Research checked: August 24, 2026
Taking a company laptop abroad can look simple: put it in your carry-on, connect to Wi-Fi and continue working.
In practice, an employer-issued laptop is more than travel luggage.
It may be:
-
A corporate asset.
-
A gateway to internal company systems.
-
A storage location for confidential, personal or regulated information.
-
A device containing encryption, software or technical information that can be subject to export-control rules.
-
A device that may be inspected by border authorities under the laws of the country you are entering or leaving.
That means employer approval is important, but approval alone does not settle every legal or compliance question.
A manager saying “yes, you can work from Spain for two weeks,” for example, does not automatically determine:
-
Whether your immigration status permits the work.
-
Whether the company is legally permitted to provide access from that country.
-
Whether export-control or sanctions restrictions apply to the device, software or technical information.
-
Whether client or regulated data can be accessed from that location.
-
Whether the laptop must be declared to customs.
-
What your company requires if the device is inspected, detained, lost or stolen.
Before travelling, work through four separate questions.
1. Immigration and work permission
Ask whether you are legally allowed to perform your normal work while physically present in the destination.
A company’s internal approval does not replace immigration permission.
A country may distinguish between tourism, business visits, remote work, employment and other forms of professional activity.
For the broader distinction, see Trailandra’s guide to digital nomad visas versus local work permits.
2. Employer and compliance approval
Confirm that your employer has approved:
-
The destination country.
-
The travel dates.
-
The work you will perform.
-
The company device you will carry.
-
The systems and data you may access.
-
Any security restrictions that apply while abroad.
Approval should be destination-specific where possible.
A country that is acceptable for ordinary email and document work may not be approved for employees with access to source code, sensitive customer information, financial systems or controlled technical data.
3. Data, software and export-control review
Do not assume that carrying a laptop temporarily means export-control rules cannot apply.
For U.S.-regulated items, the Export Administration Regulations can treat taking equipment, software or controlled technology outside the United States as an export.
U.S. rules include a Temporary Imports, Exports, Reexports and Transfers — TMP license exception that can authorize certain tools of trade for temporary use abroad when its conditions are satisfied.
Among other requirements, qualifying tools of trade must generally remain under the exporter’s or employee’s effective control, and software must be protected against unauthorized access.
The regulations specifically identify precautions such as secure network connections, passwords and firewalls.
However, the TMP exception is not a universal permission to take every corporate device or controlled technology to every country.
The destination, item classification, software, technical information, end user and sanctions restrictions can all matter.
Employees should therefore rely on their employer’s export-control or legal team rather than attempting to classify company technology themselves.
4. Customs, border and device security
A laptop can also create practical border and customs issues.
Rules differ by country, so check whether temporarily imported professional equipment requires:
-
A customs declaration.
-
Proof of ownership.
-
A temporary-import procedure.
-
Additional documentation for high-value professional equipment.
Electronic-device searches are another separate issue.
For example, U.S. Customs and Border Protection states that electronic devices crossing the U.S. border can be searched under its border authority. CBP distinguishes between basic and advanced searches and states that its searches are limited to information resident on the device rather than information stored only remotely.
Other countries apply their own laws and procedures.
Before travelling, know your employer’s instructions for:
-
Border inspection requests.
-
Device unlocking.
-
Confidential or privileged information.
-
Loss or detention of the laptop.
-
Reporting a security incident.
-
Remote locking or wiping.
Do not improvise a response at immigration or customs if your employer already has a travel-security or border-search policy.
This guide provides general information, not immigration, customs, tax, sanctions, export-control or legal advice for a particular trip.
Rules can change and the answer can depend on your nationality, destination, transit countries, employer, device configuration and the information you can access.
Why taking a company laptop abroad creates more obligations than a personal laptop
An employer-issued device commonly provides access to resources that a personal travel laptop does not.
That may include:
-
Corporate email.
-
Internal networks.
-
Customer or client records.
-
Cloud storage.
-
Source-code repositories.
-
Financial systems.
-
Administrative consoles.
-
Confidential business documents.
-
Regulated or export-controlled technical information.
