A practical digital checklist before international travel.

The useful preparation is rarely dramatic. Make essential information work offline, remove data you do not need to carry, and test how you would recover your accounts if the phone or SIM disappeared.

72 hours before departure: make the phone work offline

A travel phone has two jobs: help you reach the next place and help you recover when something goes wrong. Start with those jobs. Downloading a pile of entertainment, buying a second device, or changing every privacy setting can wait until the basics work.

Do this while you are still on your normal network. Open each saved item, sign in to the accounts that matter, and make one deliberate test with Wi-Fi and mobile data disabled. A file that only exists behind an expired web session is not an offline copy.

  • Download an offline map for the area around your airport, hotel, and first meeting point.
  • Save the hotel address in English and the local language, plus a phone number that can be dialled without opening a booking app.
  • Keep airline, rail, hotel, insurance, visa, and itinerary documents available offline. Open every file once before departure.
  • Check which important accounts still send sign-in codes only to your home mobile number. Banks and your primary email deserve attention first.
  • Generate fresh recovery codes where the service offers them. Keep them separate from the password they recover.
  • If you use an authenticator, turn on airplane mode and confirm that current codes still appear. Reconnect before completing a real sign-in.
  • Confirm that a trusted second device or another recovery method can reach your primary email account.
  • Write down the correct numbers for freezing your mobile service and payment cards. Do not assume you will be able to search for them later.
  • Remove old client files, unneeded identity scans, private screenshots, and downloaded mail that have no purpose on this trip.
  • Keep only the document copies you actually expect to use, and place them somewhere protected rather than loose in Photos or Downloads.
  • Verify one recent backup by checking that the expected files are present. A green backup icon is not the same as a tested recovery path.
  • Install operating-system and essential app updates early enough to recover if an update causes trouble, then confirm the phone still works offline.

24 hours before departure: remove the single points of failure

A travel eSIM usually solves data access. It does not automatically solve account recovery. Before leaving, note the critical accounts that still send every sign-in code to your home number, and add one independent recovery method where the service allows it.

This checklist deliberately stops there. Moving an authenticator or changing recovery settings deserves a separate, careful test while the old method still works; the companion 2FA guide covers that process in detail.

  • Start with the primary email and any bank or work account you will need during the trip.
  • Keep the home SIM and old sign-in method active until the replacement has passed a real sign-in test.
  • Keep recovery codes away from the password and away from the only phone you are carrying.

Before leaving: carry less without breaking the trip

Deleting everything is not a practical privacy plan. It can remove the very documents needed at a border, hotel, clinic, or airline desk. The better question is purpose: what information will this device need during this trip, and what can safely remain at home or in a verified backup?

Review photos, downloads, message attachments, locally cached email, shared cloud folders, work chat, browser tabs, and document-scanning apps. Old scans and screenshots are easy to forget because they are not part of the current trip. Remove them only after confirming that an appropriate backup exists and that removal does not conflict with work, legal, or travel requirements.

Use a strong device passcode and know how to report the device lost. Biometrics are convenient, but laws and procedures around device access vary. Do not rely on a hidden interface or a single app as a promise that data cannot be discovered. If the consequences are serious, seek current legal advice for the countries involved.

  • Use a strong device passcode and shorten the automatic lock interval before departure.
  • Review what the lock screen reveals from messages, email, calendars, and travel notifications.
  • Know the official lost-device and carrier suspension process before the device is missing.
  • Keep irreplaceable information in a tested backup, not only in a private local vault.
  • Treat any exported QR code or plain document copy as sensitive from the moment it leaves its protected store.
  • Pack one known-good charging cable and the plug adapter you need. A secure phone with no power is still unavailable.

Primary sources worth reading

These are the sources behind the checklist. Read the current guidance rather than relying on a dramatic second-hand story.

CANADA

Cyber security while travelling

Government of Canada guidance on reducing device data, backups, public networks, loss, and border searches.

Read the guidance →
EFF

Digital privacy at the U.S. border

A practical guide to threat modelling, legal uncertainty, and preparation before crossing the U.S. border.

Read the guide →
U.S. STATE DEPARTMENT

Communication while abroad

Official planning notes for mobile service, local SIMs, Wi-Fi, emergency contact, and communication failures overseas.

Review the advice →
CISA

Choose stronger authentication

A useful hierarchy for security keys, number matching, authenticator codes, and SMS or email verification.

Compare MFA methods →

Questions that come up before departure

Short answers for the decisions that tend to get postponed.

Should I buy a second phone for travel?

Sometimes, but not automatically. A travel-only device can reduce exposure when the trip or work genuinely warrants it. It also creates setup, update, recovery, and availability work. Start by reducing unneeded data and testing recovery on the device you will actually carry.

Is storing a passport copy on a phone safe?

It is a trade-off. An offline copy can be useful after loss or at a desk without connectivity, but it is sensitive. Keep only what you need, use protected storage, retain a separate verified backup, and follow the requirements of the destination and document issuer.

Will an authenticator work without roaming?

Standard time-based codes are generated on the device and normally appear offline when the device clock is correct. Sign-in still needs a connection and may impose other checks. Verify that codes appear in airplane mode, then reconnect and complete a real sign-in before leaving.

Does a private vault make data undiscoverable?

No such promise should be made. A vault can reduce casual exposure and organize protected local data. Device backups, exports, temporary files, credentials, physical access, forensic tools, and legal process create separate risks.

One item deserves its own check: account recovery.

Use the companion guide to review passkeys, offline authenticator codes, exports, and recovery methods before a SIM change or trip.

Continue to the offline 2FA guide