

![]()
Three weeks later, something surfaces on the company’s network.
No one makes the connection, because there is no alert for this kind of event.
The breach didn’t occur at headquarters. It arrived in a suitcase, and you were the one who had sent that suitcase to fetch him.
This is the blind spot that our profession prefers not to talk about.
We have built a duty of protection that stops at the traveler’s skin. We insure him against car accidents, guarantee hospital care, we craft impeccable repatriation procedures, and at the same time we let them cross borders that copy their equipment with no scruple, without briefing, without a dedicated device, without the slightest written trace of what we did to prevent it.
The only baggage that is truly valuable, the one containing contracts, client files, and the company’s intellectual property, is precisely the one that no one thinks to protect.
The legal dimension of the duty to protect
ISO 31030, the reference standard for travel risk management, the one your teams cite in meetings to check the box, explicitly places data, equipment and the company’s intellectual property among travel-related risks.
The text doesn’t talk only about health or physical safety. It talks about information. And it reminds us of a point we often forget: the duty to protect has a legal dimension, which can arise from negligence, contract, or the law, and courts have already ruled against employers who did not uphold it.
Put plainly, deliberately sending someone into an environment where we know their data will be siphoned, without doing anything to prepare for it isn’t chance when things go wrong. It is a fault.
I’ll be told this is specialist paranoia. But the problem isn’t in the “exotic” countries we no longer use; it sits in destinations where you send people every month.
The phone, luggage like any other
It authorizes inspections of baggage and electronic devices, and the authorities have tools to extract the contents of a phone seized at a checkpoint.
The U.S. State Department now warns its nationals to expect on-site digital privacy to be almost non-existent. This isn’t just a theoretical worry: some European pharmaceutical inspectors have already reduced or suspended factory visits in China, fearing their own data could be collected under this law.
When professionals start to forego travel, the risk stops being theoretical.
Hong Kong, in particular, has removed the last reflex many still relied on: refusal. Since March 23, 2026, the police can compel anyone they suspect of threatening national security to hand over their password or decryption key, without a warrant, including a simple transit passenger who never even leaves the international zone.
And refusal is no longer neutral: it has become a crime in itself, punishable by up to a year in prison, where digital silence now amounts to an admission.
The American consulate alerted its citizens the day after. Several companies have already decided, removing Hong Kong from routes for employees carrying sensitive data or requiring them to use pristine phones.
When a hub as connected as one of the world’s busiest airports abandons its flight plans, this is not a posture, it’s a risk calculation.
And let’s not delude ourselves into thinking this only targets authoritarian regimes.
In the United Kingdom, an officer can, under anti-terrorism legislation, detain you for several hours and demand access to your device without a shred of suspicion.
In Canada, you are required to hand over your passwords on demand.
In New Zealand, refusal is met with a fine.
In the United States, customs inspect devices at entry, manually and without justification, intensified whenever a suspicion arises.
The phone has become baggage like any other, something that can be opened and copied, and this isn’t limited to the countries we point to. The excuse of exoticism no longer exists.
