Apple customers in the United Kingdom can now receive different security for the same categories of iCloud data, depending on when they enabled the company’s Advanced Data Protection feature. Existing users who switched it on before Apple withdrew the option can retain it, while other UK customers cannot newly activate it.
Advanced Data Protection, or ADP, extends end-to-end encryption to additional iCloud categories including backups, photos and notes. Under that design, Apple does not possess the keys needed to decrypt the protected material. Some especially sensitive iCloud categories are end-to-end encrypted by default, but Apple can decrypt other categories when ADP is not enabled and may be legally compelled to provide them.
The split dates to February 2025, when Apple stopped offering ADP to new UK users. The company said at the time that it had never built a backdoor or master key into its products and would not do so. The practical consequence is an unusual two-tier arrangement: a customer who activated ADP earlier may continue protecting the expanded set of data, while somebody with an identical device and service plan who missed that window cannot turn the feature on.
The withdrawal followed reporting that UK authorities had issued Apple a Technical Capability Notice under the Investigatory Powers Act. Such a notice can require a communications provider to maintain or develop the technical capability needed to comply with lawful access requirements. It does not itself authorize access to a particular person’s data, which would require the relevant legal authority or warrant. Notices are generally secret, limiting what recipients can say publicly about their contents.
The reported demand placed Apple’s encryption architecture at the center of the dispute. If a provider does not hold the keys to end-to-end encrypted information, it cannot simply retrieve readable copies on demand. Creating a mechanism to make that data accessible would change the security design, raising the risk that the same capability could be abused by criminals, hostile governments or other unauthorized parties.
Apple chose to remove the expanded protection from new UK activations rather than publicly announce a means of bypassing it. That decision did not eliminate end-to-end encryption from every iCloud service, and all iCloud data still receives encryption of some kind. It did, however, leave access to the broadest protection dependent on a user’s activation history.
For UK customers, the distinction matters because cloud backups and photo libraries can contain extensive personal records. The outcome also illustrates a broader policy conflict: governments seek lawful access for investigations, while security providers argue that an exceptional-access mechanism cannot reliably be limited to intended users. As of the event date, September 24, 2026, that conflict remains visible in the different protections available to people using otherwise equivalent Apple accounts and devices.



