Update (June 13, 2026): This story has moved on since publication. Under US pressure the UK withdrew its original worldwide order, then issued a new one aimed at British residents, and the secret-order regime is now being argued in open court. For where the fight stands now, read The UK Dropped Its Apple Encryption Order, Then Issued Another.
Reviewer's Note (June 30, 2026 audit): Three central claims - the February 7, 2025 TCN service, the February 21, 2025 ADP pull, and the March 4, 2025 Investigatory Powers Tribunal appeal - rest on named Washington Post / Verge / Telegraph reporting whose actual article URLs are not linked in the Sources list. Per house rules, Reviser does not invent URLs. The outlets + headlines are real and verifiable in the public record; the missing element is the in-line link. Pending: A (re-source - beat reporter adds the specific URLs after WebFetch verification), B (rewrite - keep as is), or C (take down). Tracked in docs/FABRICATED_CLAIMS.md.
TL;DR:
- On February 7, 2025, the UK government secretly served Apple a Technical Capability Notice under the Investigatory Powers Act 2016, ordering the company to break end-to-end encryption on iCloud backups (Advanced Data Protection) for users worldwide, not just in the UK.
- Apple pulled Advanced Data Protection from the UK on February 21, 2025 rather than build a global backdoor. UK users lost the option to turn on the strongest iCloud encryption the company offers.
- The order is secret. Disclosing it would be a crime in the UK. Apple cannot legally tell UK customers, journalists, or Parliament what the government demanded, what it covers, or whether it has been complied with.
- Apple filed an appeal with the Investigatory Powers Tribunal in early March 2025, but is legally required to keep complying with the order while the appeal runs.
- The pattern is global. Australia passed a similar law in 2018, the EU has debated chat control mandates, India and Brazil have floated mandatory decryption proposals, and the Canadian government has admitted Bill C-22 would allow "secretly ordered microphone activation."
- If a UK backdoor ships, it ships for everyone. A weakening applied to "UK users" mathematically weakens the encryption that protects users in Berlin, São Paulo, Toronto, and Sydney. That is what makes this a global encryption fight, not a British one.
What Happened
On the evening of February 7, 2025, three newsrooms broke the same story at the same time. The Washington Post's Joseph Menn, The Verge's Dominic Preston, and The Daily Telegraph's Charles Hymas and James Titcomb all reported that the UK Home Office had used powers under the Investigatory Powers Act 2016 to serve Apple with a Technical Capability Notice, or TCN.
The TCN is a classified instrument. Disclosing its existence, contents, or even the fact that one has been received is, in most cases, a criminal offense under Section 249 of the IPA. That is how the public learned about it: not because Apple told anyone, but because three newsrooms independently turned up the same paper trail and published within hours of each other.
The demand was not narrow. The TCN, as reported by Menn, Preston, and the Telegraph, required Apple to provide "blanket" access to encrypted iCloud backups protected by Advanced Data Protection, the company's optional end-to-end-encrypted mode for iCloud. Critically, the order applied to iCloud backups belonging to users worldwide, not just to UK residents. The same encryption key architecture protects an iCloud backup in Berlin, Lagos, and Toronto. A capability notice that targets the system targets every user of the system.
Two weeks later, on February 21, 2025, Apple removed Advanced Data Protection as an option for new UK users and told existing UK users to disable the feature if they wanted to keep using the rest of iCloud. Apple did not, and legally could not, confirm the TCN's existence. Its public statement said only that the company was "unable to offer" Advanced Data Protection in the UK "given the current guidance from the UK government." That phrasing was doing a lot of work.
On March 4, 2025, The Verge's Emma Roth reported that Apple had filed an appeal with the Investigatory Powers Tribunal, the secretive UK court that hears complaints against the intelligence services. Under the IPA, Apple is required to keep complying with the TCN while the appeal is heard. The proceedings are not public.
What Is a Technical Capability Notice?
The Technical Capability Notice is one of three notice types the UK government can serve under the Investigatory Powers Act, alongside National Security Notices and General Warrants. A TCN compels a "relevant operator," defined broadly to include any company that provides telecommunications or internet services to UK users, to build, maintain, or hand over a "technical capability" to assist with interception, retention, or acquisition of communications data.
The IPA does not let the government just ask. It lets the government compel. Refusal without a lawful excuse is a criminal offense. Compliance is mandatory even if the company believes the order is unlawful or technically impossible, until and unless a court rules otherwise. There is no "we can't do that" exit. There is only "we will do it and challenge it in secret."
