The Passport Fight You Already Lost

The visa service sent a stranger on a motorbike, and I handed him both our passports. I'd do it again tomorrow. The fight to keep your passport data private was lost years ago. The real leverage is somewhere else.

The Passport Fight You Already Lost

A few years ago in Thailand, we needed a thirty-day extension on our tourist visa. The visa service sent a guy on a motorbike. He rolled up our driveway, took both of our passports out of my hand, stuffed them into the pocket of his Grab jacket, and rode off. Two days later a different guy on a different motorbike brought them back with the extension stamp inside. We never met the lawyer. We never saw the office. We never watched anyone photocopy a thing.

I'd do it again tomorrow.

Every blog post about passport privacy would tell me I shouldn't have. That I handed a foundational identity document to a stranger I'd never meet again. That I had no visibility into how many copies got made at the lawyer's office, or whose Google Drive those copies ended up on, or who has them now. All of that is true.

It's also irrelevant.

The cybersecurity advice being sold to travelers is built on a premise that stopped being true years ago. The premise is that you can, by being vigilant, keep your passport data out of circulation. You can't. It's already in circulation. The only question worth asking is what you do about it downstream, and the answer has almost nothing to do with which hotel you let photocopy the data page.

The Math Nobody Wants to Run

Run the math on your own passport. Start with the breaches you were almost certainly in. Marriott/Starwood in 2018: 5.25 million unencrypted passport numbers and 20.3 million encrypted ones, the breach running from 2014 to 2018. If you stayed at any Starwood or Marriott property in that window, you're in it. MGM Resorts in 2019 and 2023: 37 million guests. IHG in 2022. Ten Italian hotels in 2025, with 90,600 scans sold on a dark-web forum at prices starting at €800. These are just the named, settled incidents at major chains. Add the regional chains, the boutique hotels, the Airbnb property management tools, the rental car companies, the airlines.

Then add the routine, non-breach circulation. The visa service. The bank that onboarded you for nomad tax residency. The second bank. The health insurer. The telecom provider. The co-working space. The long-stay rental agent, and the owner, and the building staff, and the person who replaces the rental agent in eighteen months and inherits the inbox. By the time a serious long-stay traveler has been on the road for five years, the number of independent storage systems holding your passport's data page is in the low hundreds, and the number of individual people with read access to at least one of those copies is in the thousands.

One more photocopy at a midrange Mexican guesthouse does not change this picture.

The traveler security industry gets this backwards. It sells vigilance at each handoff (watermarked copies, manual entry, polite refusals at front desks) as if the marginal scan were the meaningful unit. It isn't. The meaningful unit is the aggregate leak, and the aggregate leak happened before you got to the front desk. Most privacy advice for travelers is being careful about the fiftieth drop of water after the dam broke.

Why Fighting Feels Virtuous But Isn't Useful

There's a real reason I understand the impulse to push back. At every handoff there's an apparent choice. The clerk asks for the passport. You can hand it over, or you can try to negotiate a smaller data footprint. The negotiation looks like agency. Exercising agency looks like doing something.

It isn't doing anything. Because the thing you're trying to protect (the idea that there's a small number of legitimate holders of your passport scan, and that with effort you can keep that number small) already isn't true. The leak happened. The only thing the negotiation protects you from is the next increment added to a set that's already enormous. It's like carefully insuring one brick in a burning house.

The calculus is worse than neutral, because the negotiation itself has real costs. An extra forty-five minutes at check-in. A manager summoned, a slight edge in the voice, a relationship with the hotel that starts hostile. A rental agent who was about to give you the keys to a three-month villa deciding you're going to be a difficult tenant. A Grab visa service who now wants twice the price to deal with your paperwork, or who decides to just not come back at all. You are spending real time and real goodwill to protect an asset that is already compromised: the locational integrity of your passport scan.

The foreign-language contracts you sign every month make the same point. Every time you check into a hotel in a country whose language you don't read, you sign a form whose terms you are not in a position to evaluate. Every car rental. Every apartment lease. You are already, routinely, agreeing to things you could not defend in court. The photocopy on top of the contract is the least of the legal exposures you've accepted in the last twenty-four hours.

Travel abroad is a standing waiver of informed consent. The traveler who tries to claw back consent at the passport-scan moment has chosen a strange hill.

Two Different Fights, and People Mix Them Up

The privacy fight is about the scan: the digital image of your data page that lives on servers after the transaction ends, and that can be sold, traded, or abused months or years later. That fight is over. The scan is everywhere. One more doesn't matter.

The logistics fight is about the physical book: the object you need in your pocket to leave the country. That fight is very much still on. If the Grab driver in Thailand had gotten run over, or if the front-desk clerk in Vietnam had been fired overnight and locked out of wherever she stashed the passports, I'd have had a different kind of problem. Not a privacy problem. A "we are stuck in Southeast Asia until the embassy produces a replacement" problem, which in some countries is a week and in others is longer.

These are two different problems. The common travel-safety advice treats them as one: "guard your passport." The conflation is where most of the bad thinking comes from. Once you separate them, the right answer in most situations becomes obvious. The privacy risk of handing the book to the motorbike guy is nil. The logistics risk is real but usually small. Accept it, and get on with your day.

The blog-advice error is spending energy on the first fight while ignoring the second. The business-traveler error is the opposite: worrying about lost books while letting unwatermarked scans float around rental-agent Gmail accounts forever. Both problems exist. They take different defenses.

The Hedge That Closes the Logistics Loop

There is one move that mostly removes the logistics risk from the equation: get a second passport.