The risk therefore comes not only from the physical laptop itself, but also from what the device can access once it is connected.
This is one reason a fully remote job does not automatically mean employees are free to work from any country with the same device and system access.

A well-run international remote-work approval process may involve several teams because each one is evaluating a different type of risk.
Depending on the company and the trip, that can include:
-
HR or global mobility.
-
Payroll and tax.
-
Information security.
-
Privacy.
-
Legal counsel.
-
Export-control specialists.
-
Sanctions or trade-compliance teams.
-
Asset management.
-
Corporate insurance or risk management.
A manager’s informal “yes” may confirm that the work itself can be done remotely, but it does not necessarily clear the destination, device, data, software or compliance risks involved.
Treat the work laptop as part of the company environment
A company laptop used abroad should not be treated like an ordinary personal travel device.
NIST’s enterprise telework guidance explains that a remote client device accessing organizational systems is effectively an extension of the organization’s network.
That supports a practical rule:
The security baseline should not become weaker simply because the laptop has crossed a border.
Before travel, confirm that the device:
-
Has current operating-system and application updates.
-
Uses employer-approved endpoint protection.
-
Has full-disk encryption where required.
-
Uses strong authentication.
-
Has unnecessary services and sharing features disabled.
-
Uses only approved remote-access tools.
-
Can be remotely locked or wiped where company policy supports it.
-
Continues to receive security and management updates while abroad.
Do not disable endpoint controls, security software or device-management tools simply because they interfere with a hotel network or local connection.
If a required security tool prevents access, contact the employer’s IT or security team rather than creating an unapproved workaround.
Get written, destination-specific employer approval first
Ask for approval before booking travel, not after arrival.
The request should identify the exact destination, dates and expected work arrangement.
Where relevant, include:
-
Destination country or countries.
-
Travel dates.
-
Transit countries if you expect to work during a stopover.
-
Any personal side trip during which you intend to access company systems.
-
Company device being carried.
-
Expected work activities.
-
Systems and applications you need to access.
-
Types of company or client information involved.
A company may approve one country while restricting another.
It may also approve ordinary email and document work while prohibiting access to more sensitive resources such as:
-
Production systems.
-
Source-code repositories.
-
Customer databases.
-
Financial systems.
-
Administrator consoles.
-
Export-controlled technical information.
Ask what the approval actually covers
A useful written approval should answer questions such as:
-
Is remote work from this country permitted?
-
Are these exact dates approved?
-
Can I carry this company laptop?
-
Can I access all normal systems, or are some restricted?
-
Are there restrictions on downloading or storing data locally?
-
Is corporate VPN use mandatory?
-
Are there additional requirements for public or hotel Wi-Fi?
-
Are there countries or transit locations where I must not access company systems?
-
What should I do if customs or border authorities request access to the device?
-
Who should I contact if the laptop is lost, stolen, detained or searched?
The more sensitive your role or system access, the less useful a vague approval becomes.
A written message saying “remote work abroad approved” is not the same as a destination-specific compliance review.
If your plans change after approval—such as adding another country, extending the trip or changing the type of work you will perform—check whether a new approval is required before continuing to work from the new location.

Ask the company to confirm the following in writing before you travel:
-
Whether the destination country and exact travel dates are approved for remote work.
-
Whether you may carry the assigned laptop, company phone, hardware security key, removable media or other corporate equipment.
-
Which systems, applications and categories of company or client data you may access from the destination.
-
Whether a managed corporate VPN, virtual desktop infrastructure (VDI), endpoint-security controls or managed hotspot is required.
-
Whether a clean or restricted travel laptop is available or mandatory for that destination.
-
Whether local storage, USB devices, printing or downloading files is restricted.
-
What to do if customs or border officials request access to the device, retain it or copy information.
-
Who to contact immediately if the device is lost, stolen, tampered with, detained or otherwise compromised.
Keep the approval and relevant emergency contacts somewhere you can access even if the laptop itself becomes unavailable.
A VPN does not change where you are legally working
Do not assume that connecting through a VPN changes your legal location.
A VPN can encrypt network traffic and route it through another server, but it does not change:
-
The country where you are physically located.
