They didn't get the data from his phone and will likely lose the case against him. They probably wanted data to go after other people and those people were protected against it.
It was likely unnecessary to use the duress PIN/password. He likely would have been better off simply refusing to provide the PIN/password. He could have rebooted or powered off the device before going through but even without that it would have automatically rebooted itself after 18 hours by default, or a lower time if he had configured one.
With a lot more preparation he could have done an encrypted backup, wiped the device and restored it later but that's very inconvenient.