security

Apple's Second Fight Against UK Encryption Demands

Apple filed a second legal challenge to the UK government's iCloud backdoor order in August 2026. What the ongoing battle means for cloud encryption everywhere.

In February 2025, Apple made an unusual announcement. Rather than comply with a secret UK government order requiring backdoor access to encrypted iCloud data, Apple disabled Advanced Data Protection for all UK users. The company refused to create a backdoor. Instead, it removed the encryption feature entirely from the jurisdiction.

That decision was widely reported as Apple’s final word on the matter. It wasn’t.

On August 3, 2026, Apple reportedly filed a second legal challenge with the UK’s Investigatory Powers Tribunal, contesting a new government order. The specific details of the order are secret — that’s the nature of UK government technical capability notices. But the pattern is clear: the UK government and Apple are in a sustained legal and technical conflict over whether Apple must provide access to data it has chosen to protect with encryption.

This isn’t just a UK story. The outcome will matter to cloud storage users everywhere.

How We Got Here: The Investigatory Powers Act

The UK’s Investigatory Powers Act 2016 — sometimes called the “Snoopers’ Charter” — grants the Home Secretary broad authority to issue Technical Capability Notices (TCNs) to communications providers. A TCN can require a company to build the capability to intercept or decrypt user communications.

The Act’s provisions were strengthened by the 2023 Investigatory Powers (Amendment) Act, which extended the government’s ability to issue notices to companies based outside the UK and to require that encryption-breaking capabilities be built before a specific product or feature is deployed.

The order that led to Apple’s ADP withdrawal in early 2025 was reportedly a TCN requiring Apple to provide access to iCloud backups for users worldwide — not just UK users. That’s the element that made the demand unusual even by the standards of government surveillance law: a domestic UK order purporting to reach encrypted data stored by users in the United States, Europe, and everywhere else.

Apple’s position was that complying would require building a global backdoor. Rather than do so, Apple withdrew the ADP feature from the UK, ensuring that UK users’ iCloud data is now protected only by Standard Data Protection — Apple’s conventional server-side encryption under which Apple holds the keys.

What Advanced Data Protection Was

Before February 2025, UK users could enable iCloud Advanced Data Protection, which extended end-to-end encryption to a broader set of iCloud data categories. With ADP enabled, Apple held no keys to the protected data. A court order compelling Apple to produce the data would have returned nothing useful.

The data categories protected by ADP included: iCloud Backup, iCloud Drive, Photos, Notes, Reminders, Safari Bookmarks, Siri Shortcuts, Voice Memos, Wallet Passes, and Freeform.

Without ADP, these categories revert to Standard Data Protection. That means Apple holds encryption keys on its servers and can, if legally compelled, produce the plaintext contents of your iCloud Photos library, your Notes, your backups.

UK users who had already enabled ADP before the cutoff retained it. New UK users and users who hadn’t enabled the feature lost access to it permanently, with no indication that Apple plans to restore it in the UK while the legal dispute continues.

The August 2026 Second Challenge

The specific content of the new government order Apple is challenging in August 2026 has not been made public — TCNs are secret and companies receiving them can be prohibited from disclosing their existence.

What has been reported is that Apple filed a complaint with the UK’s Investigatory Powers Tribunal contesting a new “technical capability notice.” Apple characterized the government’s demand as going beyond what UK law permits.

The Investigatory Powers Tribunal is the body tasked with oversight of UK surveillance laws. Appeals to it are rare, legally complex, and expensive. Apple pursuing a second formal challenge signals that the conflict has not resolved — and that the UK government has issued new demands since the first dispute over ADP.

The case is ongoing. Its outcome is not yet known.

Why This Matters Beyond the UK

The concern that Apple, privacy advocates, and cryptographers have raised consistently is the backdoor problem: there is no such thing as a backdoor accessible only to authorized parties.

Any system built to give the UK government decryption access to iCloud Photos is a system that has a recoverable key or a mechanism to bypass encryption. The security properties of that system are weaker than end-to-end encryption by definition. And weaker security properties are a vulnerability that doesn’t care about jurisdiction.

