The Spectrum Dispatch News

technology

UK Government Ordered Apple to Weaken iCloud Encryption, Prompting Service Restrictions

After a secret legal notice, Apple withdrew its strongest encryption feature for new UK users, citing government pressure to create backdoor access to encrypted data.

UK Government Ordered Apple to Weaken iCloud Encryption, Prompting Service Restrictions

In January 2025, the UK government issued a secret Technical Capability Notice (TCN) to Apple, ordering the company to create a way to access encrypted iCloud data belonging to Apple users worldwide, according to reporting by The Washington Post. The notice was issued under the Investigatory Powers Act 2016, which grants UK authorities powers to compel technology companies to maintain capabilities for law enforcement access.

UK Government Ordered Apple to Weaken iCloud Encryption, Prompting Service Restrictions

Advanced Data Protection (ADP) is Apple’s strongest iCloud encryption feature, which encrypts additional categories of user data—including iCloud Backup, Photos, and Notes—using end-to-end encryption. With ADP enabled, Apple itself does not possess the keys needed to decrypt this data, meaning the company cannot comply with government requests for access, even with a warrant.

The TCN required Apple to develop a mechanism to decrypt ADP-protected data on demand. According to the source, Apple’s position remained consistent with statements made by Tim Cook over a decade earlier during the San Bernardino iPhone dispute: deliberately weakening encryption for any purpose would compromise security for all users. Creating such a backdoor, Apple argued, would make the system vulnerable to exploitation by hackers and hostile governments.

On February 21, 2025, Apple announced it would no longer offer Advanced Data Protection to new UK users, stating “we have never built a backdoor or master key to any of our products or services and we never will.” The decision effectively sidestepped the legal order by removing the feature that created the compliance dilemma, while reverting affected UK iCloud data to Standard Data Protection, where Apple retains decryption keys and can respond to lawful legal requests.

Apple maintained that it could not automatically disable ADP for existing UK users who had already activated the feature. The company said the decision left them “gravely disappointed.” Privacy International and other groups challenged the government’s approach through the Investigatory Powers Tribunal, arguing that secretly compelling technology companies to weaken encryption lacked adequate public scrutiny. The dispute reflects an ongoing tension between government surveillance capabilities and technological security architecture.

Key facts

  • The UK government issued a secret Technical Capability Notice in January 2025 requiring Apple to create access to encrypted iCloud data worldwide
  • Advanced Data Protection uses end-to-end encryption, meaning Apple cannot decrypt the data even when presented with a warrant
  • Apple withdrew ADP availability for new UK users on February 21, 2025, rather than comply with the order
  • Existing UK users who enabled ADP before the withdrawal can still use the feature
  • The dispute echoes Apple’s 2015 refusal to help the FBI access an iPhone used in the San Bernardino terrorist attack

Sources

← All posts