In early 2025, the UK government secretly ordered Apple to build a backdoor into iCloud’s strongest encryption tier, using a Technical Capability Notice issued under the Investigatory Powers Act. Apple’s response wasn’t to comply and it wasn’t to fight indefinitely in secret — it withdrew Advanced Data Protection (ADP) from the UK entirely. The legal fight over that order has continued through 2026, with courts so far siding with the government’s ability to issue the demand, and privacy organizations pursuing further challenges.
The practical result: UK iCloud users today have measurably weaker encryption protections than users in most other countries, not because of a technical limitation, but because of a deliberate legal and policy decision made on their behalf. It’s a concrete case study in something that’s easy to discuss abstractly and much more useful to understand concretely — what “private” actually means when a government, not a hacker, is the one asking.
What Advanced Data Protection Actually Did
Standard iCloud backups are encrypted, but Apple holds the decryption keys for most data categories — which means Apple can, and does, hand over iCloud data in response to valid legal requests, including from law enforcement.
Advanced Data Protection changed that for users who opted in. With ADP enabled, the encryption keys for most iCloud data categories — including device backups, photos, notes, and more — are held only on the user’s own trusted devices, not by Apple. The technical claim was straightforward: even if compelled by a court order, Apple could hand over only encrypted data it couldn’t itself decrypt, because it never held the key.
That’s the same underlying model — zero-knowledge or end-to-end encryption — that providers like Tresorit and Internxt build their entire product around, and the same one Apple offered as an optional upgrade rather than a default.
What the UK Government Demanded
The Technical Capability Notice reportedly ordered Apple to create a method for UK authorities to access ADP-protected data on demand — in effect, to build the backdoor that the zero-knowledge model is specifically designed to make impossible. Critically, reports indicated the original order wasn’t limited to UK citizens’ data; it would have applied globally, to any ADP user whose data UK authorities wanted to access, regardless of where that user lived.
This is the standard tension at the center of every government backdoor debate: a backdoor built for “lawful access” by one government is, by construction, a backdoor that exists for anyone who can get to it — a different government, a future administration with different priorities, or an attacker who compromises the access mechanism itself. Encryption that can be selectively bypassed for the “right” requester isn’t really the same encryption anymore.
What Apple Actually Did
Apple didn’t build the backdoor, and didn’t continue offering ADP in the UK while fighting the order in court. Instead, it withdrew Advanced Data Protection from the UK market entirely — both for new users, who can no longer enable it, and reportedly for existing users, who lost the protection they’d already turned on.
This was, in effect, Apple’s way of honoring the zero-knowledge promise: rather than maintain a feature it could be compelled to compromise, it removed the feature where the legal environment made that compromise possible. The UK government revised its order at some point to apply only to UK users specifically rather than globally, which is part of why the case proceeded the way it did — but the underlying outcome stands. UK iCloud users today have access to standard iCloud encryption, where Apple holds the keys, but not to the stronger tier where it doesn’t.
The legal fight hasn’t fully resolved. A tribunal dismissed Apple’s procedural challenge over the secrecy of the proceedings, and organizations including Privacy International and Liberty have pursued further complaints into 2026 over the government’s use of secret surveillance orders more broadly. For now, the practical reality for UK users hasn’t changed back.
Why This Matters Beyond Apple and Beyond the UK
The specifics are about Apple and the UK, but the underlying lesson generalizes, and it’s worth taking seriously regardless of which country you’re in or which provider you use.
“End-to-end encrypted” can be a claim about today, not a guarantee about tomorrow. ADP was genuinely zero-knowledge encryption while it was available. It stopped being available to UK users not because the cryptography failed, but because a government with legal authority over Apple’s UK operations made it commercially and legally unworkable to keep offering. Any provider’s encryption posture exists inside the legal jurisdiction it operates under, and that jurisdiction can change the terms.
Government access requests are a more realistic threat model for most providers than a sophisticated cryptographic attack. The UK didn’t try to break Apple’s encryption. It used legal authority to compel a change in what Apple offered. Any provider, anywhere, is subject to the legal regime of the countries it operates in, and that’s a different, often more relevant question than “how strong is the encryption algorithm.”