If Apple builds a mechanism to comply with UK TCNs, it’s building a mechanism. The operational security practices around that mechanism, the insider threats, and the risk of it being discovered or stolen by actors other than the UK government are all real attack surfaces.

This is why Apple described the original 2025 demand as requiring a “global backdoor.” Technical capabilities built to satisfy one government’s legal requirements don’t automatically stay within that government’s control.

The UK precedent also matters diplomatically. If Apple complies with UK government access demands, other governments — many with far weaker rule-of-law protections — have a template and a precedent to demand the same. The legal framework Apple has chosen to fight, rather than accommodate, is precisely because the first accommodation tends to become the floor rather than the ceiling.

Who Is Affected Right Now

UK users without ADP: If you’re in the UK and didn’t enable ADP before February 2025, your iCloud Photos, Drive files, Notes, and backups are currently under Standard Data Protection. Apple holds keys that it could produce under legal compulsion. Your data is more exposed than it would have been.

UK users who had ADP enabled: You retained ADP if it was active before the cutoff. Apple has not disabled existing ADP protections for users who already had them.

Non-UK users: For now, ADP remains available outside the UK and the current conflict hasn’t expanded to other jurisdictions. But the legal arguments being made, and the legislative frameworks being used, have parallels in legislation pending or enacted in Australia, Canada, the EU, and India.

Anyone using iCloud with Standard Data Protection globally: Standard Data Protection has always meant Apple holds your encryption keys and can be legally compelled to produce them. The UK dispute has clarified, publicly and visibly, what “Standard Data Protection” means in practice.

What It Means for Cloud Storage Choices

The Apple-UK dispute is a useful lens for evaluating any cloud storage service’s encryption claims.

Server-side encryption means the service provider holds the keys. The service encrypts your data, but it also has the technical ability to decrypt it — and can be legally required to do so by governments in the jurisdictions where it operates.

End-to-end encryption (true E2EE) means only you hold the keys. The service provider cannot decrypt your data even if compelled. This is what ADP provided for specific iCloud categories.

Almost every mainstream cloud service uses server-side encryption. That includes Google Photos, iCloud with Standard Data Protection, OneDrive, Dropbox, and most alternatives. Server-side encryption is meaningful protection against external attackers. It is not protection against the service provider being legally compelled to produce your data.

Daftei uses TLS 1.3 in transit and AES-256 at rest — which is server-side encryption. That’s an honest description of the protection model: strong encryption against interception and external breach, but not end-to-end encryption where only you hold the key. Understanding this distinction is more important now than ever.

The Apple-UK case has made server-side encryption’s limitations more visible to mainstream audiences. The tradeoffs between cloud convenience and cryptographic control are real, and the legal landscape around them is actively shifting.

The Broader Encryption Battle

The Apple-UK conflict is part of a longer-running global debate. Governments have argued for years that they need mechanisms to access encrypted communications for law enforcement purposes. Cryptographers and security researchers have argued, with equal consistency, that any such mechanism weakens security for everyone.

The EU’s proposed Chat Control regulation — which would have required scanning of encrypted messages for illegal content — stalled repeatedly amid strong opposition from member states and civil society. Australia’s Access and Assistance Act created a framework that has drawn legal challenges from technology companies. The Five Eyes intelligence alliance has issued joint statements calling on tech companies to provide lawful access to encrypted data.

Apple’s decision to fight rather than comply is significant because it comes from a company with substantial leverage — it operates the platform on which a large share of smartphones run. The outcome of the Investigatory Powers Tribunal case will establish UK precedent. Whatever that precedent is, it will be referenced in legal arguments in other jurisdictions.

For anyone thinking carefully about where to store personal data, the relevant takeaway is simple: understand what encryption protections are and aren’t being offered, understand the legal jurisdiction of the storage provider, and make an informed choice about what level of legal access risk you’re comfortable with.

The Apple-UK case hasn’t been resolved. But it has clarified the terms of the debate in ways that matter for every cloud storage user.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts