Two convicted in U.K. for refusal to decrypt data
securityfocus.com
securityfocus.com
A decoy in simple.
They'll bring in a forensic investigator, who will explain to the judge/jury that TrueCrypt has a feature designed to be used by criminals to subvert the judicial process. Then, he will present the results of his investigation, which will show your drive to be consistent with you using that "plausible deniability" thing. Then, he will introduce external evidence that says you almost certainly have, I don't know, kiddie porn -- look, we can prove he downloaded it, here are the ISP logs, and here are the 47 intercepted posts which use the same nickname he used for his online banking, and here is the previous complaint against him for lascivious comments made to a young lady on Facebook.
That will probably be good enough to convict you of possession. Circumstantial, yes, but so are most convictions.
IANAL, but I believe there is no legal defence concerning self-incrimination, but you do generally have the right to remain silent. Doing so, however, now allows the court to draw conculsions from your silence.
Some years ago, for example, the warning given to suspects when arrested changed to: "You do not have to say anything, but it may hurt your defence if you do not mention something you later rely upon in court."
Unfortunately in this case, the offence is complete when you don't say anything (don't give up the key(s)).
And just for completeness, the caution in the UK is:
"You do not have to say anything, but it may harm your defence if you do not mention, when questioned, something which you later rely on in court. Anything you do say may be given in evidence."
There's no actual fifth amendment equivalent, but there _is_ a bill of rights (at least, since 1998). RiderOfGiraffes is exactly right about silence being a factor that can be drawn to the attention of a jury ...
On the subject of the bits of the Regulation of Investigatory Powers Act (2002) that make failure to hand over encryption keys an imprisonable offense, it's worth noting that an order to hand them over has first to be made in the process of a criminal investigation. If someone has encrypted data and refuses to hand over the keys despite facing a maximum 5-year prison term, then it's reasonable to presume that they consider the data to be so incriminating that they'd pull a _longer_ sentence if they decrypted it. I believe (but am not certain -- the powers have been used to rarely that there's little to go on) that a plausible explanation of why the keys are unavailable ("I generated a PGP keychain in 1996 out of curiousity, but I lost interest and stopped using it, and that was twelve PCs ago") would probably work in court (in the absence of evidence contradicting it).