Apple is fighting the UK government again over encryption. The company filed a second legal challenge with the Investigatory Powers Tribunal in July 2026, pushing back against a renewed demand for backdoor access to iCloud data protected by end-to-end encryption.

The dispute matters beyond the UK — if Apple is forced to weaken encryption for one government, it sets a precedent that every government can demand the same, and any backdoor built for law enforcement is a backdoor that hackers can find too.

Apple Advanced Data Protection for iCloud encryption screen
Image: Apple

What the UK wants and what Apple did

The UK government uses “technical capability notices” — secret legal orders that compel tech companies to provide access to user data, even when that data is end-to-end encrypted. In early 2025, London secretly ordered Apple to build a backdoor into iCloud backups protected by Advanced Data Protection (ADP).

ADP is Apple’s optional encryption feature that extends end-to-end encryption to iCloud Backups, Photos, Notes, Voice Memos, and other categories. With ADP enabled, not even Apple can read your data — only you hold the keys.

Rather than comply, Apple disabled ADP entirely for UK users in February 2025. New UK users could no longer turn it on, and existing users were told to switch it off. That was Apple’s answer: if we cannot keep it secure, we will not offer it at all.

The timeline so far

  • February 2025 — UK secretly issues the first technical capability notice demanding iCloud backdoor access
  • February 2025 — Apple disables ADP for UK users rather than build a backdoor
  • March 2025 — Apple files its first legal challenge with the Investigatory Powers Tribunal
  • August 2025 — US officials intervene; UK drops demands covering American users’ data
  • October 2025 — UK issues a revised second order, this time targeting British users only
  • July 2026 — Apple files a second legal challenge against the revised order

Why this matters for everyone, not just UK users

The UK government has claimed that such backdoors do not imperil security or privacy — without explaining how. Security researchers universally disagree. A backdoor is a vulnerability by design. Once it exists, it can be exploited by anyone who discovers it, not just the government that requested it.

Apple maintains that it has never built and will never build a backdoor or master key into its products. The company’s position is that since it does not hold encryption keys for ADP-protected data, compliance with the order would require fundamentally weakening the security architecture — not just for UK users, but potentially for everyone.

Privacy International has also filed a complaint with the tribunal, adding external pressure on the UK to back down.

What UK users should know

If you are in the UK, you cannot currently enable Advanced Data Protection for iCloud. Your iCloud Backups, Photos, and Notes are encrypted in transit and at rest, but Apple holds the keys — meaning the company can hand data over if compelled by a court order. Standard iCloud encryption still protects your data from hackers breaching Apple’s servers, but it does not protect you from government access requests.

Users outside the UK can still enable ADP through Settings > [your name] > iCloud > Advanced Data Protection on iPhone, or System Settings > Apple Account > iCloud > Advanced Data Protection on Mac. If you value privacy, it is worth turning on — it is one of the few cases where a major tech company genuinely cannot access your data, even if asked.

There is no timeline for the Investigatory Powers Tribunal’s ruling. Until it decides, the standoff continues — and UK users remain without the strongest encryption Apple offers.

Sources: TechCrunch, 9to5Mac, AppleInsider, original reporting via Financial Times