Every time we've sent our passports off on a motorbike or into a hotel's back office, we've been briefly without them. That's fine when everything goes smoothly. It's a different situation if, in those few days, we'd needed to leave the country suddenly—an unexpected death in the family, a medical emergency back home, a political situation that rearranges your plans overnight. The passports might be halfway to Bangkok at a lawyer's office. Getting them back could take days. A consular replacement would take longer.

The US, for travelers who have a legitimate need, will issue a second full-validity passport. The process involves documenting the need and applying through the State Department's secondary passport procedures; a third or fourth is possible on the same basis. The second passport lives in our possession whenever the first is in someone else's. The motorbike guy takes the primary; the secondary stays in the safe in the room. If we need to leave that afternoon, we can.

This is the only piece of identity-document infrastructure I'd tell a serious long-stay traveler to invest in. It doesn't change the privacy calculus (both books have the same data page, both get scanned just as often, both contribute equally to the aggregate leak). What it changes is the logistics calculus. You can hand one over without becoming stranded. The motorbike guy can do his job and the death-in-the-family flight can still happen.

Most citizenship regimes have something equivalent. Canadians can get a second passport for valid need. Most EU member states too. If you're traveling enough to be reading a piece like this, the administrative lift is worth doing once, and the peace of mind is worth it every time you let the primary book out of your sight.

What Actually Protects You

If the scan is already out there, the useful defensive work is downstream of the scan. It's what you have in place for when somebody tries to use it.

Freeze your credit at the source. In the US, the three major credit bureaus (Equifax, Experian, TransUnion) let you place a credit freeze for free, online, in fifteen minutes per bureau. A freeze prevents a new credit account from being opened in your name without you temporarily lifting it. This is the single most effective defense against the canonical passport-fraud attack, which is: someone uses your scan plus some other data to open a loan or credit line in your name. A freeze makes that attack fail at the last step.

Know what's open in your name. Once a year, pull all three US credit reports (free, annualcreditreport.com). Look for accounts you don't recognize. Every jurisdiction where you have banking or residency, do the equivalent: request whatever consumer credit report is available. If you're a US person, check the IRS for tax identity fraud (file an IP PIN, and pull transcripts if you suspect something). If you've been a director or shareholder of anything, check periodically whether you've been added to any company register you didn't sign up for.

Split banking between home base and travel. The checking account you use in Thailand should not be the account that holds your house down payment. A compromise to the travel-exposed account needs to be a compromise to a lower-limit, easier-to-close account. Small banks, second accounts, low balances, easy cancellation. Treat your travel money like a walking-around wallet, not like your life savings.

Have a passport replacement plan. Know, for every country you might be in, where the nearest embassy or consulate is that serves your nationality and how long a replacement takes. Carry a color photocopy of the data page separately from the book. If your passport is stolen, the first twenty-four hours matter, and you don't want to be figuring out the procedure while standing in line at a consulate.

Fraud alerts at the big US identity services. Experian, TransUnion, Equifax all offer free fraud alerts that require lenders to make extra verification before opening credit. Renew them.

If you're not a US national, the specifics change but the architecture doesn't. The UK has Cifas protective registration. Canada has Equifax and TransUnion with file-freeze equivalents. Most EU countries have a national credit registry (SCHUFA in Germany, BKR in the Netherlands, Banque de France's FICP) that will show you what's reported in your name. The discipline is the same: know what's open under your identity, make it harder to open new accounts without you noticing, and have a schedule for checking. A dark-web monitoring service (Have I Been Pwned is free, and the paid services from identity-protection vendors cover the rest) catches exposures that don't show up in credit files.

Search your own name on a schedule. Every six months. Not vanity—a watch. The first signal that someone has monetized your passport scan is usually a public record showing up in your name somewhere you didn't authorize. A civil judgment, a company filing, a property transaction. You want to find these early.

None of this is cybersecurity theater. All of this is the actual defense that engages after your data has been misused. It's the fire alarm and the insurance policy for the house that's already flammable. The energy you might have spent arguing with a clerk about whether they can photocopy your passport is better spent here, where it actually changes outcomes.

What's Left Worth Doing

Two things.

Don't email full-resolution unwatermarked scans to long-stay rental agents when you don't have to. Not because it changes your aggregate exposure (it doesn't) but because it's almost free to send a watermarked copy instead. You were going to send a PDF anyway. You can send a slightly worse PDF with a diagonal stamp that reads FOR [AGENT NAME] VILLA RENTAL—APRIL 2026—NOT FOR KYC across the face of the data page. Takes thirty seconds in Preview or any PDF editor. A watermark like that doesn't stop a determined forger, but it renders the scan useless for automated KYC capture at a bank or exchange, because the bank's fraud filter will flag the legible "NOT FOR KYC" text. The marginal defensive value is small. The marginal cost is also small. Net positive, do it.

Manage the logistics fight consciously, not by default. The privacy risk is resolved—you lost. The logistics risk is not. When you hand the book over to a visa service, a hotel safe, or a minivan driver at a border, you're making a logistical trade: convenience now against the tail risk of a lost or delayed document. Most of the time the trade is fine. Occasionally it isn't. Know which one you're making.

The second passport is the big hedge. Below that, the small hedges already covered do the rest. With them in place, losing a book is a bad afternoon. Without them, the same event is a catastrophe.

The lawyer in me used to argue with front desks. Eleven years of travel taught me where the actual leverage is, and it isn't at check-in. Everything else, I've stopped fighting. I hand the passport over. I let them make the copy if they're going to insist. I sign the form in the language I can't read. I pay the ten dollars to the clerk and get the extension the same afternoon. The visa service sends the guy on the motorbike and I hand him the book.

He always brings it back.