Subscribe for free: compensation & pay equity law review
You'll receive a weekly newsletter email with the most important legal news on compensation and pay equity. We handle your contact details in line with our Privacy Policy
Editor's Note
Protecting Data While Employees Travel
As a lawyer, I figured I was pretty knowledgeable about protecting data on the road. I know you don't hook into public Wi-Fi. I have and know how to use a VPN. And I would never plug in a USB drive I did not know the origins and contents of.
Even so, I learned a lot from this article from Fisher Phillips. It's a helpful refresher for understanding the risks, the limits of legal protections—especially at borders, and how to protect confidential and proprietary data.
The most important thing is not the tech though. It's the people. You can have the best tech and security available, but it's worthless if people don't use it. The tech can't help you if people aren't trained to protect their devices and what people can see or access when employees are using them.
It's also essential to educate people about personal apps and sites that may allow unintended access to company data. And this is not a one and done training issue. Data security requires a regular cadence of training and updates, especially whenever tech changes or new threats are discovered.
Last, this information on keeping your data secure is really good to know even when you are traveling inside the US or for fun. It's a different world out there now and we all need to be more aware and careful.
- Heather Bussing
by David Jones
International travel may pose serious data security risks – especially for your foreign national workers carrying sensitive, proprietary, or regulated information. Travelers must be aware of potential border inspections, surveillance practices abroad, and export control regulations that may impact their devices and data. What does your organization need to know about these significant risks, and what can employers do to safeguard their information?
In countries like the United States, border agents can inspect electronic devices without a warrant or suspicion of wrongdoing. While the Fourth Amendment protects against unreasonable searches, this protection does not fully apply to searches at the U.S. border.
Searches can range from viewing accessible content on an unlocked device to requesting passwords, accessing encrypted files, or copying data for forensic review. And it’s not just foreign nationals subject to these searches. U.S. citizens and permanent residents are also subject to these inspections, even when entering lawfully. This is why professionals carrying confidential information should take extra precautions, as your company data may be accessed or copied – and your workers could be detained.
But it’s not just border searches that can lead to loss of data. Once inside a country, travelers – especially foreign nationals – may face a range of digital security threats that go beyond airport inspections.
Network surveillance is common in many regions, particularly when using public Wi-Fi in hotels, airports, or cafes, where communications can be intercepted or monitored without the user’s knowledge.
In addition to state-sponsored monitoring, cyber criminals often exploit these same environments, targeting unsecured connections to steal sensitive data, login credentials, or financial information. Travelers unaware of these risks may become easy targets for man-in-the-middle attacks or malware installations, especially when using outdated software or unsecured devices.
Carrying certain data, software, or technologies abroad may trigger export control laws, especially in fields like defense, technology, and pharmaceuticals. Even encrypted files on a laptop can violate export laws if shared or accessed abroad. In the U.S., laws like ITAR and EAR impose serious penalties for violations.
Professionals in law, research, journalism, and academia may be ethically or legally obligated to protect sensitive data. A New York State Bar ethics opinion, for example, concludes that attorneys must take “reasonable precautions” to avoid ethical breaches at borders. Third-party access of devices may also constitute a data breach that would require disclosure.
Here are some recommended safeguards to help avoid a security breach or device access when your workers travel internationally:
In an era of digital mobility, data protection is essential. By preparing properly – through encryption, legal awareness, and secure data practices – foreign nationals can reduce their risk and travel with confidence.
You'll receive a weekly newsletter email with the most important legal news on compensation and pay equity. We handle your contact details in line with our Privacy Policy
CompAnalyst® Pay Equity Suite can help you achieve and sustain pay equity