UK Court: Apple iCloud Backdoor Secrecy Called “Farcical”

London’s Investigatory Powers Tribunal weighs whether the Home Office can legally stay silent on a surveillance order Apple itself has already challenged in court

Al Landes Avatar
Al Landes Avatar

By

Image: Deposit Photos | Gadget Review

Key Takeaways

Key Takeaways

  • UK court challenges government secrecy over Apple iCloud encryption order as publicly exposed.
  • Apple withdrew Advanced Data Protection in the UK rather than build an encryption backdoor.
  • IPT ruling could reshape how future UK surveillance orders are disclosed in high-profile cases.

A barrister representing two leading civil liberties groups told a London court on September 17, 2026, that the UK government’s refusal to confirm or deny ordering Apple to break its own encryption is “farcical” and “logically unsustainable.” The case, heard at the Investigatory Powers Tribunal, raises a question that touches your iCloud data directly: whether government secrecy over a surveillance order remains defensible once that secret is already public.

What the UK Government Actually Demanded

A Technical Capability Notice (TCN) is a legally binding order issued under the Investigatory Powers Act, compelling a company to build or maintain the ability to hand over data to UK authorities. According to court filings and BBC reporting, the Home Office served Apple with one in January 2025. The order initially required access to encrypted cloud backup data belonging to iCloud users globally, not only those in the UK.

The target was Apple’s Advanced Data Protection (ADP), an opt-in end-to-end encryption feature that locks iCloud backups so thoroughly that even Apple cannot read them. That level of protection is precisely what UK authorities wanted removed.

Apple Withdrew the Encryption Feature Rather Than Comply

Apple declined to weaken ADP and instead made it impossible to activate in the UK. In effect, Apple chose to reduce the security available to its British customers rather than compromise the underlying architecture for everyone.

A second TCN followed in October 2025, narrower in scope and focused specifically on encrypted backups belonging to British users, according to reporting from multiple outlets. ADP remains unavailable in the UK regardless, and Apple has challenged both notices before the Investigatory Powers Tribunal (IPT), a specialist court that handles complaints about the use of surveillance powers.

The Secret That Stopped Being Secret

The existence of the January 2025 TCN first reached the public through a leak to the Washington Post. Home Office sources then confirmed the report to The Times within hours, according to summaries of the disclosure chain cited in proceedings.

Investigatory Powers Commissioner Sir Brian Leveson later made a public statement on the matter: “lawful access can be achieved in a way that strikes a balance between maintaining strong encryption and ensuring law enforcement and the government can protect the public from terrorism, serious crime, and hostile state activity.” Civil liberties lawyers argue that statement itself presupposes such notices exist.

WhatsApp and Google have each filed witness statements with the tribunal confirming they have not received TCNs, a disclosure the law permits them to make freely. Apple, by contrast, is constrained from publicly confirming or denying whether it received one. Ben Jaffey KC, representing Privacy International and Liberty, pointed to one further detail at the September 17 hearing: Apple reportedly required permission before discussing the TCN with the US government, and that permission was granted. Jaffey argued that arrangement is itself evidence that a constraining notice exists.

The Government’s Case for Keeping Quiet

Counsel for the Home Office, Neil Sheldon KC, submitted that the Home Secretary’s decision to maintain a “neither confirm nor deny” (NCND) stance was neither irrational nor without evidentiary support. The government’s written position holds that acknowledging a TCN in one high-profile case would erode the doctrine across its entire surveillance portfolio. That exposure could allow criminals and hostile actors to infer which services are and are not subject to compelled access orders.

Jaffey’s counter-argument is pointed: there is a moment at which NCND becomes untenable, and that moment arrives when the information being protected is already in wide public circulation.

What Comes Next

The IPT’s eventual ruling on whether NCND can survive this level of public exposure may reshape how such orders are disclosed in future high-profile cases. For iCloud users in the UK, the immediate situation is unchanged. Advanced Data Protection is still unavailable, and the legal process that could restore it, or permanently close the question, is still working through the courts.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →