Your Phone’s Security Feature Could Be a Legal Landmine
Your business phone holds the map of your entire operation. Client lists, ongoing contracts, supplier pricing, employee records, and access to your company’s cloud accounts. To protect this, you have likely locked it down with strong passwords and encryption. Some of you may have even enabled a specific feature: a “duress” password or an auto-wipe that destroys all data if someone enters the wrong code too many times.
Now picture this. An officer from the Malaysian Anti-Corruption Commission (MACC), the Royal Malaysian Police, or Customs asks you or one of your traveling employees to unlock a company phone at a checkpoint. The password is entered. The screen goes blank. The data vanishes permanently.
This exact scenario is currently playing out in a United States federal court. A US citizen named Samuel Tunick is being prosecuted because his phone used a “duress password” that wiped the device when US Customs and Border Protection (CBP) officers entered the code during a secondary inspection. The US government charged him under a federal statute for “knowingly destroying or damaging property to prevent its seizure.” Security experts told TechCrunch this is the first known case of its kind. And it has immediate implications for how you manage your business data in Malaysia.
TL;DR
A US court is testing whether a pre-set “wipe password” constitutes criminal destruction of evidence. The logic behind the charges directly applies to Malaysian law. Your device security features must be designed so they do not conflict with your duties under the Personal Data Protection Act 2010 (PDPA) or your obligations under the Penal Code. If you are not careful, your “security” tool can legally be seen as a tool for obstruction.
What This Means: The Clash Between Security Software and the Law
The case revolves around GrapheneOS, a custom Android operating system with a specific feature. It allows the device owner to set one passcode that unlocks the phone, and a second passcode that “deliberately wipes the contents of that device.” The prosecution alleges that Tunick knowingly provided this duress password to authorities, destroying the data they were legally seizing.
Why should a business owner in Kuala Lumpur or Penang care? Because the legal principle at stake is universal. In Malaysia, destroying or concealing evidence is explicitly covered under the Penal Code. Meanwhile, the PDPA binds you to a duty of care for the personal data you process.
Here is the painful contradiction: The PDPA says you must protect data. A wipe feature protects data from strangers. But the moment a lawful authority demands access, using that same wipe feature flips from “protection” to “obstruction.” You have a duty to protect, and a duty not to destroy. A poorly planned security policy breaks that balance.
How This Applies to Malaysian SMEs
This is not just a story about an activist in Atlanta. It is a direct reflection of the risks you face today.
1. Your Employees Carry the Risk.
Every salesperson, manager, or technician on your team with a company phone is a potential liability point. A duress password is often seen as a cool privacy trick. But what happens when your employee is stopped at the Johor Causeway, KLIA, or a roadblock? Under pressure, they enter the duress code. Your client data is gone. You have lost business-critical information. If the authorities were investigating something related to your industry, you have just lost the ability to prove your compliance, and you have potentially committed an obstruction offence.
2. Your MDM Policies Need an Immediate Audit.
Many Malaysian SMEs use Mobile Device Management (MDM) tools that include remote wipe capabilities. This is standard practice for lost devices. However, if a device is seized during a dispute or investigation, triggering a remote wipe converts a security measure into a legal act of spoliation of evidence. You must ensure that your cloud backup strategy makes wiping a device a non-critical event, never a legal one.
3. Cross-Border Data Brings Cross-Border Laws.
If your SME serves clients in Singapore, the UK, or the US, your data is subject to their laws. The US case proves that foreign authorities can interpret your security features as hostile acts. A “duress password” might be a privacy best practice in one jurisdiction and a criminal act in another. Your data governance must account for the strictest law your data touches.
“I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” — Runa Sandvik, Digital Security Expert, speaking to TechCrunch [source]
Practical Takeaways for Your Business
- Inspect every phone’s “panic” setting today. Check your own device and your employees’ devices for “duress codes”, “panic codes”, or “auto-wipe after failed attempts” features. Disable them unless you have a specific security profile that requires them, and you have cleared that decision with legal counsel.
- Shift your data to the cloud. The safest wipe is one that doesn’t lose anything. If your data syncs to a secure cloud server, wiping a device becomes an inconvenience, not a catastrophe. This keeps you compliant with the PDPA duty to protect data without destroying it.
- Write a one-page legal access protocol. Tell your employees exactly what to do if an authority demands their device. The rule should be: “Power off the device immediately. Do not enter a password. State that you require legal counsel before providing access.” This buys you time and prevents an accidental deletion.
- Separate business and personal data. Implement Android Work Profiles or iOS Managed Apple IDs. If an employee’s personal device has a duress password for their own protection, it should not wipe your corporate data. A managed profile allows IT to preserve business data even if the personal side is wiped.
The Bigger Picture: From Security Features to Data Governance
The Tunick case is a watershed moment. For years, software companies marketed coercive wipe features as essential privacy tools. The legal system has now drawn a line. A feature designed to resist an unauthorized request is being treated by prosecutors as a weapon to foil a lawful one.
This does not mean you should stop securing your data. It means you must be smarter about how you secure it. The future of SME protection in Malaysia is not just about locking down hardware. It is about data governance. You need to know exactly what data sits on each device, how it is backed up, who controls access, and what your legal obligations are when that device enters the hands of an authority.
| Security Approach | Benefit | Risk in the Malaysian Legal Context |
|---|---|---|
| Duress / Wipe Password | Protects data from a thief using coercion | High risk of obstruction charge if used when authorities demand access (Source: TechCrunch) |
| Remote Wipe via MDM | Secures a lost or stolen device remotely | Spoliation of evidence if triggered during a legal hold, dispute, or investigation |
| Cloud Synchronization & Backup | Data survives the complete destruction of a device | Low risk. Complies with PDPA duty of protection without risking data destruction |
| Full Disk Encryption | Data is unreadable without the passcode | Low risk. Provides strong protection while allowing an individual to comply with a lawful disclosure order |
Your security setup must assume that someday, you could be the one handing over the password. What happens next is a direct test of how well you planned for the real world. A feature that destroys your business data and puts you on the wrong side of the law is not a security feature at all. It is a trap.
Plan around this reality. Audit your devices. Separate your data. Train your people. And ensure your security tools serve your business without putting it at risk.
This analysis is based on reporting by Zack Whittaker at TechCrunch, July 24, 2026.
Ready to Streamline Your Operations?
Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →
