Hong Kong: when refusing to hand over your password becomes a confession
Since 23 March 2026, Hong Kong police can demand the password of any device, and refusal is a criminal offence. An extension written into the national security law, one that also targets third parties and reaches passengers simply in transit.

You are in transit at Hong Kong airport. You do not even leave the international zone. A police officer stops you, points at your phone and asks for your passcode. Not because you have done anything. Not because a judge has signed anything. Simply because he can. And since 23 March 2026, if you refuse, you are a criminal.
This is not fiction. It is the latest extension of the implementation rules under Hong Kong's national security law. Police can now compel anyone suspected of endangering national security to hand over their password, their decryption method, or any assistance deemed "reasonable and necessary" to access the contents of their devices. The word "anyone" is to be read broadly: the suspect, but also whoever holds, controls or knows the password. A colleague. A relative. A former user. Refusal carries a year in prison and a 100,000 Hong Kong dollar fine. Providing false information, up to three years and 500,000 Hong Kong dollars.
1 year in prison + HK$100,000Penalty for refusing to hand over your passwordImplementation rules under Hong Kong's national security law (in force since 23 March 2026)The American consulate did not miss the point. On 26 March, it issued an unambiguous alert: this rule applies to everyone, including American citizens, including passengers simply in transit, and the authorities now hold an expanded power to seize and retain devices as soon as they see a link with national security. Beijing responded within hours, summoning the American consul general to convey its "strong dissatisfaction and firm opposition" and to demand an end to any interference in the affairs of Hong Kong and China. That sequence alone says how much is at stake.
Should you still transit through Hong Kong for work?
For anyone who travels regularly across the Asia-Pacific region, Hong Kong was until now an obvious point of passage. One of the most connected air hubs in the world, a natural stopover between Europe and Southeast Asia. That is over, or at the very least it has become a calculation. If you are a consultant, an auditor, a lawyer, if you work in finance, tech or compliance, your laptop holds information covered by confidentiality agreements, client data, internal strategies, exchanges with regulators. Your phone holds your encrypted messaging apps, your authenticators, your VPN access. All of it can now be demanded of you in Hong Kong, and you have no right to say no.
The question is no longer posed in the abstract terms of digital liberties. It comes up on a Tuesday morning, when you book a flight with a stopover and have to decide whether passing through Hong Kong territory is worth the risk of exposing the data of your employer, your clients or your partners. Some companies have already started to make the call. A few are banning Hong Kong transits for staff carrying sensitive data. Others require blank phones dedicated to the trip, with cloud sync disabled and data stored remotely. These are pragmatic responses, but they say something about the state of the world when an airport becomes a point of legal vulnerability.

Is searching a phone at the border already common practice?
It would be a mistake to believe that device searches at the border are an Asian peculiarity. In the United States, border officers inspected 55,318 electronic devices in fiscal year 2025, against 47,047 the year before and 41,767 two years earlier, an increase of roughly 66 per cent since 2018. The curve is not coming back down, it is climbing. Everywhere, the traveller crossing a border is increasingly seen as a carrier of data to be examined rather than a person to be let through.
The difference lies in a line Hong Kong has just erased. The American agency's doctrine forbids its officers from accessing data stored only in the cloud and requires the device to be switched to airplane mode during the inspection: you look at what is on the phone, not at what lives on the servers behind it. A directive issued in January 2026 even restated in black and white that officers could not use a device to reach remotely held data. By demanding the password and the decryption method, Hong Kong reaches precisely what the American regime still forbids itself to touch, and turns mere refusal into a criminal offence. Where the American text draws a perimeter, the Hong Kong rules set none. This is no longer a digital baggage search, it is an obligation to collaborate in your own stripping down.
What Hong Kong owns openly, others are preparing in silence
You could treat this as a Hong Kong problem. One more authoritarian slide in a territory where civil society's room to manoeuvre has been shrinking since 2020. That would be convenient. It would also be dishonest.
Because the principle that has just been written into law in Hong Kong, namely that encryption is an obstacle to be removed and that digital silence is suspect, is not a Chinese idea. It is an idea that has been circulating in most Western capitals for twenty years. The difference is that Hong Kong has stopped pretending.