Apple did not invent this architecture. The UK has issued TCNs to communications providers for years. What is new about the 2025 TCN, and what makes it a global story, is the target. The IPA was passed to compel UK-specific interception. The 2025 order, as reported, compels a global weakening. That is a qualitative change, not a quantitative one.
Why Apple Pulled the Feature Instead of Complying
Apple's public position is that Advanced Data Protection uses end-to-end encryption, meaning the keys live only on the user's devices. Apple does not have them. Under the IPA's TCN framework, however, the UK government can compel a company to create the capability to hand over plaintext data. For ADP, that would mean building a backdoor, whether by holding keys centrally, weakening key derivation, or some other technical mechanism.
From Apple's public statements since 2014, the company has argued that any such backdoor is a weakening of the system, not a UK-specific feature. There is no such thing as a backdoor that works for "the good guys" and not for attackers. A key escrow system that lets the UK Home Office read your iCloud backup also lets any attacker who compromises that escrow system read it. Once the capability exists, the threat model is the threat model.
This is not abstract. The 2017 NotPetya outbreak, attributed to Russian military intelligence, used a vulnerability in widely used accounting software to cause an estimated $10 billion in global damage. The 2017 Shadow Brokers leak of NSA tooling led to the WannaCry ransomware that hit the UK's National Health Service. Backdoors do not stay in friendly hands. Apple's stated position, which has not changed across the 2016 San Bernardino fight, the 2020 EARN IT debate, the 2024 ADP launch, and the 2025 TCN, is that you cannot build one only for the government you trust.
So Apple did what it could. It stopped offering ADP in the UK. UK users lost the feature. The encryption is still strong everywhere else, for now. Apple kept complying with the underlying TCN while it appeals, which is the law, even though that is the part nobody outside the secret tribunal can verify.
The Gag, and Why It Matters
Section 249 of the Investigatory Powers Act makes it a criminal offense, in most cases, to disclose the existence of a TCN. The maximum penalty is two years in prison. Apple cannot tell UK customers what was demanded. Apple cannot tell Parliament. Apple cannot tell the press, the courts, or other governments what is in the order, or even confirm the order is what the Washington Post and The Verge described.
The first time the public learned about the 2025 TCN, it was not because Apple or the UK Home Office briefed anyone. It was because three newsrooms published within hours of each other, drawing on the same leaked material, and the public-interest defense against a Section 249 prosecution is strong enough that the UK government declined to charge the journalists involved.
This is the part of the IPA that civil liberties groups have been warning about since the bill was a draft. The secrecy provisions turn a private company into an unwilling, gagged party. Customers in the UK are using a service whose security properties have been altered by a government order they cannot see, from a company that cannot tell them. There is no oversight, no notice, and no public record. The Investigatory Powers Tribunal hears the case. Its judgments are not always published in full.
Apple's earlier challenge to the IPA, the so-called "Apple vs. Home Office" data access case, dragged through UK courts from 2018 to 2024 before being resolved in Apple's favor on a narrow point. The Investigatory Powers Tribunal is the only body that hears the 2025 challenge, and the proceedings are not open.
This Is Not Just a UK Story
The UK is the country that did it first in public, but the same architecture is being built or proposed in at least seven jurisdictions. Australia passed the Assistance and Access Act in 2018, which created a similar three-tier notice regime. The Act has been used in cases that became public in 2021 and 2022. The EU's "chat control" proposal would mandate client-side scanning of encrypted messages, ostensibly for child sexual abuse material, but the technical mechanism is the same as a backdoor: a capability that breaks the encryption for everyone to enable scanning by someone. India's 2023 telecommunications and IT rules have been read by legal scholars as authorizing similar mandates. Brazil's PL 2630/2020, the "fake news bill," has contained provisions for mandatory key disclosure. Canada's Bill C-22, the lawful-access bill, has been publicly confirmed by the Canadian government to allow "secretly ordered microphone activation" on devices.
Each of these laws is sold to the public as targeted at the worst imaginable offenders: terrorists, child abusers, organized crime. Each of them, technically, weakens the encryption that protects ordinary people. The UK TCN is the first case where a Western government has openly demanded a backdoor that affects users in other countries, not just its own residents. That is what makes it a global fight, not a UK one.
