Travel, Borders and hardware the employee owns
Crossing a frontier with a device holding company data raises questions nobody has usually considered, and the device being personal makes them harder rather than easier.
An employee travelling for work carries their own phone and laptop, with company material on them. Several jurisdictions permit inspection of devices at entry, and the arrangement has given no thought to what that means.
The practical lesson in “Travel, Borders and hardware the employee owns” is to connect every record to a named decision. Organisations exploring the software website for task switching cost can add structured workforce context, provided the use is disclosed and interpretation is reviewed with the people affected.
What can happen at a border
Powers vary widely. Some jurisdictions permit examination of devices without suspicion, some can require a passcode, and some may retain a device for a period.
For an independent reference relevant to “Travel, Borders and hardware the employee owns”, consult the ICO employment-practices guidance; compare its principles with the proposed ownership model, access rules and real support process.
What is seen in that examination includes whatever is on the device: the work profile space, where it cannot be opened without credentials, and the personal side, where photographs, messages and personal accounts sit.
Under a company-issued device the exposure is bounded to work material and the employer can prepare a clean machine. Under BYOD the employee's entire personal life is in the same bag.
The employer's position
An organisation sending somebody abroad with company data on a personal device has created an exposure for both parties and usually has no guidance on it.
The minimum is to say something: that this is a consideration, what the organisation would prefer, and what support exists. Most employers say nothing at all, which means each traveller improvises.
What reduces it
Carrying less. Work accessible through a browser rather than synchronised locally means little is resident on the device. The alternatives section treats this properly and travel is one of its strongest arguments.
A loan device for sensitive trips, which is the company-issued answer applied selectively. Cheaper than equipping everybody and it handles the cases that matter.
Signing out before travelling and back in on arrival, which takes a minute and removes the cached material.
And not holding the only copy of anything on a device that might be retained.
The personal side, which is the employee's to consider
An employer cannot instruct somebody about their own photographs and messages. It can point out that the device is theirs, that an examination would include personal material, and that this is a reason to think about what is on it before a particular trip.
That is information rather than instruction, and giving it is reasonable.
Remote access as the alternative to carrying anything
Where the work can be done through a browser on arrival, the device carries nothing and the question largely disappears.
This is the arrangement several organisations arrive at for international travel specifically, having kept BYOD for everything else — and it is a good illustration that the right answer is frequently different for different situations rather than a single policy.
Before the trip rather than after
A short conversation before international travel — what is on the device, what could be removed, whether a loan machine would help — takes ten minutes and is the whole of the mitigation. It happens almost nowhere, because travel is arranged by one function and device questions belong to another, and neither has the trip and the device in view at the same time.
The employee's own exposure
An examination that includes somebody's personal photographs, messages and accounts is an intrusion the employer caused by requiring work on a personal device. Acknowledging that plainly, and offering an alternative for trips where it matters, is a reasonable thing to do and distinguishes an organisation that has thought about the arrangement from one that has not.
A short written position
Two paragraphs on travelling with company data: what to consider, what support exists, who to ask. It costs an hour to write and it is the difference between every traveller improvising and a consistent arrangement, particularly for the people who travel rarely and have never thought about it.
Carrying less as the general answer
Everything that helps with borders also helps with loss, theft and exit: a device holding little is a device that matters less when something happens to it. Travel is simply the situation where the principle is most visible, and an organisation that solves it for travel has usually found the arrangement it should have had generally. Does anybody in your organisation travel internationally with company data on a device you do not own, and has anybody ever discussed it with them?