Apple added Advanced Data Protection to iCloud in late 2022. It extends end-to-end encryption to most of your iCloud data — including Photos, iCloud Backup, iCloud Drive, Notes, Reminders, Safari bookmarks, Siri shortcuts, Voice Memos, and Wallet passes.
With it enabled, not even Apple can read those files. Without it, Apple holds the encryption keys to most of what you store in iCloud.
Most iPhone users have never turned it on. If you haven’t, this guide is for you.
What “End-to-End Encrypted” Actually Means for iCloud
Before Advanced Data Protection, iCloud used a tiered approach to encryption. Some data — iMessage conversations, Health data, passwords saved in iCloud Keychain — was already end-to-end encrypted. Apple genuinely couldn’t read this data, and couldn’t produce it in response to a legal request.
Most iCloud data, however, including iCloud Photos, iCloud Backup, and iCloud Drive, was encrypted with keys Apple holds on its servers. Apple can access this data. If a government presents Apple with a valid legal order, Apple can and does produce it. If an Apple server experiences a breach that exposes encryption keys, your data could be exposed.
Advanced Data Protection changes this for the extended category list. When you turn it on, your photos, files, backups, and notes are encrypted with keys that only exist on your trusted devices. Apple’s servers hold only encrypted blobs they cannot decrypt. The encryption keys never leave your devices.
This is a meaningful difference, not a marketing claim.
What Is and Isn’t Covered
Advanced Data Protection extends end-to-end encryption to the following iCloud data categories (these were not E2EE before):
- iCloud Backup (including device and Messages backup)
- iCloud Drive
- Photos
- Notes
- Reminders
- Safari bookmarks
- Siri shortcuts
- Voice Memos
- Wallet passes
A small number of iCloud data categories are not covered by Advanced Data Protection, even when it’s enabled, because they need to interoperate with other systems:
- iCloud Mail: End-to-end encryption for email would break compatibility with external mail servers. iCloud Mail remains server-side encrypted, with Apple holding the keys.
- iCloud Contacts and Calendars: These use open standards (CalDAV, CardDAV) that require server-side access for interoperability with non-Apple devices and apps.
These are genuine exceptions, not loopholes. If you store particularly sensitive material in Notes, Photos, or your device backup, those are the areas where Advanced Data Protection matters most — and they’re covered.
The Trade-Off You Need to Understand Before You Enable It
This is the part most guides skip or bury. It’s the most important thing to understand before you enable Advanced Data Protection, and not understanding it is why some people lose access to their iCloud data after turning it on.
Apple cannot recover your data if you lose access to your account.
With standard iCloud, if you forget your Apple password, lose your phone, and can’t authenticate, Apple’s account recovery process can eventually get you back in. That process works because Apple has copies of your encryption keys.
With Advanced Data Protection, Apple has no copy. If you lose access to your account — lost device, forgotten password, no trusted device available — you can only recover your data using one of two methods you set up in advance:
- A recovery contact: A trusted person in your contacts who can approve your account recovery from their own Apple device.
- A recovery key: A 28-character code you generate and store somewhere safe.
If you have neither, and you lose access to your account, your data is gone. Apple cannot help you. This is not a bug in Advanced Data Protection — it’s the definition of end-to-end encryption. The only way to guarantee that Apple can’t read your data is to ensure Apple doesn’t have the keys, which means you bear the responsibility for what happens if the keys are lost.
Set up both a recovery contact and a recovery key before enabling Advanced Data Protection. Store the recovery key somewhere you’ll actually be able to find it: a password manager, a secure printed document in a safe, or both.
How to Enable Advanced Data Protection on iPhone
Requirements:
- iPhone running iOS 16.2 or later
- Two-factor authentication must be enabled on your Apple account
- All devices signed into your Apple account must run a software version that supports Advanced Data Protection — older devices that can’t update must be removed from your account first
Step 1: Open Settings and tap your name at the top.
Step 2: Tap iCloud.
Step 3: Scroll down and tap Advanced Data Protection.
Step 4: Tap Turn On Advanced Data Protection.
Step 5: Apple will prompt you to set up at least one recovery method before proceeding. You cannot skip this step — it’s a requirement of the feature, not optional. Set up a recovery contact, generate and save a recovery key, or both.
