← All guides

Privacy

Can Governments Track You Through a Travel eSIM? The Honest Answer in 2026

Can governments track a travel eSIM? What any mobile connection reveals, which countries demand ID, what Airalo, Holafly and Saily log, and what a VPN changes.

By the eSIM Verdict research desk Last checked 19 July 2026 14 min read

Some links on eSIMVerdict are affiliate links. If you buy through them we may earn a commission at no extra cost to you. Commercial relationships never affect rankings or conclusions; our assessments are based on independent research.

Short answer: yes, in the ways that any mobile connection can be tracked, and no, not in some of the ways people fear. A travel eSIM is still a SIM. The moment your phone registers on a mobile network, that network can see your device identifier (IMEI), your subscriber identifier (IMSI) and your approximate location from the cell towers you connect to. That is true whether the SIM is plastic or digital, local or foreign. No eSIM provider can switch this off, because it is how mobile networks function.

What a travel eSIM genuinely changes is the paperwork and the jurisdictions involved. Buying a local SIM in Turkey, the UAE or India means registering your passport in a national database. Buying a travel eSIM from a foreign provider usually does not, because you are technically a roaming customer of an operator based somewhere else. Your data traffic may also surface on the internet in a different country from the one you are standing in, which changes who can most easily inspect it.

This guide sets out what is well documented, what is plausible but unproven, and what is simply myth. It is written for ordinary travellers who want a realistic picture, not for spy thrillers.

At a glance

  • Every phone on a mobile network exposes its IMEI, IMSI and cell-level location to that network. An eSIM does not change this.
  • Host networks in almost every country are legally required to support lawful interception for their own authorities. Roaming traffic complicates, but does not eliminate, that access.
  • Travel eSIMs usually route your data back to a gateway in another country, so your traffic surfaces abroad. See where your eSIM traffic actually goes.
  • Roughly 160 governments mandate ID registration for local SIMs. Most travel eSIMs are sold as roaming products and skip local registration, though some destinations still trigger passport checks (eKYC).
  • Providers do keep records. Airalo, Holafly, Saily and Holiday.com all state in their privacy policies that they will disclose data to authorities when legally required.
  • HTTPS already protects the content of what you do online. A VPN hides destinations from the carrier but does nothing about radio-level location tracking.

What any mobile connection exposes, eSIM or not

Three identifiers matter, and none of them are optional.

The IMEI is your phone's hardware serial number. It is transmitted to every network you register on and does not change when you swap SIMs or install a new eSIM profile. The IMSI is the subscriber identity inside the SIM profile itself; it tells the network who to bill and which home operator you belong to. The EID is a third identifier unique to eSIMs: a permanent serial number for the eSIM chip, used when profiles are downloaded.

Then there is location. Mobile networks know which cell tower your phone is talking to at all times, because they could not deliver service otherwise. The Electronic Frontier Foundation's Surveillance Self-Defense project notes that operators can triangulate a handset to within roughly a kilometre using signal data, and modern network features can be far more precise. This tracking "is impossible to prevent while your phone remains powered and registered on the network", as the EFF puts it. A 2025 Northeastern University study presented at USENIX Security found that even eSIM resellers, not just operators, could in some cases access device location to within about 800 metres.

Finally, lawful interception. Nearly every country licenses its mobile operators on condition that they can intercept communications and hand over records when legally ordered. In Europe this is standardised by ETSI's lawful interception specifications; in the United States the CALEA statute plays the same role. This applies to the network carrying your radio signal, regardless of whose logo is on your eSIM app.

Does an eSIM change anything versus a physical SIM?

At the network level, essentially nothing. An eSIM profile contains the same IMSI and authentication keys as a plastic SIM, and your phone presents the same IMEI. There is no extra tracking chip, no special government back door in the eSIM standard that a physical SIM lacks, and no anonymity benefit at the radio layer either.

Two second-order differences are worth knowing. First, eSIM profiles are delivered remotely over the internet, so there is a download record linking a profile to your device's EID and usually to an account with your email and payment card. Second, a physical SIM can be bought for cash and thrown away; an eSIM purchase almost always leaves a digital payment trail. For ordinary travellers this is irrelevant. For anyone trying to be genuinely anonymous, it matters, and it cuts against eSIMs.

