Field Notes

concept

Encryption key disclosure compulsion

Jurisdictions take structurally different approaches to compelling disclosure of an encryption key or passcode, and the difference matters for whether refusing to decrypt functions as a bounded, predictable choice or an open-ended one. Swedish encryption and passcode disclosure law has no compulsion mechanism at all for a password or PIN. The United Kingdom criminalizes non-disclosure directly, with a fixed statutory sentence. The United States has no unified rule and instead litigates each case under a doctrine whose outcome is genuinely unpredictable.

The United Kingdom: a discrete offense with a fixed ceiling

Section 49 of the Regulation of Investigatory Powers Act 2000 (RIPA) lets an authorized person serve a notice requiring disclosure of an encryption key or the underlying data in intelligible form. Section 53 makes non-compliance a distinct criminal offense, with a maximum of five years’ imprisonment where the case involves national security, and two years in any other case. The Court of Appeal upheld this scheme against a self-incrimination and Article 6 challenge in R v S and A [2008] EWCA Crim 2177, reasoning that the key itself, unlike compelled testimony, exists independently of the suspect’s will.

Two documented cases show this operating, in practice, as a genuinely bounded process crime. Oliver Drage, arrested in a child-sexual-exploitation investigation (Lancashire Police’s “Awaken” operation, 2010), refused to disclose a 50-character password protecting a seized computer. He was convicted under section 53 and received sixteen weeks in a Young Offenders Institution — far below even the two-year non-national-security maximum — and no substantive charge was ever brought, because the drive was never decrypted. “JFL”, arrested during a false-alarm anti-terrorism incident and later served a section 49 notice in a terrorism-adjacent investigation, refused across ten counts covering multiple encrypted drives and received nine months on the section 53 counts, again well under the statutory ceiling, combined with separate sentences for unrelated passport-fraud and bail-jumping charges. The judge found he posed no threat to national security. Neither man is publicly quoted stating that the refusal was a deliberate strategic trade-off against a worse substantive charge; that inference is plausible from the investigative context but not independently confirmed.

The United States: an unsettled doctrine, and unbounded civil contempt

US courts disagree sharply about whether the Fisher v. United States (1976) “foregone conclusion” exception to the Fifth Amendment — developed for compelled document production, not decryption — transfers to a password or passcode. Outcomes turn on how much the government can already show it independently knows about the specific files sought, not on a settled general rule:

Case Result Basis
In re Grand Jury Subpoena Duces Tecum (11th Cir. 2012) Foregone conclusion did not apply Government did not even know whether the drives held anything
United States v. Fricosu (D. Colo. 2012) Applied A recorded jail call established the defendant’s knowledge of a specific file
Commonwealth v. Gelfgatt (Mass. 2014) Applied Defendant had admitted ownership and ability to decrypt
Commonwealth v. Davis (Pa. 2019, 4-3) Did not apply State had not shown particularized knowledge of the full range of files, only one already-viewed file
State v. Andrews (N.J. 2020) Applied Passcode’s mere existence and authenticity were enough once ownership was established
In re Feldman (E.D. Wis. 2013) Did not apply Circumstantial evidence of files existing did not establish this suspect’s control of these specific drives

A defendant cannot reliably predict, in advance, whether refusing to decrypt will be constitutionally protected; this is case-specific litigation risk, not a settled safe harbor, and it depends heavily on which jurisdiction’s courts hear the case.

More important for evaluating any “bounded lesser charge” strategy is that the US alternative to a discrete criminal offense is typically civil contempt, which is coercive rather than punitive in form: held until compliance, rather than sentenced to a fixed term. Francis Rawls, a former Philadelphia police sergeant, was held in civil contempt from September 2015 for refusing to decrypt two hard drives the government believed contained child sexual abuse material. He was held for more than four years before the Third Circuit ruled, in 2020, that 28 U.S.C. § 1826(a)’s eighteen-month cap on confining a recalcitrant witness applied to him, and ordered his release. He was never charged with the underlying offense. He spent roughly 2.7 times longer in unadjudicated detention than the cap eventually applied to him, and the government could plausibly have kept arguing the cap did not apply at all had the Third Circuit characterized him as a suspect rather than a witness, the exact point on which the majority and dissent split. Commonwealth v. Davis, above, shows the same risk even where the defendant ultimately won: he was held for four years of pretrial detention before the Pennsylvania Supreme Court barred compelled disclosure on the merits.