-
Your immigration status.
-
Whether local law permits the work you are performing.
-
Potential employer payroll or tax obligations.
-
Export-control or sanctions restrictions.
-
Company rules concerning access from particular countries.
Likewise, using a VPN to make an internet connection appear to originate from another country should not be treated as a way to bypass employer, immigration, financial or compliance restrictions.
If your employer requires a corporate VPN or VDI, use the approved configuration rather than replacing it with a personal service.
For the broader non-technical issues, see Trailandra’s employer, visa, tax and insurance checklist for working while travelling.
Taking a company laptop abroad does not make visitor status a work permit
“I work online for an overseas employer” is not a universal exception to immigration rules.
Each destination decides what activities are permitted under its own:
-
Tourist or visitor status.
-
Business-visitor rules.
-
Remote-work or digital-nomad visa.
-
Employment visa.
-
Work permit.
-
Residence status.
Those categories should not be treated as interchangeable.
A country may permit limited business activities such as attending meetings or conferences while restricting productive employment. Another country may expressly allow qualifying remote work for a foreign employer. Others may require a specific visa or residence status once the activity goes beyond ordinary tourism or business travel.
Employer approval therefore answers only one question:
“Will my company allow me to work from this location?”
Immigration law answers a different question:
“Does this country allow me to perform this work while I am physically here?”
You need both answers before relying on the trip as a lawful remote-work arrangement.
For a deeper comparison of these boundaries, see Trailandra’s guide to digital nomad visas versus local work permits.

For example, current U.S. Department of State guidance distinguishes permitted B-1 business activities from taking employment in the United States or performing skilled or unskilled labor.
That is a U.S.-specific rule, not a global template, but it illustrates an important principle: immigration authorities may care about the activity you perform while you are physically present in their country, not simply where your employer is located or where your salary is paid.
Check the destination’s official immigration authority, embassy or consulate for rules that apply to:
-
Your nationality.
-
Your immigration status.
-
The length of your stay.
-
The identity and location of your employer.
-
The work you intend to perform.
-
Whether you will receive local compensation.
-
Any specific remote-work or digital-nomad route that may apply.
If a destination offers a digital-nomad or remote-work visa, it may be relevant, but it is not automatically the correct category for every employee or every type of work.
Trailandra’s digital nomad visa versus local work permit guide explains why the immigration category should match the actual working arrangement.
Customs when taking a company laptop abroad
Customs rules are another reason why taking a company laptop abroad should be planned before departure rather than handled for the first time at the border.
A company laptop may be treated as temporarily imported professional equipment, ordinary accompanied equipment or another category under the destination’s customs rules.
The correct treatment can depend on:
-
The destination.
-
Your residence.
-
Who owns the equipment.
-
Its value.
-
The number of devices you are carrying.
-
The purpose of the trip.
-
Whether the equipment will leave the country again.
Depending on those facts, customs rules may require nothing beyond ordinary entry procedures—or may involve a declaration, temporary-import procedure, security deposit, carnet or other documentation.
Do not assume that every laptop requires an ATA Carnet.
Equally, do not assume that employer-owned or professional equipment is automatically exempt from customs requirements.
Check the destination’s official customs authority or obtain advice from the employer’s customs, logistics or legal team before travel.
Additional review may be appropriate when travelling with:
-
Several computers.
-
High-value professional equipment.
-
Specialized communications equipment.
-
Drones.
-
Satellite equipment.
-
Product samples.
-
Prototype hardware.
-
Equipment that will remain in the destination.
Carry proof that you are authorized to possess the laptop
For an employer-owned device, consider carrying a company asset or authorization letter.
The letter can identify:
-
The company.
-
A company contact person.
-
Your name.
-
Your role.
-
The laptop manufacturer and model.
-
Serial number.
-
Company asset tag.
-
Confirmation that the company owns the device.
-
Confirmation that you are authorized to carry it internationally.
-
Confirmation that it is intended for temporary company use rather than local sale or transfer.
This can help establish why you are carrying the device.
However, an employer letter is only supporting evidence.