Claims that eSIMs are inherently easier for governments to track than physical SIMs are not supported by anything in the public record. Claims that they are harder to track are equally unsupported.

Which country's networks actually see your traffic

This is where travel eSIMs are genuinely different, and it is the part most travellers have never thought about.

A travel eSIM works as a roaming product. The radio connection is provided by a local network in the country you are visiting, but your data sessions are typically tunnelled back to the sponsoring operator's gateway, which may be in a completely different country. Your traffic then exits to the internet there, which is why your IP address often shows up as British, Singaporean or Hong Kong-based while you are standing in Rome. We cover this in depth in our guide to eSIM traffic routing.

The Northeastern University research team tested 25 travel eSIM providers and found that "in almost all cases the device's public IP address did not correspond to its physical location", with some traffic surfacing on networks in third countries, including one Holafly profile that exited via China Mobile's Hong Kong network. The researchers also observed eSIM profiles performing silent background communication via SIM Application Toolkit commands, without user awareness.

The privacy consequences run in both directions, and honesty requires saying so. The visited country's authorities can always see your radio-level metadata and location, because that happens on local infrastructure. But with home-routed data, the content of your traffic transits an encrypted tunnel through the local network and surfaces in the gateway country, so the authorities most easily positioned to inspect the actual data stream are the ones where the breakout happens. Whether any particular government does inspect travel eSIM gateway traffic is not publicly documented; that it could compel a domestic operator to assist is simply how telecoms law works everywhere. If knowing your breakout country matters to you, check before you buy, because providers rarely advertise it.

ID checks and KYC: where anonymity ends

According to the GSMA, roughly 160 governments now mandate identity registration for prepaid SIMs. The UK, USA and Czech Republic are notable holdouts that considered mandatory registration and rejected it. For local SIMs, the rules bite hard in exactly the destinations travellers ask about:

  • Turkey registers every local SIM against a passport, and using a foreign phone with a Turkish SIM long term triggers IMEI registration requirements.
  • UAE requires an Emirates ID or passport for any local SIM.
  • Hong Kong has required real-name registration for all local SIMs, including local eSIMs, since 2022-23 under its OFCA programme.
  • China goes further, pairing passport checks with facial recognition.

Travel eSIMs mostly sidestep this because you are not buying a local service; you are roaming on a foreign subscription, and roaming visitors are outside the local registration database. That is a genuine privacy difference: your passport never enters the Turkish, Indian or Emirati SIM registry. However, it is not absolute. Some providers require eKYC passport upload for specific destinations where regulators insist; Airalo, for instance, states that verification "may be required to access eSIMs for certain countries" and flags affected plans in its app before purchase. And your identity still exists in the provider's own records via your account and payment card, reachable by legal process in the provider's jurisdiction.

What the big providers log and hand over

We read the current privacy policies of four major travel eSIM providers. None of them promises to resist legal demands, and it would be misleading to expect otherwise.

Provider Legal home ID to buy? Stated retention Disclosure to authorities
AiraloAiralo AirGSM Pte Ltd, Singapore No, except eKYC destinations "As long as we need it, or are required legally" Yes: subpoenas, court orders, government requests
HolaflyHolafly Holafly Limited, Dublin, Ireland No for most plans Contract term plus 7.5 years; connection history 6 months Yes: legal or regulatory duty
SailySaily Saily Inc (US) with Saily UAB (Lithuania); Nord Security family No for data plans; passport for phone-number add-on Plan data 3 years; usage records 30 days; billing 10 years Yes: law enforcement and regulators as required by law
Holiday.com ExpressVPN team No Until you request deletion Yes: subpoena or suspected unlawful use

The detail is instructive. Airalo collects account data, IP address, device information and location, and discloses it "to comply with laws or respond to legal claims (including subpoenas and court orders) and requests from government or public authorities". Holafly retains customer data for the contract period plus 7.5 years, keeps six months of connection history, and shares data with "regulatory authorities and law enforcement agencies" where obliged; on the network side it states that carriers see only "minimal technical information", such as the IMSI and connection IP addresses, not your name or browsing activity. Saily's policy is the most granular, listing IMEI numbers, call detail records and SMS metadata among processed data, with usage records kept 30 days and billing data ten years. Holiday.com collects name, date of birth, address and click-level site usage, and reserves the right to release information when subpoenaed; note that the standalone Holiday.com eSIM does not include ExpressVPN's VPN or inherit its audited no-logs policy. Background on the companies is in our Airalo review and our Saily review.

