Apple's UK iCloud encryption splits users into two tiers

Apple's Advanced Data Protection (ADP) extends end-to-end encryption to iCloud categories such as backups, Photos and Notes, data Apple itself cannot decrypt. In January 2025, UK security officials secretly issued Apple a Technical Capability Notice under the Investigatory Powers Act 2016, a legal instrument that compels a company to maintain or build a capability to comply with future access demands, without itself authorising access to specific data. The Washington Post revealed the order on 7 February 2025, reporting that the UK's original demand sought access to encrypted iCloud data belonging not just to UK users but to Apple users worldwide. Recipients of such notices are generally barred from confirming their existence without the Home Office's permission.
Apple could not comply without building a mechanism to unlock ADP-protected data, something it says would function as a master key exploitable by hackers or hostile governments as well as legitimate authorities. Unable to discuss the notice directly, Apple instead announced on 21 February 2025 that Advanced Data Protection would no longer be available to new UK users, repeating its long-standing line that "we have never built a backdoor or master key to any of our products or services and we never will," and saying it was "gravely disappointed" by the outcome. Because ADP can only be toggled from a user's own trusted device and Apple's servers cannot change or roll back the setting remotely, the company could not switch it off for existing users either. The result is a two-tier system: UK residents who had already enabled ADP keep the stronger protection, while everyone else in the UK, whether they missed the deadline or bought an iPhone afterward, cannot turn it on. Apple has not published a deadline by which existing users must eventually disable the feature.
The dispute has continued in the Investigatory Powers Tribunal, the UK body that hears complaints about state surveillance. The UK's original global-reach demand was replaced in late 2025 by a narrower notice covering only UK citizens, after the Trump administration pushed back over the implications for American users. In July 2026, Apple lodged a fresh complaint at the tribunal, made public the following month. On 11 September 2026, Democratic Senator Ron Wyden and Republican Congressman Warren Davidson sent a joint letter urging the tribunal to open its proceedings, warning that Congress cannot exercise oversight if "foreign non-disclosure orders are weaponized" against US companies. On 17 September, the Daily Telegraph reported Apple had asked the tribunal to lift the gag order so it could confirm the notice publicly; Apple's barrister Daniel Beard KC argued this would let "facts to be deployed in the open," while lawyers for Liberty and Privacy International called the continued secrecy "farcical" and, through barrister Ben Jaffey KC, likened it to the "emperor's new clothes." The tribunal has not yet ruled on either Apple's underlying complaint or the request to unseal the proceedings.
The piece situates the standoff in Apple's decade-long resistance to encryption backdoors, from Tim Cook's 2014 interview about a US gag order and "no back door," through the 2015 San Bernardino case, in which the FBI sought Apple's help unlocking a shooter's iPhone after an attack that killed 14 people and wounded 22, and Apple refused, calling the requested tool "too dangerous to create" and the "equivalent of cancer," before the FBI got in via a third party and dropped its case.
Key facts
- The UK issued Apple a secret Technical Capability Notice in January 2025 under the Investigatory Powers Act 2016, seeking access to Advanced Data Protection encrypted iCloud data; The Washington Post revealed it on 7 February 2025.
- Apple withdrew ADP for new UK users on 21 February 2025 rather than build the requested access mechanism, but could not remotely disable it for existing users because the setting can only be changed from a trusted device.
- The UK's original demand reportedly covered Apple users worldwide; it was narrowed in late 2025 to UK citizens only after US pressure.
- Apple lodged a fresh complaint at the UK's Investigatory Powers Tribunal in July 2026, made public in August 2026, and in September asked the tribunal to lift the gag order barring it from confirming the notice's existence.
- On 11 September 2026, US Senator Ron Wyden and Congressman Warren Davidson urged the tribunal to open its proceedings, warning that secret foreign non-disclosure orders undermine congressional oversight of US companies.
Why it matters
This is a rare documented case of a Western democracy using a secret legal order to try to compel a major tech company to weaken end-to-end encryption for its users, not just for one suspect's device but, in the UK's original reported demand, for Apple customers worldwide. Apple's response, quietly dropping a security feature rather than building a backdoor, shows a company choosing to degrade its own product instead of creating an access mechanism it says could be exploited by hackers or hostile states.
Who it affects
UK iCloud users are split into two groups by an accident of timing: those who enabled Advanced Data Protection before 21 February 2025 keep end-to-end encryption on iCloud Backup, Photos, Notes and similar data, while new UK Apple customers and anyone who hadn't turned ADP on by that date cannot get it. The dispute also touches US oversight, since Senator Wyden and Congressman Davidson argue that a foreign gag order stops elected US lawmakers from questioning an American company about the demand.
How to use it
There is no action UK users can take: Apple has confirmed there is no way for someone who missed the window to enable ADP, and the company has not set a deadline for existing users to eventually turn it off. The only live process is legal, Apple's complaint and its request to unseal the case at the Investigatory Powers Tribunal.
How solid is it
The account rests on The Washington Post's February 2025 reporting of the Technical Capability Notice, Apple's own public statements and security documentation, and subsequent reporting by the Daily Telegraph on the tribunal proceedings, plus the September 2026 congressional letter. The UK Home Office does not confirm or deny the existence of the notice, so its existence and terms rest on that reporting rather than official acknowledgement, and the tribunal has not yet ruled on either Apple's complaint or the request to make the proceedings public.
Risks and caveats
The reported notice itself did not order Apple to withdraw ADP; it reportedly required Apple to maintain a technical capability to produce ADP-protected data under warrant, and Apple chose withdrawal as a way to satisfy that without building an access mechanism. The article does not say how many UK users are affected by the split, and the case used to illustrate it, two hypothetical iPhone owners named Alice and Bill, is the author's own device to explain the situation rather than real, named individuals from the reporting.
“If you put a back door in, then that back door is for everybody. For good guys and bad guys.”
— Tim Cook