
The real fight over border phone searches is no longer whether agents can look—it is what they can copy, how long they can keep it, and whether privileged or sensitive material is walled off. Two Floridians’ lawsuits crystallize that shift, forcing courts to confront the digital stakes of a policy built for luggage in an era of smartphones.
The Short Version
- Two Florida residents have gone to court to compel CBP to return their phones and delete any copies of data allegedly taken during airport inspections, using Rule 41(g) as the recovery vehicle.
- CBP’s current directive authorizes basic manual searches without individualized suspicion and advanced forensic searches with reasonable suspicion or a national security concern, plus supervisory approval.
- Agency policy promises guardrails: searches are limited to data resident on the device, not the cloud, and materials flagged as attorney-client privileged should be segregated and handled by a filter process.
- Courts are increasingly scrutinizing copying and prolonged detention of devices—often treating forensic extraction as a non-routine search that requires heightened justification.
What these Florida cases are actually testing
Media accounts report that immigrant advocate Thomas Kennedy and another Florida resident filed suit to recover their phones’ data and to force deletion of any copies CBP allegedly made during border inspections—relief that tracks the long-standing mechanism in Federal Rule of Criminal Procedure 41(g) for the return of seized property. Their claims target the digital heart of border screening: even if an agent may manually scroll through a phone, does the Constitution or CBP policy permit duplicating its contents, including legally privileged or sensitive material, during a short secondary inspection? The procedural hook matters. Rule 41(g) gives a court power to order return and, where appropriate, purge of improperly retained data; litigants increasingly deploy it when a search never ripens into a prosecution but the privacy harm persists in the government’s files.
Coverage of Kennedy’s account describes a secondary inspection in which an agent took his phone for roughly 45 minutes, after which he believes data was copied. The suits seek not only physical return but also deletion of any derivative digital images or extractions. That remedy question—can a court make the government delete copies—sits at the center of modern device-search litigation, where the injury is less a lost handset than a trove of personal communications, location histories, and professional confidences.
CBP’s authority and its internal guardrails
CBP maintains that it has statutory authority to conduct border searches of electronic devices for travelers entering or leaving the United States, and emphasizes that inspections target the data present on a device at the time of examination—not the traveler’s remote cloud content. The agency’s 2026 directive, 3340-049B, formalizes a two-tier structure: “basic” manual reviews the officer can conduct without individualized suspicion, and “advanced” forensic examinations requiring reasonable suspicion of a violation or a national-security concern, plus supervisory approval. This policy framework also extends the definition of “electronic device” beyond phones and laptops to wearables, vehicle infotainment systems, SIM cards, and other digital media—reflecting where personal data now lives.
Crucially for the Florida plaintiffs’ posture, the directive instructs officers who encounter or are told they may encounter attorney–client privileged or work-product material to stop and invoke special procedures: seek clarification, involve a designated filter or segregation process, and consult agency counsel before any substantive review proceeds. On paper, those rules are designed to prevent the very harm Kennedy alleges—sweeping in protected communications during a bulk copy of a device. The litigation implicitly tests not only constitutional boundaries but also whether these internal safeguards work as advertised in a fast-moving secondary inspection line.
Where courts draw the line: manual look versus forensic copy
The border search doctrine has always given the government more latitude at ports of entry; courts have treated routine inspections of persons and effects as reasonable without a warrant. The smartphone changed the calculus. Several courts have differentiated between a manual, on-the-spot look—akin to opening a suitcase—and a forensic extraction that creates a complete image of the device, potentially detained for days or weeks. The latter, many judges have held, is a non-routine search that triggers heightened justification, often at least reasonable suspicion tied to border objectives. Put differently: the deeper and more durable the intrusion, the stronger the government’s reasons must be.
That distinction maps directly onto the relief Kennedy and his co-plaintiff seek. If an officer merely scrolled for contraband, there may be little to purge. If the agency imaged the phone wholesale, the question becomes whether that copying was justified under policy and the Fourth Amendment, and—if not—whether a court should order deletion. Rule 41(g) motions have become the channel for that remedy in cases that never proceed to indictment but leave a digital shadow in government databases.
Privileged and sensitive data: policy promises versus practice
Attorneys, journalists, advocates, and executives carry data that implicates privileges, confidentiality duties, and trade secrets. CBP’s directive addresses that reality by directing officers to segregate asserted privileged material via a filter process, limiting who may review it and for what purpose. For travelers, the promise is straightforward: if you flag privilege, the government will pause and keep those materials siloed. The problem, as these Florida suits frame it, is operational. Secondary inspections unfold quickly; officers are making triage decisions; devices can be whisked away from view. A 45-minute out-of-sight interval, followed by a return of the phone, raises classic questions: was only a basic search performed, or did tools copy a wider dataset? Did a filter team actually segregate anything before an extraction occurred? Litigation is where those operational details are forced into the record.
Even CBP’s position that only “resident” device data may be searched can be messy in practice, given modern app caches and background syncs. The principle is clear—no cloud rummaging through an on-device login—but the boundary between local and remote can blur technically. That is one reason advanced, tool-driven extractions draw scrutiny: they risk sweeping beyond a targeted look to a comprehensive archive susceptible to secondary uses far removed from the initial inspection rationale.
Why these cases matter even if device searches are rare
CBP publicly characterizes device searches as infrequent relative to the volume of travelers. Rarity, however, cuts both ways. It rebuts the claim of mass, routine digital dragnets; at the same time, it means each case can become a vehicle for clarifying national rules. When courts articulate the threshold for a forensic copy or endorse deletion as a remedy for overreach, those holdings ripple through frontline practice and training. The Florida filings are part of a broader trend away from binary “can they search or not?” disputes and toward more granular questions: scope, method, retention, and minimization—especially for privileged data.
Practical guidance for professionals and frequent travelers
Policy and doctrine are evolving, but a few practical points are durable. First, the basic-versus-advanced search distinction is here to stay; tools and prolonged detention signal the latter and, with it, a need for articulated suspicion and supervisory sign-off. Second, if you carry privileged or confidential material, assert that status clearly and specifically; CBP’s own rules contemplate written clarification of the categories at issue and consultation with counsel before review proceeds. Third, understand the “resident data” limitation: disable connectivity, log out of cloud services, and minimize local caches before travel if feasible, which aligns your device posture with policy boundaries. Finally, if a seizure or copy occurs and no charges follow, Rule 41(g) remains a viable pathway to seek the return or deletion of data in civil court, forcing the government to justify retention and the means of acquisition.
The trajectory from here
Expect continued convergence on a few principles. Manual, in-person reviews will remain broadly permissible at the border. Forensic duplication and retention will face sustained judicial pressure to rest on reasonable suspicion tethered to border purposes. Filter protocols for privileged material will migrate from policy soft law to court-enforced requirements, with sanctions—including deletion—when they fail. And as more data lives in cars, wearables, and peripherals, the directive’s broad device definitions will matter as much as the phone in your hand. The Florida lawsuits do not challenge the existence of border authority; they demand that its exercise meet the constitutional scale of modern digital life.
Sources:
reason.com, yahoo.com, bgr.com, ecf.flmd.uscourts.gov, cbp.gov, miaminewtimes.com, adc.org, supremecourt.gov, visaverge.com