Step 6: Follow the remaining prompts. If any devices on your account are running older software that doesn’t support Advanced Data Protection, you’ll be asked to either update them or remove them from your account.
The entire process typically takes five to ten minutes, most of which is the recovery method setup.
How to Enable It on Mac
Step 1: Open System Settings (or System Preferences on older macOS versions).
Step 2: Click your name, then click iCloud.
Step 3: Click Advanced Data Protection.
Step 4: Click Turn On, then follow the prompts.
The same requirements apply: current macOS, two-factor authentication enabled, all account devices compatible.
What Happens to Your Existing iCloud Data
When you enable Advanced Data Protection, Apple re-encrypts your existing iCloud data with the new key arrangement. You don’t have to manually do anything with your existing photos, backups, or notes — the transition happens automatically as part of enabling the feature.
This process can take some time to complete in the background, depending on how much data you have stored. You’ll see a progress indicator in the iCloud settings during the transition.
A Note on Account Access After Enabling It
Two scenarios worth thinking through:
Switching to a new iPhone: When you set up a new iPhone and restore from an iCloud backup with Advanced Data Protection enabled, you authenticate from your old device or use your recovery method. The process is similar to standard iCloud restore — the difference is that you’ll need to authenticate more carefully, since without device access, the recovery key is your fallback.
What to do if you lose your phone: If your iPhone is stolen or lost before you can disable ADP from a trusted device, you’ll need to use your recovery contact or recovery key to regain account access. This is why storing the recovery key securely — not just “on your phone” — matters.
Does This Apply to iCloud.com Access?
When Advanced Data Protection is enabled, accessing your iCloud data from icloud.com in a browser requires a temporary authorization from one of your trusted devices. The web session is granted a temporary key — only for that session — which expires when the session ends.
You can turn off web access entirely from within the Advanced Data Protection settings if you prefer to never allow browser-based access to your E2EE data.
How Standard iCloud Compares to Advanced Data Protection
| Feature | Standard iCloud | Advanced Data Protection |
|---|---|---|
| Photos encryption | Server-side (Apple has keys) | End-to-end (Apple has no keys) |
| Backup encryption | Server-side | End-to-end |
| Notes encryption | Server-side | End-to-end |
| iCloud Drive encryption | Server-side | End-to-end |
| Apple can access in legal cases | Yes, for covered categories | No, for covered categories |
| Recoverable if you lose access | Yes, via Apple support | Only via your recovery method |
| Email encryption | Server-side | Server-side (unchanged) |
| Contacts/Calendars | Server-side | Server-side (unchanged) |
The right column is strictly more private. The cost is that the recovery responsibility moves entirely to you.
When You Should and Shouldn’t Enable It
Enable it if:
- You use iCloud Photos as your primary photo library
- You store sensitive documents in iCloud Drive or Notes
- You have concern about legal access to your iCloud data
- You’ve set up — and stored — both a recovery contact and a recovery key
Think carefully before enabling it if:
- You routinely lose or reset devices and rely on Apple support for account recovery
- You’re not confident you can reliably store and retrieve a 28-character recovery key
- You share an Apple account with family members who also need account-recovery access
This isn’t a recommendation against the feature — it’s genuinely the right choice for most users who take privacy seriously. But going in without the recovery setup in place is how people lose years of photos, and that outcome is preventable if you do the setup properly.
Where daftei Fits in This Picture
Advanced Data Protection is Apple’s answer for iCloud-stored data. It’s one of the best consumer privacy features any major cloud platform has shipped, and enabling it meaningfully improves the privacy of your iPhone’s photos and files.
If you store photos or files somewhere other than iCloud — or in addition to it — the encryption model of that service matters too. daftei encrypts files in transit with TLS 1.3 and at rest with AES-256, stored server-side. That’s a different model from iCloud’s Advanced Data Protection: daftei’s encryption is server-side, not end-to-end, meaning the architecture differs from E2EE. What daftei provides that’s complementary is a platform that never runs AI on your content, never trains third-party models on your files, never sells your data, and never shows ads — so the question of what Apple can legally access is a different risk profile from the question of what a storage platform does commercially with your content.
Both the encryption model and the business model are worth understanding for any service you trust with your personal photos and files. Advanced Data Protection addresses one. Knowing your storage provider’s incentive structure addresses the other.