It is not a substitute for any declaration, permit, carnet, temporary-import procedure or other documentation that the destination actually requires.
Be careful with CBP Form 4457
U.S. Customs and Border Protection provides Form 4457, Certificate of Registration for Personal Effects Taken Abroad.
The form is intended to help document that certain personal effects were already in the United States before departure, which can help establish prior possession when they are brought back.
For a personally owned laptop, camera or similar item, this type of documentation may therefore be useful.
For a company-owned laptop, do not automatically assume Form 4457 is the correct or sufficient documentation.
The employer owns the equipment, so ask the company and, where necessary, CBP or a customs professional how ownership and authorized possession should be documented.
Border searches: encryption does not eliminate the issue
Border-search rules vary significantly by country.
For the United States, CBP states that its border-search authority extends to electronic devices crossing the U.S. border.
CBP distinguishes between basic and advanced electronic-device searches.
Basic search
A basic search generally involves an officer manually examining information available on the device without using external equipment for a forensic review.
Advanced search
An advanced search involves connecting external equipment to the device to review, copy or analyze its contents.
Under current CBP policy, an advanced search generally requires:
-
Reasonable suspicion of activity that violates a law enforced or administered by CBP, or a national-security concern.
-
Approval from an appropriate senior manager.
CBP also states that its electronic-device searches are directed at information resident on the device at the time of examination.
Its procedures instruct officers to disable network connectivity so that the device is not used to retrieve information stored only remotely.
Know the company procedure before you reach the border
Encryption is still an important security control, but it does not make border-search questions disappear.
CBP states that travelers must present devices and information resident on those devices in a condition that permits examination.
If a device cannot be inspected because of a passcode, encryption or another security mechanism, the device may be detained or subject to further action.
For foreign nationals seeking admission to the United States, refusal or inability to facilitate an inspection can also affect the broader admissibility process depending on the circumstances.
CBP separately states that a U.S. citizen will not be denied entry to the United States solely because an electronic-device inspection cannot be completed, although the device itself may still be detained or otherwise handled under applicable procedures.
These distinctions illustrate why an employee should not invent a border-response strategy while standing in front of an inspection officer.
Before taking a company laptop abroad, know whether your employer instructs you to:
-
Contact corporate legal counsel.
-
Contact information security.
-
Follow a specific procedure for access requests.
-
Request a supervisor where appropriate.
-
Surrender or leave the device rather than disclose certain information.
-
Use a clean travel device for particular destinations.
-
Report the inspection immediately afterward.
Follow lawful employer guidance rather than weakening security controls before travel.
Minimize locally stored data
Encryption protects information when a laptop is lost or stolen, but another important risk-reduction measure is simply carrying less sensitive information locally.
Where company policy permits, avoid unnecessary local copies of:
-
Client datasets.
-
Source-code archives.
-
Confidential email.
-
Authentication secrets.
-
Financial files.
-
Controlled technical information.
-
Sensitive research.
-
Large offline document repositories.
A device containing less local information generally exposes less local information if it is searched, copied, lost or stolen.
Keep approved backups in the employer’s approved storage environment rather than carrying the only copy of important work on the travel laptop.
Encryption and export controls: crossing a border can be an export
For equipment, software or technology subject to U.S. export controls, physically taking a company device outside the United States can constitute an export.
That does not mean every business laptop requires an individual export license.
U.S. export rules include exceptions that may apply to qualifying temporary business equipment, but those exceptions have conditions.
Current EAR §740.9, License Exception TMP, can authorize certain temporary exports of tools of trade, including qualifying commodities and software used abroad by an exporter or its employees.
Among other requirements, relevant tools of trade may need to remain under the effective control of the exporter or employee.
Software used as a tool of trade must also be protected against unauthorized access.
BIS gives security examples that can include:
-
Secure network connections such as VPNs.
-
Password controls.
-
Firewalls.
Destination restrictions and the broader limitations applicable to license exceptions still matter.
In other words, taking a company laptop abroad should not be treated as automatically authorized simply because the trip is temporary.
Encryption does not create a blanket exemption
BIS separately regulates certain encryption items under Category 5, Part 2 of the Commerce Control List.