In the United Kingdom, the Online Safety Act passed in 2023 gives the regulator Ofcom the power to require platforms to scan encrypted messages in order to detect illegal content. The British government actually used that lever in early 2025, serving Apple with a secret "technical capability notice" demanding access to end-to-end encrypted iCloud data. Apple chose to withdraw its Advanced Data Protection feature from the British market rather than comply. In August 2025, after several months of American pressure, London announced it was dropping its demand for access to the data of American citizens, without withdrawing the notice issued under the Investigatory Powers Act. The measure has not disappeared, it has retreated onto a narrower perimeter.
At the European level, the "Chat Control" project keeps coming back to the table: since 2022 the European Commission has been pushing to force messaging platforms to run automated scanning of communications, including encrypted ones, in the name of the fight against child abuse. On 9 July 2026, a majority of members of the European Parliament, 314 against 276 with 17 abstentions, voted to reject the extension of the detection regime, without reaching the 361 votes of the absolute majority required at second reading. With the threshold unmet, the scanning of communications is extended until 2028, or until agreement is reached on a permanent regulation. End-to-end encrypted messaging was set aside, and negotiation of the permanent text resumes in September. The project is not buried. It mutates, it comes back under other names, it waits for the right news story to resurface.
In France, the debate turned concrete in 2025, during discussions on the anti-narcotics law. Amendments proposed to require providers of encrypted messaging services to install access mechanisms for the intelligence services. The word "backdoor" was never uttered officially, but that is exactly what it was. On 20 March 2025, against the forceful advice of Interior Minister Bruno Retailleau, the National Assembly rejected the article that would have obliged messaging services to open up the content of correspondence in the clear, ANSSI having described the approach as dangerous. The agency that guards the security of the state's information systems restated what every cybersecurity professional knows: a backdoor created for the state is a backdoor usable by anyone else.
Can a backdoor stay reserved for the good guys?
And that is not a theoretical claim. In 2015, security researchers discovered that a backdoor had been inserted into the firmware of Juniper Networks equipment. The flaw came down to a rigged random number generator, Dual EC, one parameter of which had been quietly modified. For years, that backdoor, most likely planted by a state intelligence service, made it possible to decrypt VPN connections without anyone knowing. When it was discovered, it was impossible to determine with certainty who had benefited from it, or how many actors had had time to exploit it. The Juniper affair became the textbook case that advocates of strong encryption cite systematically, and for good reason: it demonstrates in practice, not in theory, that there is no such thing as a vulnerability reserved for the good guys.

The French paradox
And this is where the French position becomes hard to ignore. On one side, France is struggling to transpose NIS2 on schedule, pushing back its deadlines, leaving its organisations in a regulatory fog that weakens the whole ecosystem. On the other, it finds the time to hold serious discussions about weakening encryption. We cannot manage to impose the basics of digital hygiene on companies and public bodies, yet we contemplate punching holes in the walls of those who have made the effort to protect themselves. There is something in this sequence that looks less like a strategy than like confusion about what "security" means.
Does the "not at random" guarantee really hold?
Hong Kong's Secretary for Security, Chris Tang, wanted to reassure. On 26 March, he called false and misleading the account according to which police could stop anyone in the street and demand their password, recalling that officers first had to obtain a warrant issued by a magistrate and backed by a national security reason.
That clarification has two limits. First, the rules themselves provide for warrantless searches in certain circumstances the text does not specify, and the power expressly targets any person present in Hong Kong, including passengers simply in transit. A legal scholar at the University of Hong Kong, Urania Chiu, judged these powers manifestly disproportionate in light of their stated objectives, precisely because they are exercised without any prior judicial review. Second, and above all, that guarantee is worth only as much as the definition of "national security" is worth. In the post-2020 Hong Kong context, that definition encompasses dissent, critical journalism and sometimes the mere expression of an opinion. It is anything but abstract: by the time these rules were published, 386 people had already been arrested for endangering national security, and 176 people together with four companies had been convicted. When the perimeter of the threat is that broad, the guarantee is no longer one.
The mechanism, moreover, is remarkably clean. You are not physically coerced. You are placed before a choice whose two branches lead to the same place: hand over your data or be prosecuted. It is legal, administrative, and perfectly calibrated so that most people comply without even realising they had an alternative. This is not brute coercion. It is a system that has understood that voluntary compliance costs less than repression.