This is exactly why providers should be specific, not just reassuring. A privacy policy that says “your data is private” without specifying the encryption model, who holds the keys, and what jurisdiction governs the service is making a claim that can change without you ever being told. The Apple-UK case is a clear, documented example of that exact shift happening to a major, trusted provider — if it can happen to Apple, “trust the brand” isn’t a sufficient due-diligence step on its own.
Why Apple Chose Withdrawal Over Compliance
It’s worth sitting with why Apple’s response took the specific shape it did, because the alternative paths were available and Apple didn’t take them.
Apple could have built the access mechanism the government requested. It chose not to, consistent with its long-stated public position that it has never built a backdoor into its products and considers doing so a dangerous precedent regardless of which government is asking. Apple could also have kept fighting the order in court while continuing to offer ADP in the meantime. It didn’t do that either — it withdrew the feature first, then continued the legal challenge separately.
That sequencing matters. It suggests Apple treated the order as binding and actionable immediately, rather than as something to contest while maintaining the status quo. For users, the practical lesson is that a company’s stated privacy commitments and its actual legal obligations can diverge with very little warning, and when they do, the obligations tend to win — not because the company’s commitments were insincere, but because a Technical Capability Notice under the Investigatory Powers Act comes with legal force a privacy policy doesn’t have on its own.
The Part of This Story That’s Easy to Miss
Much of the coverage of this case focuses on Apple and the UK government as the two parties in conflict. The detail that’s easier to miss is what happened to existing ADP users specifically — people who had already opted in, already understood they were getting a stronger protection tier, and then had that protection withdrawn after the fact, through no action of their own.
That’s a meaningfully different experience than a company simply not offering a feature in a given country. It’s a company offering a security guarantee, users relying on it, and then the guarantee being removed retroactively because of a legal order most of those users never knew existed until it became public. For anyone evaluating a provider’s privacy claims, this is the scenario worth asking about directly: not just “what do you offer today,” but “what happens to that offer if your government changes the rules tomorrow, and would I be told?”
How to Actually Evaluate “Private” Storage After This
A few concrete questions are more useful than general reassurance, and the Apple-UK case is a good lens for asking them about any provider you use or are considering.
Does the provider specify its encryption model precisely? “Encrypted” alone tells you almost nothing. Zero-knowledge/end-to-end encryption, where the provider never holds the decryption key, is a meaningfully different — and stronger — guarantee than server-side encryption, where the provider holds the key but commits by policy not to misuse it. Both are legitimate models. The difference matters for what threat each one actually protects against.
What jurisdiction is the provider legally subject to, and what’s its track record under pressure? A provider operating primarily under GDPR has different legal obligations and protections than one without comparable jurisdiction. This doesn’t make one model universally safer, but it’s a factual question worth having an answer to.
If the threat you’re worried about is a government request rather than a criminal hack, zero-knowledge encryption is the only model that structurally limits what a provider can hand over — because it limits what the provider can technically access, not just what it’s willing to access. If that’s your specific threat model, this is the deciding factor, full stop.
If your realistic concern is closer to “I don’t want a company reading my photos to sell ads or train AI,” the calculus is different. Server-side encryption with explicit, audited commitments — no ad sales, no third-party AI training, GDPR/CCPA compliance, a defined deletion policy — addresses that threat directly, even though the provider technically holds the keys. The Apple-UK situation is specifically about the first threat model, government-compelled access, and doesn’t change much about the second.
Where This Leaves Most People
Most individuals aren’t weighing their storage choice against a state-level Technical Capability Notice. But the Apple case is a useful, concrete reminder that “private” is not one fixed thing — it’s a set of specific technical and legal commitments, and those commitments can be tested, and sometimes changed, by exactly the kind of pressure most users never see happen.
daftei’s model is server-side encryption, not end-to-end — AES-256 at rest, TLS 1.3 in transit — and it’s described that way deliberately rather than marketed as something stronger. What it commits to instead is explicit: GDPR and CCPA compliance, no data sales, no third-party AI training on your content, no ads, and a defined 30-day deletion window before permanent erasure. That’s a different threat model than zero-knowledge encryption addresses, and it’s worth knowing which one actually matches what you’re trying to protect against before choosing where your files live.