Apple Fights the UK's Second Demand for a Backdoor Into Encrypted Data
Key Takeaways
- Apple filed a legal complaint last month at the UK's Investigatory Powers Tribunal (IPT), challenging a second government demand for backdoor access to encrypted iCloud data belonging to British users.
- The new "technical capability notice" is scoped only to British users — unlike the first order, which would have applied to UK and US customers and was dropped after US government pressure in 2025.
- Apple is challenging not just this specific order but the UK's broader power to issue TCNs under the Investigatory Powers Act — a wider legal challenge with significant implications for encryption globally.
- Privacy International and Liberty have parallel complaints already at the IPT; a case management hearing is scheduled for next month. Both Apple and the Home Office are legally restricted from discussing the existence of TCNs.
Apple filed a legal complaint last month at the UK's Investigatory Powers Tribunal — an independent court with the power to investigate claims that UK intelligence services have acted unlawfully — challenging a second government demand for backdoor access to encrypted iCloud data belonging to British users, according to reporting by the Guardian and Reuters, published August 3rd, 2026.
The demand came in the form of a "technical capability notice" (TCN), a secret legal order that compels companies to provide access to user data, including data protected by secure encryption.
This is the second such order the UK has issued against Apple. The first, issued in early 2025, would have applied to both UK and US customers. It was dropped after a heated transatlantic dispute involving the Trump administration.
The new order was subsequently issued in October 2025, scoped only to British users — a narrowing that removed the US political pressure that killed the first one. Apple confirmed the filing but declined to comment further. Both Apple and the Home Office are legally restricted from discussing TCNs publicly.
The specific target is iCloud data protected by Apple's Advanced Data Protection (ADP) — a feature that makes backups end-to-end encrypted and inaccessible to anyone, including Apple itself. After the first order, Apple withdrew UK users' access to ADP entirely in January 2025. UK iCloud users have been operating without that protection for over a year.
This Challenge Is Bigger Than One Order
What makes this legal complaint particularly significant is its scope. According to the Guardian, Apple is challenging not just this specific TCN, but the UK government's broader power to issue TCNs under the Investigatory Powers Act. That's a wider legal argument — one that could, if successful, constrain the entire framework through which the UK compels companies to undermine encryption.
Privacy International and Liberty, which had already filed a separate complaint against TCNs at the IPT, have submitted requests for Apple's claims to be heard in public given the public interest in the matter. A case management hearing to decide how the parallel complaints will be handled is scheduled for next month.
Privacy International's spokesperson said: "If it relates to the previously reported orders aimed at undermining the security of Apple's iCloud storage, then Apple's claim, alongside ours and Liberty's, is crucially important to preserving all of our privacy and security."
Apple has previously stated it has "never built a backdoor or master key to any of its products or services and never would." Ruth Ehrlich, director of external relations at Liberty, put the stakes plainly: "This is a hugely important case that will have far-reaching implications for the public's privacy rights well into the future. Opening a backdoor to all of that information carries a wide range of risks to our personal data."
The UK government's position, delivered through a spokesperson, was: "The UK supports strong encryption and robust privacy protections, but it is also vital that law enforcement can access communications when necessary and proportionate to protect the public from terrorism, serious crime, and child sexual abuse."
No Such Thing as a Backdoor Only Governments Can Use
The UK government's framing — that backdoor access can be limited to legitimate law enforcement use cases, applied only when "necessary and proportionate" — runs up against a technical reality that doesn't bend to policy intent. Encryption either works for everyone or it doesn't work for anyone.
A system designed to allow government access to end-to-end encrypted data is a system with a vulnerability built into its architecture. That vulnerability doesn't remain exclusive to the government that demanded it. It's available to anyone who finds or exploits it — foreign intelligence services, criminal actors, or future governments with different values than the ones that created the access point.
Apple made exactly this argument when the first TCN was issued: removing ADP "would make users more vulnerable to data breaches from bad actors and other threats to customer privacy." Creating a backdoor means Apple itself can access the data — which means it can be compelled to share it with any law enforcement agency holding a warrant, anywhere. The "national security" framing of the original request doesn't contain the exposure to that use case.
I've written about the UK's direction of travel across several stories this year — the Online Safety Act, the social media age ban, the proposed VPN restrictions that were ultimately ruled out. Each of these represents an expansion of state access to digital infrastructure.
The backdoor demand is the sharpest version of that trajectory: a government demanding that a private company break its own encryption guarantees on the government's behalf, in secret, with no public oversight. Apple fighting it — publicly, through the courts, in a case now joined by Liberty and Privacy International — is the right response. The outcome will matter well beyond the UK.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
