Apple iCloud encryption encryption backdoor Investigatory Powers Act government surveillance cloud backup privacy

Apple Is Suing the UK Over an iCloud Backdoor. Your British Photos Are Already Readable Anyway.

Adrian Maverick · · 8 min read

Picture a person in London. iPhone in their pocket, iCloud switched on, photos and notes and a full device backup syncing to Apple the way they have for years. This week Apple went to court to defend that person's encryption from the British government.

Here is the uncomfortable part. That person's photos are already sitting on Apple's servers in a form Apple can read. No backdoor required. The government would not need one to ask for them.

That gap, between the fight in the headlines and the reality on the phone, is the whole story. Let me walk through both.

What Apple actually filed

According to the Financial Times, which broke the story, Apple has taken the UK government to the Investigatory Powers Tribunal. That is the court that hears cases about state surveillance. TechCrunch and Euronews, following the FT, report the complaint was filed in July 2026 and surfaced publicly on August 3.

The thing Apple is fighting is a Technical Capability Notice, or TCN. Under the UK's Investigatory Powers Act of 2016, a TCN is a secret order that can compel a company to provide access to user data, including data the company has encrypted. You are not allowed to confirm you received one. That secrecy is written into the law.

This is round two. Euronews reports the first order landed in January 2025 and reached for both UK and US customer data. That version set off a fight with Washington, and the UK backed off. Rather than build the backdoor, Apple did something blunt in February 2025: it switched off Advanced Data Protection for everyone in the UK. Apple's own support documentation confirms the feature has been unavailable to UK users since then. The government came back with a narrower notice aimed at UK users only. That narrowed notice is what Apple is now contesting in tribunal.

Apple's position, stated to Euronews and consistent with everything it has said for years, is simple. It will not build compelled access into its products, because any such tool, once it exists, is a weakness for every user everywhere, not just the ones a government names.

The part the coverage skips

Two things go almost entirely unsaid in the reporting, and both matter more than the courtroom drama.

The first is that a "UK-only" backdoor is a fantasy. Encryption is math, and math does not check your passport. If Apple builds a mechanism that can decrypt a British user's data on demand, that mechanism now exists. It can be copied, stolen, subpoenaed by the next country, or turned on quietly for someone who is not British at all. The narrowing from "UK and US" down to "UK only" sounds like a compromise. Technically it is meaningless. A door in the wall is a door in the wall, no matter whose name is on the request slip. This is exactly why Apple keeps saying the tool endangers everyone. It is not a talking point. It is how the cryptography works.

The second unsaid thing is the one that should change how you feel about your own phone. Advanced Data Protection has been off in the UK for over a year. That feature is the thing that end-to-end encrypts your iCloud backup, your photos, your notes, your files. With it off, those categories fall back to what Apple calls Standard Data Protection, where Apple holds the keys. Which means for the average UK iPhone user, the sensitive stuff is already readable by Apple, and therefore already reachable by a normal legal request. The tribunal case is about a possible future backdoor into the strong encryption. Most people never turned the strong encryption on, and in the UK they are not even allowed to.

So the real headline is not "government wants to break your encryption." It is "most of your cloud life was never end-to-end encrypted in the first place, and you probably assumed it was."

Is iCloud encrypted?

Short answer: yes, but not the way most people think, and the difference is everything.

iCloud is always encrypted in transit and at rest, so a random attacker or a snooping employee cannot casually read it. But there are two levels, and they are not the same threat model.

Under Standard Data Protection, the default, Apple holds the encryption keys for most categories. Your iCloud Backup, Photos, Notes, iCloud Drive, and more sit under this by default. Apple can decrypt them, which is convenient when you forget a password, and which also means Apple can be compelled to hand them over. A handful of categories, like your passwords in iCloud Keychain and your Health data, are end-to-end encrypted even here.

Under Advanced Data Protection, the opt-in mode, the keys live only on your devices. Apple cannot read the covered categories, and cannot hand over what it cannot read. This is the setting that actually delivers the privacy people assume they already have.

If you are outside the UK, you can turn Advanced Data Protection on right now, in Settings, under your name, iCloud, then Advanced Data Protection. It takes a minute. If you are in the UK, Apple has been ordered into a position where it cannot offer it to you. That is the entire fight.

What you can do about your cloud backups

You do not need to wait for a tribunal ruling to close the gap on your own data.

Turn on the strongest encryption your provider offers. For Apple users outside the UK, that is Advanced Data Protection. Flip it on. For anyone, the principle is the same: prefer services where the provider cannot read your data, not just ones where they promise not to.

Decide what actually belongs in a cloud backup. The most private data is the data you never uploaded. Sensitive photos, documents, and notes can live in a local or end-to-end encrypted store instead of a general backup where the provider holds the keys.

Assume standard cloud storage is readable by the provider. Not because they are villains, but because holding the keys means they can be forced to use them. Treat anything under provider-held keys as visible to a court order, and plan accordingly.

Spread your identity out. The reason one order to one company can expose so much is that so much of your life funnels through a single account. Separate services, separate logins, and separate email aliases mean no single legal request, breach, or backdoor drains the whole tank. This is the principle we build Secria on: keep encryption where the keys stay with you, and keep as little of you in any one place as the job needs. One option among several, and the habits above matter more than any product.

The uncomfortable takeaway

Apple deserves credit here. Pulling a feature for an entire country rather than quietly building a backdoor is a real stand, and dragging a secret surveillance order into open tribunal is rarer still.

But do not let the courtroom distract you from the phone in your hand. The lesson of this case is not that your encryption is under threat. It is that the strongest encryption is one secret order away from being switched off, and that most of us never switched it on to begin with. Governments will keep asking for the keys. The only data that survives that request is the data whose keys were never theirs to hand over. Check which kind you have.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.