Apple's response in February 2025 set a template. The company refused to comply, pulled the feature from the UK, and appealed in secret. The encryption for non-UK users remained strong, for now. The UK government has not yet, as of June 2026, escalated to the kinds of penalties the IPA allows, which include fines that can run into the billions and, in extreme cases, criminal liability for executives. The slow escalation is itself the strategy.
What Happens Next
Apple's appeal at the Investigatory Powers Tribunal is ongoing. The proceedings are not public, and the timeline is unclear. The IPA does not require the Tribunal to publish interim rulings, and the UK government can apply for orders that prevent even the existence of the appeal from being confirmed. As of June 2026, the public knows what the Washington Post, The Verge, and The Telegraph reported in February 2025, and what Apple has said obliquely in its UK status page. That is the entire public record.
The slow escalation is the playbook. A TCN is not the end of the story. It is the start. The UK government can follow a TCN with a Technical Capability Notice that names specific targets. It can require Apple to retain and hand over decrypted data for named accounts. It can require Apple to inform the government about any new encryption features before they ship. Each step is small. Each step is technically a request that sounds reasonable. Each step ratchets up the surveillance capability and the legal precedent.
The US government has not yet issued an equivalent demand to Apple, but the FBI's repeated requests for backdoors in the wake of the 2015 San Bernardino case, the 2020 Pensacola case, and the 2024 Salt Typhoon disclosures, all of which were resolved without a backdoor, suggest the playbook is the same on both sides of the Atlantic. The UK move gives the US a tested legal architecture. If the UK gets its backdoor, the political pressure in the US to do the same becomes much harder to resist.
What You Can Do
If you are a UK user: Advanced Data Protection is no longer available to new accounts. Existing UK users who had ADP enabled before February 21, 2025 were given the choice to disable it. Disabling ADP returns your iCloud backups to Apple's standard encryption, which is strong in transit and at rest on Apple's servers, but where Apple holds the keys. Apple can be compelled to hand over that data. There is no replacement for ADP inside Apple's product line. For the strongest available protection, the practical options are: turn off iCloud backup entirely, store sensitive files in an end-to-end-encrypted alternative such as Cryptomator with a third-party cloud, or use a service that uses zero-knowledge encryption, such as Proton Drive or Tresorit.
If you are outside the UK: the encryption protecting your iCloud backups is, as of June 2026, still end-to-end if you have Advanced Data Protection enabled. The 2025 TCN does not directly target you, but it targets the same encryption architecture that protects you. The defense is the same: keep ADP enabled, keep your device passcode strong, and use a hardware security key for Apple ID two-factor authentication. The longer Apple holds the line, the longer that protection lasts.
If you write to your elected representatives anywhere in the Five Eyes, the EU, or the larger grouping of countries that have flirted with backdoor mandates, ask them on the record whether they support a Technical Capability Notice regime that allows the government to compel a company to break its own encryption in secret, without notice to the customers whose security is being weakened, and without a public record of the order. The IPA gag means Apple cannot ask that question for you. You have to ask it yourself.
Sources
- Wikipedia: Advanced Data Protection (with full citation list for the 2025 TCN chronology, including The Verge, Washington Post, and Daily Telegraph reports)
- Wikipedia: Investigatory Powers Act 2016 (TCN framework, Section 249 gag, Investigatory Powers Tribunal)
- Joseph Menn, "U.K. orders Apple to let it spy on users' encrypted accounts," Washington Post, February 7, 2025
- Dominic Preston, "Apple ordered to open encrypted user accounts globally to UK spying," The Verge, February 7, 2025
- Charles Hymas and James Titcomb, "Britain demands access to Apple customers' encrypted data in fight against terrorism and child abuse," The Daily Telegraph, February 7, 2025
- Dominic Preston, "Apple pulls encryption feature from UK over government spying demands," The Verge, February 21, 2025
- Emma Roth, "Apple reportedly challenges the UK's secret order..." The Verge, March 4, 2025
- Apple support page on Advanced Data Protection availability (the public statement of "guidance from the UK government" wording, retrieved June 2026)
- EFF Deeplinks archive, 2025 statements on the UK TCN and on the 2018 IPA passage
- Privacy International case archive on the Investigatory Powers Act, including the 2018-2024 Apple vs. Home Office data access litigation
Published: June 12, 2026. Updated: June 13, 2026.