A third US path appeared in 2026, closer in form to the UK’s discrete offense than to contempt: rather than compelling disclosure or coercing it through detention, the government can prosecute the destruction itself. In United States v. Tunick, the Justice Department charged a defendant under 18 U.S.C. § 2232, which criminalizes destroying or removing property to prevent its seizure, because his phone wiped itself after he provided a passcode during a border inspection. The indictment’s own language — destruction “before and during the search for and seizure” — stakes out the untested position that the statute reaches wiping one’s own device after a seizure threat but before physical seizure. The case also ties this path back to the compulsion doctrine above: Tunick’s suppression motion cites the Eleventh Circuit’s 2012 In re Grand Jury Subpoena Duces Tecum — the case in the table where the foregone-conclusion doctrine did not apply — for the proposition that his compelled passcode was testimonial. The charge’s viability awaits the case’s suppression ruling.

Cooperation can surface material beyond the original predicate

Rawls’s own case record supplies direct, documented evidence for a risk distinct from the compulsion mechanism itself: that cooperating, even partially, can expose material unrelated to the offense that triggered the investigation. Investigators eventually decrypted Rawls’s Mac Pro independently of his cooperation and found an image and browsing history connected to the original Freenet file-sharing investigation. But when Rawls voluntarily unlocked a separate iPhone, that device held images and video of his young nieces distinct in kind and origin from the online-sharing predicate that began the investigation, material his sister separately testified she had also seen on the still-encrypted external drives. Whatever the merits of the underlying case, this shows partial cooperation can widen an investigation’s scope into material the original warrant or predicate never described. Commonwealth v. Davis was decided on exactly this concern: the Pennsylvania Supreme Court’s majority rejected compelled disclosure specifically because the government could not show its knowledge was limited to one already-viewed file, reasoning that decryption could expose “an unknown number” of additional files. The court’s holding, not just its outcome, treats scope creep from cooperation as the central doctrinal question. Why a known harsher penalty can beat an uncertain lesser one takes that up as an independent reason to prefer non-disclosure, separate from the sentence-length comparison this note otherwise covers.

Sweden: no compulsion mechanism for the credential itself

Swedish encryption and passcode disclosure law takes a third structural path. Sweden does not criminalize non-disclosure the way the UK does, and does not litigate a foregone-conclusion doctrine the way the US does, because Swedish law does not attempt to compel disclosure of a password or PIN at all; only a physical biometric unlock can be compelled, classified as a bodily examination rather than testimony. Refusal to disclose a knowledge-based credential carries no criminal exposure under current Swedish law, though whether actively destroying the underlying data is separately punishable remains only partly settled, discussed in How does Swedish law treat duress wipes.

Comparative summary

Jurisdiction Mechanism Bounded?
United Kingdom Discrete criminal offense, fixed statutory maximum Yes, in the two documented cases, well under the ceiling
United States Civil contempt (coercive), unsettled Fifth Amendment litigation, or prosecution of the destruction itself under § 2232 No — civil contempt can exceed any bounded sentence, as Rawls shows; § 2232’s reach to self-wipes is untested
Sweden No compulsion mechanism for a password or PIN Not applicable — refusal carries no criminal exposure

This comparison is the evidentiary basis for Why a known harsher penalty can beat an uncertain lesser one, which evaluates the strategic question of deliberately choosing non-disclosure over risking a worse substantive charge.

Scope and reliability

The UK and US findings rest on primary case law and, for the UK cases, contemporaneous news reporting of actual sentences. No case was found, in any jurisdiction, of a defendant explicitly and publicly stating they refused specifically to avoid a worse charge’s collateral consequences; the connection between the investigative context and the refusal’s strategic purpose is inferred, not confirmed by the defendants’ own statements. The scope-creep risk described above is better grounded: it rests on the Rawls case’s own factual record and on the Pennsylvania Supreme Court’s own stated reasoning in Davis, not on inference from investigative context.

Built on 5 sources (5 external).

Working out connections…