Warrants, Borders and Geofences: Searching a Phone or Laptop
By the Legal Cyber Academy editorial team ·
Three rules govern most device searches. A phone seized on arrest needs a warrant. Historical cell-site location records from a carrier generally need a warrant. At the border, a manual look is treated differently from a forensic extraction, and the circuits have not agreed on what the forensic search requires. Almost everything else — warrant particularity, how long an image may be kept, geofence requests — is genuinely unsettled.
This article is educational. It is not legal advice, and it is not a substitute for reading the opinions and your own circuit's law.
Why does a phone need a warrant when a wallet does not?
Because the Supreme Court decided a phone is categorically different. Riley v. California holds that police generally may not search the digital contents of a cell phone seized incident to an arrest without a warrant: the search-incident-to-arrest exception rests on officer safety and evidence preservation, and neither rationale extends to the data on a phone.
The reasoning is what gets cited onward, and examiners should know it because it is the analytic move that drives the rest of this area. The Court treated a modern phone as different in kind from the physical items the exception was built around — its storage capacity, the breadth and combination of data types it aggregates, and its reach into records held in the cloud mean a phone search exposes far more than an arrest-scene inventory ever did. Data cannot harm an officer, and the government's remote-wiping and encryption concerns were answered by measures short of a warrantless search. The Court's own summary of the answer was to get a warrant.
For the practitioner, three operational points follow:
- The rule is about the search, not the seizure. Securing the device pending a warrant is a different question from reading it.
- The measures short of a warrantless search — powering off, removing the battery, placing the device in a Faraday bag or an aluminium wrapper — are exactly the steps that appear in ISO/IEC 27037 and the SWGDE mobile device collection guidance. The evidentiary rule and the collection standard point the same way, which is unusual and worth exploiting in a brief.
- "Cloud reach" is part of the constitutional rationale, which means an extraction that pulls synced cloud content is doing something the Court expressly identified as more intrusive than searching a container.
Do carrier location records need a warrant?
For historical cell-site location information, generally yes. Carpenter v. United States holds that the government's acquisition of historical CSLI from a wireless carrier is a Fourth Amendment search generally requiring a warrant, and that an order under the Stored Communications Act's § 2703(d) — which rests on a "reasonable grounds" showing — falls short of probable cause and is not a permissible mechanism for those records.
Two things about Carpenter are routinely overstated. First, the Court declined to extend the third-party doctrine to these records precisely because they are generated automatically, retained cheaply and indefinitely, and map the whole of a person's physical movements — not because carrier records are generally protected. Second, the Court described the decision as narrow and expressly reserved real-time CSLI, tower dumps, conventional surveillance techniques, and national-security collection. If your issue is one of those, Carpenter is a starting point and not an answer.
The pre-Carpenter decisions retain value as history and as a map of what the fight was about, and they should be cited as superseded rather than as law. The Fourth Circuit sitting en banc in United States v. Graham held a user had no reasonable expectation of privacy in historical CSLI held by a carrier. The Eleventh Circuit en banc in United States v. Davis held a § 2703(d) order for historical cell-tower records did not violate the Fourth Amendment. The Fifth Circuit in In re Application of the United States for Historical Cell Site Data held such orders are not per se unconstitutional. Those holdings are inconsistent with Carpenter on the core question.
State constitutions ran ahead in places, and still matter where the state provision is more protective. Commonwealth v. Augustine held under article 14 of the Massachusetts Declaration of Rights that a subscriber has a reasonable expectation of privacy in historical CSLI notwithstanding that it is the carrier's business record, that obtaining two weeks of it was a search requiring a warrant on probable cause, and that a valid § 2703(d) order was not sufficient.
On tracking devices, United States v. Jones holds that attaching a GPS device to a vehicle and using it to monitor the vehicle's movements is a Fourth Amendment search — a physical-trespass-plus-information-gathering rationale distinct from the expectation-of-privacy analysis, and a rationale that does not transfer cleanly to purely digital collection.
What is the rule for email and other provider-held content?
The Sixth Circuit's answer in United States v. Warshak is that a subscriber has a reasonable expectation of privacy in the contents of emails stored with, or sent or received through, a commercial internet service provider, so obtaining them without a warrant violated the Fourth Amendment — and to the extent the Stored Communications Act purports to permit that, it is unconstitutional. The emails were not suppressed, because the agents relied in good faith on the statute.
That good-faith outcome is the pattern to expect in this area: a constitutional holding announced and then not enforced against the officers who acted before it existed. Note also that Warshak is one circuit's holding, and while it is widely followed in practice and reflected in provider policy, the Supreme Court has not decided the question.
The statutory overlay is separate and independently important. The Stored Communications Act and Wiretap Act cases turn on whether a communication was in transit or at rest, which is a technical question with legal consequences. Konop v. Hawaiian Airlines, Inc. holds that for electronic communications, an "intercept" under the Wiretap Act requires acquisition contemporaneous with transmission, so acquiring a secure website's contents after transmission was not an intercept. United States v. Councilman, sitting en banc, holds that intercepting an email while it sits in temporary, transient electronic storage during transmission can state a Wiretap Act offence. And Theofel v. Farey-Jones holds that email left on an ISP's server after delivery is in "electronic storage" as backup-protection storage, so prior access by the recipient is irrelevant to the Act's coverage — and that access obtained through a patently overbroad civil subpoena was "without authorization," because consent procured by deceit is no consent.
What actually happens at the border?
This is the most live split in device-search law, and the honest answer is that the level of suspicion required for a forensic examination is not settled.
| Decision | Manual search | Forensic examination |
|---|---|---|
| Cotterman (9th Cir., en banc) | Not at issue as a separate category | Reasonable suspicion required |
| Kolsuz (4th Cir.) | Routine | Nonroutine; individualized suspicion required, level left open |
| Cano (9th Cir.) | No reasonable suspicion needed | Reasonable suspicion of digital contraband; scope limited to contraband |
| Wanjiku (7th Cir.) | Not decided | Level not decided; good faith applied |
The shape of each holding matters.
United States v. Cotterman holds that reasonable suspicion is required for a forensic examination of a laptop seized at the border, and that it is the comprehensive and intrusive nature of the forensic examination — not where it is carried out — that triggers the requirement. The court rejected both the government's no-suspicion position and the extended-border-search framing, and expected officials to continue conducting forensic examinations where their suspicions were aroused.
United States v. Kolsuz holds that a month-long, off-site forensic examination of a smartphone seized at an airport is a nonroutine border search requiring individualized suspicion, while the manual airport search of the same phone was routine. It declined to resolve whether the required showing is reasonable suspicion or a warrant on probable cause. The privacy-intrusion reasoning is concrete and useful to cite: the extraction produced a nearly 900-page report cataloguing the phone's data.
United States v. Cano goes further on scope, and this is the holding most likely to help a defendant. Manual searches need no reasonable suspicion; forensic searches do, and in this context reasonable suspicion means suspicion that the phone contains digital contraband. Any border search of a phone, manual or forensic, must be limited in scope to looking for digital contraband; a broader search for evidence of a crime is not justified by the border exception. Recording phone numbers from the call log and photographing messages for later processing had no connection to verifying the phone lacked contraband, so those actions exceeded the scope even though opening the call log to check for hidden images did not. Most of the evidence was held to have been suppressible.
United States v. Wanjiku shows the escape hatch. The Seventh Circuit affirmed denial of suppression of evidence from border searches of a phone, laptop and external drive without deciding what level of suspicion such searches require, because agents acted in good faith: they had reasonable suspicion at a time when no court had ever required more than reasonable suspicion for any search at the border.
For an examiner, the practical consequence is that the distinction between a manual review and a forensic extraction is a legal category, not just a workflow choice. Document which one you performed, when the device left the port, what tool was used, and what the extraction actually produced — because in Kolsuz the report's size was part of the constitutional analysis.