The practical reading: a determined government with jurisdiction, or cooperation from one that has it, can identify who bought a travel eSIM. A casual data grab by a border officer cannot, because the local registry has nothing on you.

Metadata versus content: what encryption and VPNs actually do

It helps to separate two layers. Content is what you say and read: your messages, the pages you load. Metadata is everything around it: which domains you contact, when, how much data, from which cell tower.

Content is already largely solved. Around 95 per cent of web traffic is HTTPS, and modern messengers are end-to-end encrypted, so neither a visited network nor an eSIM gateway operator reads your WhatsApp messages or banking sessions in transit. What networks can see is metadata: server names during connection setup, IP addresses, volumes, timing, plus everything at the radio layer. We break this down fully in what your eSIM provider can actually see.

A VPN moves the metadata problem; it does not remove it. With a VPN active, the mobile network sees only an encrypted tunnel to one server, so it loses visibility of which sites you visit. The VPN provider gains exactly that visibility instead, which is why provider choice matters; see the best eSIMs for VPN users. What a VPN does not and cannot do is hide your physical location from the mobile network, mask your IMEI or IMSI, or prevent tower-level tracking. Anyone selling a VPN as protection against government location tracking is misinforming you.

Advantages and disadvantages of travel eSIMs for privacy

Advantages

  • No passport registration in local SIM databases for most destinations, unlike buying a SIM in Turkey, the UAE or India.
  • Traffic usually surfaces outside the visited country, reducing casual local visibility of your browsing metadata.
  • No market visit, no shop CCTV, no photocopied passport left with a reseller.
  • Set up before departure, so no dependence on airport kiosks; see also eSIM versus roaming.

Disadvantages

  • Radio-level tracking (IMEI, IMSI, cell location) is completely unchanged.
  • Purchase leaves a digital payment and account trail; cash anonymity is impossible.
  • Breakout countries are rarely disclosed, and research shows traffic can transit unexpected third-country networks.
  • Providers retain records for years and comply with legal demands, as their policies openly state.

Who should choose what

Ordinary travellers need no special measures. A travel eSIM from a reputable provider, HTTPS everywhere and sensible app hygiene put you in the same position as virtually every other visitor. The realistic privacy gain of an eSIM is staying out of local SIM registries; the realistic limit is that your location is always visible to the serving network. Pick a provider on coverage and value, not on privacy marketing; our eSIM reliability guide is the better basis for that decision.

Privacy-conscious travellers should choose a provider whose policies they have actually read, prefer short retention periods, add a reputable VPN for metadata protection on data traffic, and check where the provider's traffic breaks out.

Journalists, activists and others facing state-level adversaries should not treat any eSIM as protection. Your device's IMEI links every SIM you ever use in it, tower tracking works regardless of provider, and IMSI catchers target phones irrespective of SIM type. Serious threat models call for separate clean devices, specialist operational advice such as the EFF's Surveillance Self-Defense guides, and the assumption that any provider will comply with lawful orders. That is beyond what any consumer eSIM guide, including this one, can responsibly cover.

The verdict

Governments can track you through a travel eSIM in the same way they can track you through any SIM: via the visited network's view of your device identifiers and cell-tower location, and via legal demands to providers. Nothing about eSIM technology adds a surveillance capability, and nothing about it defeats one. The genuine differences are administrative and architectural: travel eSIMs keep your passport out of local registration databases in ID-mandatory countries, and they shift your internet traffic's exit point, and therefore its most convenient point of inspection, to another jurisdiction. For ordinary travellers that is a modest, real privacy improvement over registering a local SIM, bought at the price of a payment trail with a foreign provider. For anyone facing targeted state surveillance, an eSIM is not a shield, and no honest reviewer will tell you otherwise.

Frequently asked questions

Can a government track my location through a travel eSIM?

The authorities of the country you are visiting can obtain your location from the local network your eSIM roams on, because cell-level location is inherent to mobile service. This applies equally to physical SIMs, local SIMs and travel eSIMs, and a VPN does not prevent it.

