Senator Ron Wyden reveals the CBP told Congress it adds data from ~10K travelers' devices per year to a database, accessible by 2,700 officers without a warrant
Washington PostDrew Harwell
Context & Ripple Effects
Wyden has been pulling this thread for years: CBP's own letters to him in 2017 conceded it lacked authority to reach travelers' cloud accounts at the border while claiming free rein over local device data, and by 2019 the agency was reporting 30,000 warrantless device searches in a single year, up roughly fourfold from three years prior. The new disclosure changes the shape of the problem: what was framed as an episodic inspection at the border is now a standing pipeline, with data from roughly 10,000 travelers' devices per year flowing into a database any of 2,700 officers can query without a warrant.
First-order effects
Travelers whose devices are searched no longer face a one-time extraction — their data persists in a CBP database where 2,700 officers can access it indefinitely without individual warrants or probable cause tied to each query.
Second-order effects
The database converts CBP's 2017 position — local data fair game, cloud off-limits — into de facto bulk retention, handing Wyden and allies a concrete target alongside the CIA bulk collection program he and Heinrich exposed earlier this year as Congress weighs warrant requirements for agency-held Americans' data.
Third-order effects
If the pattern holds, border-search authority becomes a back door to domestic surveillance infrastructure: agencies argue each step (local search, retention, broad internal access) is lawful in isolation while the aggregate functions as a warrantless database — pushing the fight toward legislation like the authorization riders Wyden flagged in 2016 and court challenges over Fourth Amendment scope.
The trend: Border device searches are drifting from case-by-case inspections into standing warrantless databases, with Wyden's disclosures serving as the primary oversight mechanism forcing the issue into Congress.
New: The government has a giant database of info taken from the phones of “suspicious” travelers at airports and borders. Data from up to 10,000 phones - call logs, contacts, messages - is added each year; kept for 15 years; and searchable for CBP staff https://www.washingtonpost…
It has always been my policy that when I travel overseas, I carry a cheap / disposable cell phone and ensure that it is wiped any time I cross a border. I also recommend leaving computers at home and bringing a “throwaway” device. https://www.msn.com/...
CBP's response indicates agents can search this data—w/o reasonable suspicion—using automated targeting. In practice this would potentially involve running contact lists from ~10K phones each year through an array of govt databases, including FBI's. Millions of names. No warrant.…
@drewharwell OMG. Automated Targeting System again. I'm having flashbacks to 2006, when this first raised major privacy issues: https://www.washingtonpost.com/ ...
Borders are rights-free, data vacuum cleaning zones. Customs officials have copied Americans' phone data at massive scale https://www.washingtonpost.com/ ...
I uncovered that customs and border officials are storing a massive trove of data from the personal devices of Americans who reenter the country. This is an egregious violation of Americans' rights. I won't stop fighting to hold the government accountable for its overreach. https…
3/ The privacy activists focused exclusively on the privacy threats presented by programmatic advertising, no matter how merely theoretical, remind me of the misinfo/disinfo researchers that only investigate social media and not cable news.
Seems like the sorta thing @RonWyden has been talking about for many, many years, and which the rest of Congress regularly ignores... https://twitter.com/...
U.S. government officials are adding data from as many as 10,000 electronic devices each year to a massive database they've compiled from cellphones, iPads and computers seized from travelers at the country's airports, seaports and border crossings. https://www.washingtonpost.com…
There is absolutely no reason for the Fourth Amendment that exists for border searches to apply to phones and other electronic devices @RonWyden has been pushing the Protecting Data at the Border Act for years to fix this problem - this type of abuse is the reason we need to act …
“...the threshold for such searches is so low that the authorities could end up grabbing data from 'a lot of people in addition to potential “bad guys,"'with some 'targeted because they look a certain way or have a certain religion.'" 👀 https://www.washingtonpost.com/ ...
“CBP should not dump data obtained through thousands of warrantless phone searches into a central database, retain the data for fifteen years, and allow thousands of DHS employees to search through Americans' personal data whenever they want.” @RonWyden https://www.wyden.senate.g…
Contacts, call logs, messages and photos from up to 10,000 travelers' phones are saved to a government database every year, and 2,700 CBP officers can access it without a warrant. This is not a reasonable search process. https://www.washingtonpost.com/ ...
The USG has a database of info taken from travelers' phones at checkpoints, with the default to download contacts, call logs & messages—and they're adding up to 10K travelers' info annually. CBP officers can search without a warrant. @drewharwell reports https://www.washingtonpos…
2/ An instructive thought experiment: if we know someone was convicted of a crime via smartphone-scoped data, is it more likely that 1) the data was aggregated via the advertising bidstream, or 2) police simply confiscated the phone and looked through it? https://www.washingtonpo…
Yes, programmatic advertising creates a privacy liability, but it can be rectified with focused remedies that wont devitalize the internet economy, vs “banning surveillance capitalism.” What Id ask privacy activists: why arent you more concerned with this? https://www.washingtonp…