How particular must a device warrant be, and how long may the image be kept?
Unsettled, and this is where the most consequential open questions sit.
On retention, United States v. Ganias is the case everyone cites and it decides less than its reputation suggests. The en banc Second Circuit affirmed on the ground that the government relied in good faith on a later warrant when it searched forensic mirror images it had retained for years after the original warrant's scope was exhausted, and expressly declined to decide whether retaining those mirrors violated the Fourth Amendment. It held that a predicate constitutional violation does not automatically foreclose good-faith reliance on a subsequent warrant; the question is whether reliance was objectively reasonable, which requires that the issuing magistrate be told the relevant history. Because the agents disclosed the circumstances, invoking good faith did not launder any earlier illegality.
So: if you are litigating over-retention of a forensic image, Ganias gives you the disclosure requirement and nothing on the merits. Say so rather than overclaiming it.
On geofence warrants — requests that ask a provider to identify every device inside a time-and-place box — there is an express circuit split. United States v. Smith holds that the use of geofence warrants as described in that case is unconstitutional under the Fourth Amendment, expressly parting ways with a contrary Fourth Circuit decision, while nonetheless affirming denial of suppression because law enforcement relied in good faith on a novel warrant type. The court's description of the mechanism is the part examiners should read: a three-step process in which the provider searches its entire location database for devices inside the box, then narrows and de-anonymises — which the court treated as a general search of everyone rather than a particularised search of a suspect.
Standing is a separate and frequently fatal obstacle. United States v. Davis holds that a defendant lacked Fourth Amendment standing to challenge a geofence warrant that returned the location of his girlfriend's phone, because the search disclosed no information about data on his own device; having found no standing, the court did not reach whether the warrant was defective or whether good faith applied. Check whose device the return concerned before drafting the motion.
What should counsel and the examiner do with all this?
The unglamorous answer is that most of these issues are won or lost on the record about what was actually done to the device, and that record is the examiner's output.
- Distinguish seizure from search in the timeline, with times and dates.
- State the extraction type by name — manual review, logical extraction, file-system extraction, physical image — and what each produced. The legal categories in the border cases track these distinctions.
- Record whether the extraction reached synced cloud content, because that is a different constitutional footprint than on-device data.
- Record how long an image has been retained, under what authority, and whether any subsequent warrant application disclosed its existence. That is the Ganias disclosure point, and it is actionable.
- Do not offer a legal conclusion in the report. The examiner's job is to establish what happened to the data; whether it was a routine or nonroutine search is the court's.
For counsel coming to this from the legal side, the DOJ CCIPS manual on searching and seizing computers is the single most useful reference because it states the government's own position, and the Digital Forensics for Lawyers track and The Digital Verdict: Mastering Smartphone Evidence in the Courtroom cover the device mechanics that these doctrinal categories rest on.
Go deeper — courses on this
Digital ForensicsThe Digital Verdict: Guide to Mastering Smartphone Evidence in the Courtroom
This seminar examines how smartphone data is handled under the Federal Rules of Civil Procedure and…
Daniel B. Garrie · 1h 1m
Digital ForensicsFrom Feed to Evidence: A Lawyer's Guide to Authenticating Social Media Posts
This course covers how social media data functions as litigation evidence, including how to access…
Daniel B. Garrie · 1h 1m
FreeDigital Forensics(Digital) Forensic Files: Computer Forensics (Part 2 of 2)
Part 2 of a two-part seminar covering how digital forensics reports are structured and produced, what…
Daniel B. Garrie
Keep reading
- Write Blocking, Imaging Formats and Verification That Holds UpAcquisition is the most attacked and least defended part of an examination, because the defence has to be built before the analysis starts.
- Why a Timestamp Is an Assertion, Not a FactFour independent places for a timestamp to be wrong: the clock, the encoding, the time zone, and what the event actually was.
- Where $MFT, $LogFile and $UsnJrnl DisagreeThree NTFS structures record file activity and none of them records the same thing. The disagreements between them are usually the finding.
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.