The signal
Hong Kong is not inventing anything. Hong Kong is accelerating. What is happening there is not an authoritarian anomaly. It is a full-scale test of what many governments are considering without daring to spell it out so clearly. The criminalisation of refusal to decrypt, the absence of genuinely binding judicial review, the extension to third parties: each of these elements exists as a proposal or a temptation in at least one Western democracy.
France would do well to look at Hong Kong not as a convenient foil, but as an uncomfortable mirror. You cannot at once claim to be building an ambitious European cybersecurity framework and flirt with the idea that encryption is a problem to be solved rather than a protection to be defended. A choice will have to be made.
Sources
- Amendment of the national security law implementation rules of 23 March 2026, extension to third parties and penalties incurred: Hong Kong Free Press and Al Jazeera, 23 and 24 March 2026.
- Absence of judicial review judged manifestly disproportionate by legal scholar Urania Chiu, and tally of 386 arrests and 176 convictions for endangering national security: Al Jazeera, 24 March 2026.
- Chris Tang's clarification, false and misleading, and the warrant requirement: Hong Kong Free Press, 26 March 2026.
- Application to passengers in transit, the warrantless search exception and device searches at the American border (55,318 in fiscal year 2025, against 47,047 and 41,767 in the previous years, roughly 66 per cent more than in 2018; ban on cloud access, mandatory airplane mode and the January 2026 CBP directive on remotely held data; absence of any equivalent limit on the Hong Kong side): Mayer Brown, April 2026.
- American consulate alert, power to seize devices and Beijing's protest (summoning of the consul general, strong dissatisfaction and firm opposition): Consulate General of the United States in Hong Kong and Macau, 26 March 2026; Seoul Economic Daily, 30 March 2026.
- Apple and the United Kingdom, withdrawal of Advanced Data Protection then partial dropping of the demand: CNN, 25 February 2025; Bloomberg, 19 August 2025.
- Chat Control, vote of 9 July 2026 (314 against 276, 17 abstentions, threshold of 361 not reached) and extension of detection until 2028: Patrick Breyer.
- Anti-narcotics law, rejection of access to encrypted messaging on 20 March 2025 and ANSSI's opinion: LCP and Futura-Sciences.
- Juniper affair (2015), backdoor in ScreenOS and decryption of VPN connections: Rapid7, 20 December 2015.
Frequently asked questions
Who can be forced to hand over their password in Hong Kong?
Anyone suspected of endangering national security, but also whoever holds, controls or knows the password: a colleague, a relative or a former user of the device.
What is the penalty for refusing?
A year in prison and a 100,000 Hong Kong dollar fine for refusal, and up to three years and 500,000 Hong Kong dollars for providing false or misleading information.
Is a warrant needed before you are asked for your password?
Secretary for Security Chris Tang stated on 26 March 2026 that police first had to obtain a warrant issued by a magistrate and backed by a national security reason. The rules nevertheless allow warrantless searches in certain unspecified circumstances, and a legal scholar at the University of Hong Kong called these powers manifestly disproportionate for lack of any prior judicial review.
Does the rule apply to travellers simply in transit?
Yes. On 26 March 2026 the American consulate issued an alert stating that it applies to everyone, including foreign nationals and passengers simply in transit within the airport's international zone, and that the authorities may seize and retain devices.
Do the United States or Europe also search phones at the border?
Yes, and the volume is rising: American border officers searched 55,318 devices in fiscal year 2025, against 47,047 the year before, roughly 66 per cent more than in 2018. The difference is that their doctrine, restated in a January 2026 directive, forbids access to data stored only in the cloud and requires airplane mode during the inspection, whereas Hong Kong demands the decryption method, sets no limit on the scope inspected and makes refusal a criminal offence.
How can you limit the risk when you have to pass through Hong Kong?
The corporate responses observed are pragmatic: banning Hong Kong transits for staff carrying sensitive data, or issuing blank travel-only devices with cloud sync disabled and data stored remotely. The calculation now starts the moment you book a flight with a stopover.
Is this a Hong Kong peculiarity?
No. The same principle of weakening encryption exists as a proposal or a temptation in several Western democracies: the Online Safety Act in the United Kingdom, the Chat Control project in the EU, narcotics-trafficking amendments in France. Hong Kong has simply stopped pretending.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
