Apple Files New Complaint Against UK Demands for Encrypted iCloud Access, Citing Security Risks

Technical capability notices (TCNs) are secret government orders that can compel access to encrypted data, including ADP-protected iCloud backups; the latest order targeted UK users and did not apply to American users.
Apple maintains ADP data is end-to-end encrypted and keys stay on user devices, and has repeatedly said it has never built a backdoor or master key; the 2025 push would have forced weakening of ADP to grant access.
The 2025 demand began as a global request but was narrowed to UK users after Washington intervened, with the UK later withdrawing the global portion and pursuing a UK-only order.
Privacy International and Liberty have filed parallel complaints with the IPT about the legality and secrecy of TCNs, and a case-management hearing has been set to determine how to handle multiple complaints.
Apple has filed a fresh legal challenge against the UK government's demand to access encrypted iCloud data, according to TechCrunch. The company lodged the complaint with the Investigatory Powers Tribunal, an independent court that reviews government surveillance actions.
The dispute centers on a secret government order — called a Technical Capability Notice — that would force Apple to weaken its Advanced Data Protection system for UK users. Apple has never built a backdoor into its products and says it does not plan to start, Neowin reported.
The UK government issued Apple a Technical Capability Notice, or TCN, under the Investigatory Powers Act. TCNs are secret orders. They can compel a company to hand over encrypted data, even if the company does not hold the keys.
The order targets iCloud backups protected by Advanced Data Protection, or ADP. ADP is Apple's strongest security option. It keeps encryption keys only on users' devices, meaning Apple itself cannot read the data. The UK wants that to change for British users, according to Courthouse News.
The conflict began in early 2025 when the UK first demanded access. The original order was even broader — it applied globally, not just to British users. Washington intervened, and the UK narrowed the demand to UK users only, TechCrunch reported.
Apple responded by pausing ADP for UK users entirely. That means British customers can no longer turn on the highest level of iCloud encryption. Apple said building a backdoor or master key would weaken security for every user — not just those targeted by governments.
Apple is not alone in challenging the order. Privacy International and Liberty have both filed parallel complaints with the Investigatory Powers Tribunal, according to Neowin. Both groups argue that TCNs are illegal and dangerously secret.
A case-management hearing has been scheduled to decide how the IPT will handle the multiple complaints together. Apple and the UK Home Office have both declined to comment on the ongoing cases, TechCrunch noted.
Security experts warn that a backdoor is not a targeted tool. Once a weakness is built into a system, anyone who finds it can use it — not just governments. Criminals and foreign state actors could exploit the same flaw Apple was forced to create.
The case has drawn wide attention because it could set a global precedent. If the UK wins, other governments may issue similar demands. Privacy advocates say forcing Apple to weaken ADP would undermine trust in encrypted services worldwide, according to Courthouse News.
Publishers
16
Articles
13
Reach
29