The applicable authorization can depend on factors such as:
-
Classification.
-
Destination.
-
End user.
-
End use.
-
Reporting requirements.
-
Other applicable export restrictions.
Many ordinary commercial encryption products can be exported broadly when the relevant requirements are satisfied.
But that does not mean every encrypted corporate device, technology or destination is automatically permitted.
Additional review may be appropriate when the device or account provides access to:
-
Controlled technical information.
-
Certain source code.
-
Advanced-computing technology.
-
Cybersecurity tools.
-
Aerospace or defense information.
-
Specialized research.
-
Product design or manufacturing information.
-
Non-public encryption technology.
Employees should not attempt to classify corporate technology or determine export-license eligibility themselves unless that is part of their assigned role.
Ask the employer’s export-compliance or legal team.
Remote access can also matter
Do not assume that storing controlled information on a server in the United States automatically removes export-control questions.
Remote access to technology can still form part of an export-control analysis depending on the technology, user, destination and applicable authorization.
BIS guidance has addressed circumstances in which temporary remote access to U.S.-based systems can fall within tools-of-trade provisions when the relevant conditions are satisfied.
That does not create a general safe harbor for cloud or remote access.
The practical rule is simple:
Ask whether you are permitted to access the relevant systems and technology from the destination, not merely whether you are permitted to carry the physical laptop there.
Sanctions are a separate compliance question
Export controls and sanctions can overlap, but they are not the same system.
For U.S. sanctions, OFAC administers programs that may involve restrictions connected with:
-
Countries.
-
Regions.
-
Governments.
-
Organizations.
-
Individuals.
-
Particular transactions.
-
Particular services or economic activities.
The compliance question is therefore not simply:
“Is this country sanctioned?”
Depending on the work, an employer may also need to consider:
-
Customers.
-
Counterparties.
-
Local service providers.
-
Software access.
-
Financial transactions.
-
Payments.
-
Restricted persons or entities.
-
Ownership or control of counterparties.
-
Services being provided while the employee is present in the destination.
Sanctions programs can change.
Do not rely on an old spreadsheet or an informal list of supposedly “safe” countries.
Use current official information and the employer’s sanctions-compliance process.
Security setup to complete before boarding
Security planning is equally important when taking a company laptop abroad.
Travel security should begin before reaching the airport.
A company-managed travel setup may include:
-
A fully patched, centrally managed work laptop.
-
Full-disk encryption.
-
Approved endpoint protection.
-
Secure backups.
-
Strong authentication.
-
Phishing-resistant MFA where supported.
-
An approved account-recovery method.
-
Corporate VPN, zero-trust access or VDI where required.
-
Automatic screen locking.
-
Remote-management capabilities.
-
Minimal unnecessary local data.
-
A record of the laptop’s serial number and asset tag.
-
Security and IT contact information stored somewhere other than the laptop.
CISA guidance supports practices such as protecting sensitive data with encryption, maintaining backups and using organization-approved secure-access methods for remote work.
Do not weaken corporate security to make travel easier
If an employer requires:
-
A managed VPN.
-
VDI.
-
Zero-trust access.
-
A hardware security key.
-
Endpoint monitoring.
-
A managed hotspot.
use the approved configuration.
Do not install a consumer VPN as a workaround for an employer access restriction.
Do not disable endpoint protection, device management or other security controls simply because a hotel, airport or coworking network is inconvenient.
If an approved security tool prevents access, contact the employer’s IT or security team.
Treat public networks as untrusted
Hotel, café, airport, conference and coworking networks should not automatically be considered trustworthy.
Where company policy permits, a managed hotspot or cellular connection may be preferable for sensitive work.
If public Wi-Fi must be used, follow the employer’s approved remote-access method.
Also:
-
Verify the legitimate network name.
-
Disable unnecessary automatic network connections.
-
Turn Bluetooth off when it is not needed.
-
Avoid unknown USB devices.
-
Avoid connecting the laptop to computers or accessories you do not control.
-
Never allow another person to use the corporate laptop.
-
Maintain physical control of the device.
