Not saying I agree with your "not too bad" assessment. But your list is incomplete without considering the violations of third parties who have shared items in confidence that are now on the local device.
So:
4) All third parties (meaning people other than the traveler) who have their privacy violated in the process must be informed immediately of the full details of the privacy violation. Which communications, pictures, etc. were viewed and or copied and by whom, and how to follow up on these violations.
> All third parties (meaning people other than the traveler) who have their privacy violated in the process must be informed immediately of the full details of the privacy violation
This isn't a requirement when e.g. police search an office and so wouldn't seem appropriate in this case. NDAs, explicitly or implicitly (through statute), tend to exempt courts, regulators and law enforcement.
Many (most?) NDAs between companies represented by competent counsel do have notification provisions (if Company A is compelled to disclose information covered under the A/B NDA, Company A is required to inform Company B of the fact [unless legally prohibited from doing so.])
I think you're thinking of cases where there is a search warrant and the potential harm to third parties has been weighed against the needs of the investigation, which should be predicated on a robust assessment that determines that this particular case justifies the harm.
I don't think leaving the decision up to the agent at the point of entry, or basing it on some kind of random selection, is as robust as a good quality court issuing warrants. Though I'm contradicting my point elsewhere in this discussion about being generally skeptical of such courts.
So:
4) All third parties (meaning people other than the traveler) who have their privacy violated in the process must be informed immediately of the full details of the privacy violation. Which communications, pictures, etc. were viewed and or copied and by whom, and how to follow up on these violations.