London demands your encrypted iCloud backups

Apple is challenging a British order targeting your iCloud backups. Narrowed to the UK, the precedent knows no border.

The fact


In July 2026, Apple filed a complaint with the British Investigatory Powers Tribunal. The target: a new government order, a Technical Capability Notice, demanding access to the encrypted iCloud backups of United Kingdom users.

Everything you just read, you know it “according to the press” and no other way, because the Investigatory Powers Act forbids Apple and the Home Office alike from confirming that such an order even exists. The information comes from the Financial Times, then picked up by TechCrunch, 9to5Mac, AppleInsider, Euronews and MacRumors.


This is not the first round. In January 2025, an earlier order already targeted iCloud backups, but it covered both British and American customers. Washington gritted its teeth, diplomatic pressure built, and it was withdrawn in August 2025. The Home Office came back with a revised version, this time limited to United Kingdom users only. Same law, same mechanism, smaller map.


The secrecy runs so deep that no substantive hearing is publicly scheduled for the Apple case itself. The only reliable marker is a separate proceeding: Privacy International and Liberty are challenging this regime of orders, and their case will be heard in December 2026. Apple’s position has not budged an inch: it refuses to build any compelled access whatsoever, with one constant argument, once the tool is built it endangers every user, not just the ones targeted at the start.


Why it matters to you


The reflex, reading “limited to the United Kingdom”, is to relax. Wrong reflex. An access that shrinks geographically is not a retreat, it is a successful feasibility test. If Apple can technically isolate a single country’s backups to make them readable on demand, the same lever works for any country that learns to pull it. The perimeter changes. The precedent, though, knows no border.


Note too where the attack comes from. Not from a European text debated in broad daylight, not from a vote you can follow and contest. From a national order, secret, that neither side is allowed to comment on. It is another door into the same room.


Read more: Chat Control, the mass surveillance advancing across Europe


That leaves the real question, the one that decides whether this concerns you: what can an order like this technically reach? A standard iCloud backup is encrypted in transit and at rest, but with a key Apple holds. Translation, Apple can access it, so Apple can be compelled to. Advanced Data Protection, by contrast, switches your backups to end-to-end encryption, with no key on Apple’s side. What Apple does not hold, Apple cannot hand over.


And an iCloud backup is no small thing: it carries a copy of almost everything, messages, photos, app data, and without Advanced Data Protection, enough to decrypt your iMessages. A conversation that is supposedly end-to-end encrypted therefore becomes readable again through the backup, as long as the option stays off.


No public source says whether the revised order explicitly targets Advanced Data Protection. Do not let anyone tell you it does, that is hot air. What we can frame is the mechanism: without that option, your backup sits behind a lock Apple keeps a copy of the key to. With ADP, the copy does not exist.


Read more: The cloud is just someone else’s computer


One last point, to avoid a false sense of armor. Even with Advanced Data Protection turned on, iCloud Mail, Contacts and Calendar stay outside end-to-end encryption, for reasons of IMAP, CalDAV and CardDAV interoperability. The option protects your backups, not your inbox. For genuinely encrypted email, the game is played elsewhere.


What you do now


1. Check your Advanced Data Protection status: Settings, your name, iCloud, Advanced Data Protection. Without it, your iCloud backup is encrypted with a key Apple holds. With it, Apple has nothing to hand to anyone.


2. Keep in mind what the option does not cover. iCloud Mail, Contacts and Calendar stay outside end-to-end encryption, even with Advanced Data Protection on. For encrypted email, Proton Mail or Tuta do the job by architecture.


3. For whatever you refuse to trust to any third-party key, back it up locally on an encrypted disk, or use sovereign end-to-end encrypted storage. An order stops where the company holds no key.


4. The marker to watch is December 2026: the Privacy International and Liberty hearing against this regime of orders. Since the Apple case is kept secret, that is where the legal framework gets argued in public.


Sources