive changes away from familiar locations.
Save your bank's international phone number and card issuer number offline, and turn on transaction alerts.
At the border: what officers can do
In the US, CBP can inspect electronic devices of anyone entering or leaving, citizen or not. A basic search is a manual look through the device. An advanced search, where equipment is connected to copy or analyse contents, requires reasonable suspicion and approval from a senior manager. Of the 55,318 device searches in fiscal 2025, 92 percent were basic.
CBP officers must disable network connectivity and may not use your device to access information stored only remotely, such as cloud email. If you do not unlock a device, foreign nationals may be refused entry, and US citizens will not be denied entry but may face delays and the device may be detained. Australia, Canada and the UK also give border officers powers to examine devices.
Do not lie to a border officer or delete data in front of them. That creates bigger problems than a search. If you carry legally privileged or confidential work material, tell the officer before the search begins.
Carry less so there is less to lose
Sign out of apps you will not need, especially work email and file storage, and sign back in when you arrive.
Leave spare cards, your Social Security or tax number documents and old devices at home.
Keep a scan of your passport in an encrypted password manager rather than your photo roll.
Power devices fully off before a border crossing or when leaving them in a hotel room. A switched-off phone needs the passcode, not a face or fingerprint.
Consider a separate travel laptop or a fresh user account with only what you need for the trip.
Roaming, local SIM or travel eSIM
Roaming: the simplest option, and you keep receiving calls and text codes on your normal number. Check your carrier's daily rate first.
Travel eSIM for data: a data-only eSIM from an app or website runs alongside your home SIM on most recent phones, so your number stays active for codes. Install it only through the provider's official app or site.
Local physical SIM: often the cheapest for long stays, but many countries require a passport to register it, and swapping out your home SIM means text codes stop arriving.
Keep your home SIM in the phone, or in a safe place with a note of its PIN, and set a SIM PIN so a stolen phone's SIM cannot be used elsewhere.
Hotel and airport habits
Treat messages saying your booking will be cancelled unless you re-enter card details as a scam, even inside a booking app chat. Call the hotel on the number from its own website.
Use your own charger in a wall socket or a power bank rather than unknown USB ports.
Sign out of streaming apps on hotel TVs before checkout.
Do not log in to email or banking on hotel business centre computers.
Keep your home address off luggage tags. A phone number and email are enough.
Do not post boarding passes, which carry a barcode with your booking details.
Follow the public Wi-Fi rules: confirm the network name, never enter account passwords into login portals, and use mobile data for banking.
If a device is lost or stolen abroad
Mark it as lost in Find My or Find My Device, which locks it and shows a contact message.
Call your carrier to suspend the SIM so text codes cannot be received by the thief.
Change your email password from another device, then your banking and password manager.
Call your bank and card issuers on the saved international numbers.
Get a police report number for insurance, and erase the device remotely if it is not recovered.
Frequently asked questions
Can US border officers look through my phone?
Yes, CBP has authority to search devices at the border, though it happened to fewer than 0.01 percent of arriving travelers in fiscal 2025. Officers may not use the device to access data stored only in the cloud.
Is a travel eSIM safer than roaming?
Neither is inherently less private. A data eSIM is usually cheaper and keeps your home number active for codes. Roaming is simpler. Avoid removing your home SIM if you rely on text message codes.
Do I need a VPN when travelling?
It helps on hotel and airport networks and in countries with heavy network monitoring, but check local laws first. A VPN does not replace two-factor authentication or careful handling of login pages.
Should I take a burner phone abroad?
For most trips, no. A well-set-up main phone with backups is easier. A separate phone makes sense for high-risk destinations, sensitive work, or if you do not want your main device examined.