Where airline rules and employer policy permit, keep the laptop with you in carry-on baggage rather than voluntarily separating yourself from the device.
Reliable mobile connectivity can reduce dependence on public Wi-Fi, but it should support—not bypass—the employer’s security design.
Trailandra’s travel eSIM for remote work guide explains what to compare when choosing a mobile-data backup for work.
Clean travel laptop or normal company laptop?
Some employers issue a clean travel laptop for higher-risk destinations or sensitive roles.
This is generally a company-managed device configured with only the applications and access required for the trip.
It may include:
-
Essential applications only.
-
Minimal locally stored information.
-
Limited cached email.
-
Restricted file synchronization.
-
Approved remote access.
-
VDI or browser-based access where appropriate.
A normal daily work laptop may contain substantially more local information, including:
-
Cached email.
-
Offline cloud files.
-
Client documents.
-
Development files.
-
Source code.
-
Credentials.
-
Local archives.
A clean travel laptop is not a legal shield.
It does not eliminate immigration, customs, border-search or export-control obligations.
Its purpose is risk reduction.
If the device is inspected, copied, stolen, lost or detained, less sensitive information may be exposed locally.
Whether a clean travel laptop is appropriate should be determined by the employer according to:
-
Destination.
-
Employee role.
-
Type of work.
-
Data sensitivity.
-
System access.
-
Security risk.
Data protection still matters
Data-protection analysis is more nuanced than saying:
“An EU employee opened a company laptop outside Europe, so a GDPR international transfer automatically occurred.”
The European Data Protection Board addresses a similar situation in its Guidelines 05/2021.
Its example involves an employee of an EU controller travelling to a third country and remotely accessing personal data in the employer’s systems.
The EDPB explains that this situation is not necessarily a Chapter V transfer simply because the employee is physically outside the EU, because the employee remains part of the same controller rather than becoming a separate controller or processor.
That narrow conclusion is not a general compliance clearance.
The organization may still need to consider:
-
Security.
-
Confidentiality.
-
Access controls.
-
Data minimization.
-
Local-law exposure.
-
Customer contracts.
-
Professional-secrecy obligations.
-
Sector-specific regulation.
If the employee discloses personal data to a separate organization, controller or processor in the third country, the transfer analysis may be different.
The correct question is therefore not simply:
“Where is the laptop?”
It is:
“Who is processing or receiving the data, under whose authority, and what legal and security requirements apply?”
Tax, payroll and social security can still matter
Employer approval and immigration permission do not automatically resolve tax, payroll or social-security questions.
Performing work while physically present in another country can potentially affect:
-
Employee income tax.
-
Employer withholding.
-
Payroll registration.
-
Social-security contributions.
-
Employment-law obligations.
-
Corporate-tax exposure.
-
Permanent-establishment analysis.
For U.S. employees, IRS guidance explains that compensation for services performed abroad can still interact with U.S. federal income-tax withholding rules when the employee works for a U.S. person, subject to applicable exceptions.
U.S. citizens and residents working abroad for an American employer may also remain subject to U.S. Social Security and Medicare taxes, depending on the circumstances.
The United States has Totalization Agreements with certain countries that can affect which social-security system applies and help reduce double social-security taxation.
The result depends on the specific facts.
Do not rely on the “under 183 days” rule
A common remote-work assumption is:
“If I stay fewer than 183 days, there cannot be a tax problem.”
That is not a safe universal rule.
Different countries may use:
-
Tax-residence tests.
-
Source-of-income rules.
-
Payroll rules.
-
Tax treaties.
-
Employer-presence rules.
-
Social-security rules.
-
Other domestic-law thresholds.
Some obligations can arise before 183 days.
In other situations, a treaty may change the result even when domestic rules initially point in another direction.
Immigration permission also does not automatically determine tax treatment.
A visa may permit you to remain or work in a country without settling:
-
Whether your income is locally taxable.
-
Whether the employer has withholding obligations.
-
Whether social-security contributions apply.
-
Whether the employer creates broader corporate-tax exposure.
For the employer-side tax question, see Trailandra’s digital nomad tax and permanent-establishment guide.