Back to Blog
Policy & Regulation August 4, 2026 5 min read

Apple Fights the UK's Second Attempt to Force a Backdoor Into iCloud

Apple filed a new legal challenge at the Investigatory Powers Tribunal against a revised UK order compelling access to encrypted iCloud data, after the original global demand was withdrawn in 2025.

Apple Fights the UK's Second Attempt to Force a Backdoor Into iCloud

Apple has filed a fresh legal challenge at the UK’s Investigatory Powers Tribunal, contesting a revised government order demanding access to encrypted iCloud data. The case, filed in July 2026, targets a Technical Capability Notice (TCN) issued under the Investigatory Powers Act.

This is round two. The Home Office issued the original TCN in January 2025, demanding backdoor access not just to UK users’ data but globally — a scope so broad that Apple’s initial response was to pull Advanced Data Protection (ADP) entirely for UK users rather than comply. That global demand was withdrawn in August 2025, reportedly after diplomatic pressure from the US government. The Home Office then came back with a narrower, UK-specific TCN, and that revised order is what Apple is now challenging at the IPT — a specialized court that handles complaints about UK intelligence and law enforcement surveillance.

The technical dispute centers on Advanced Data Protection, Apple’s end-to-end encryption scheme covering iCloud backups, photos, and device data. UK authorities argue they need a technical capability to bypass ADP for investigations involving terrorism, serious organized crime, and child sexual abuse material. Apple’s position, consistent since the first TCN, is that there’s no way to build backdoor access for law enforcement without weakening the encryption for every user — including the ones the backdoor is supposedly meant to protect from criminals.

Privacy International and Liberty are running parallel complaints challenging the legality, necessity, and secrecy of the UK’s TCN regime more broadly. The secrecy piece matters procedurally: TCNs are typically issued under gag orders that prevent companies from confirming their existence, which is part of why this dispute has played out through leaks and legal filings rather than public government statements.

For anyone building products with client-side encryption, this case is the clearest live test of how far a national security apparatus can push a global tech company on backdoor access — and whether “UK-only” carve-outs are technically or legally coherent for a service built on end-to-end encryption. The IPT’s ruling, whenever it lands, will shape how other governments draft similar demands.

Sources

apple encryption privacy regulation