Is an eSIM more private than a physical SIM?

At the network level they are equivalent. An eSIM avoids passport registration in many countries where local plastic SIMs require it, which is a real benefit, but it creates a payment and account trail and adds a chip identifier (the EID). Neither format hides your IMEI or location.

Do I need to show ID to buy a travel eSIM?

Usually not. Most travel eSIMs are roaming products and skip local registration laws, even for ID-strict destinations such as Turkey, the UAE and India. Some providers require a passport upload (eKYC) for specific countries where regulators demand it; Airalo, for example, flags these plans in its app before purchase.

Does a VPN stop government tracking on an eSIM?

Partly. A VPN hides which sites and services you use from the mobile network and from whoever operates the traffic gateway. It does not hide your physical location, IMEI or IMSI from the network carrying your signal, and the VPN provider itself then sees your traffic metadata.

Which country's laws apply to my travel eSIM data?

Several at once, which is the honest complication. The visited country's laws govern the radio network; the provider's home jurisdiction (Singapore for Airalo, Ireland for Holafly, the US and Lithuania for Saily) governs your account records; and the country where your traffic breaks out governs the gateway. Requests to the provider follow its local legal process.

Sources and fact-checking notes

  • Cell-tower tracking, triangulation accuracy, tower dumps and IMSI catchers - https://ssd.eff.org/module/mobile-phones-location-tracking - accessed 19 July 2026
  • Northeastern University USENIX Security study of 25 travel eSIM providers, IP geolocation mismatch, Hong Kong breakout, reseller access to location (~800 m) - https://www.itnews.com.au/news/travel-esims-secretly-route-traffic-over-chinese-and-undisclosed-networks-study-619659 - accessed 19 July 2026
  • Airalo privacy policy: data collected, disclosure to authorities, AirGSM Pte Ltd Singapore - https://www.airalo.com/more-info/privacy-policy - accessed 19 July 2026
  • Airalo eKYC requirements and process - https://www.airalo.com/blog/whats-an-ekyc-and-why-do-some-esims-require-it and https://www.airalo.com/help/getting-started-with-airalo/E8DFWD88SHUX/why-do-i-need-to-verify-my-identity/MEMBY8RNOAT0 - accessed 19 July 2026
  • Holafly privacy policy: Holafly Limited Dublin, retention (contract plus 7.5 years; 6 months connection history), law enforcement disclosure, carrier visibility of IMSI and IPs - https://esim.holafly.com/privacy-policy/ - accessed 19 July 2026
  • Saily privacy policy: Saily Inc and Saily UAB, IMEI, CDRs, SMS metadata, retention periods, law enforcement disclosure - https://saily.com/legal/privacy-policy/ - accessed 19 July 2026
  • Holiday.com privacy policy: data collected, retention until deletion request, subpoena disclosure - https://holiday.com/privacy-policy - accessed 19 July 2026
  • GSMA on mandatory prepaid SIM registration: ~160 governments, UK/USA/Czech Republic declined, no empirical crime-reduction evidence - https://www.gsma.com/solutions-and-impact/connectivity-for-good/public-policy/mobile-policy-handbook/consumer-protection/mandatory-registration-of-prepaid-sims/ - accessed 19 July 2026
  • SIM registration rules by country (India passport and visa, China biometrics, Turkey, UAE; travel eSIMs outside local registration) - https://simology.io/blog/sim-registration-country-top-30-destinations-do-you-need-id-2025 and https://voyeglobal.com/sim-card-id-requirements-vs-esim/ - accessed 19 July 2026
  • Hong Kong real-name SIM registration programme (OFCA) - https://www.ofca.gov.hk/en/consumer_focus/guide/hot_topics/sim_registration/index.html - accessed 19 July 2026
  • ETSI lawful interception requirements framework - https://www.etsi.org/deliver/etsi_ts/101300_101399/101331/01.06.01_60/ts_101331v010601p.pdf - accessed 19 July 2026
  • Airalo Turkey (Merhaba, Turk Telekom) plan page, no eKYC note at time of checking - https://www.airalo.com/turkey-esim/merhaba-7days-1gb - accessed 19 July 2026

Photo credits: David Hawgood (CC BY-SA 2.0), N Chadwick (CC BY-SA 2.0), all via Wikimedia Commons.