Apple has launched a fresh legal challenge against the UK government’s demand for access to its customers’ encrypted data, months after it withdrew a security feature for UK users rather than comply with an earlier version of the same request.
The US technology company filed a complaint last month with the Investigatory Powers Tribunal (IPT), an independent court that examines claims of unlawful conduct by UK intelligence services.
At the heart of the dispute is whether the UK government can force Apple to give it access to iCloud data that is otherwise protected by encryption so strong that even Apple cannot read it.
According to an order issued by the court, the Home Office made a second request for backdoor access to encrypted iCloud data belonging to British users.
The UK backed down on its original demand last year after a heated dispute with Washington. That first order, issued under the Investigatory Powers Act in January 2025, sought access to UK and US customers’ data alike.
Authorities subsequently narrowed their approach, issuing a new “technical capability notice” (TCN) limited to UK users only later in 2025, which is the order Apple is now contesting.
TCNs compel companies to hand law enforcement agencies information for cases including terrorism and child sexual abuse, even where that data is protected by encryption.
Apple’s position
Apple has long insisted it will not build any form of compelled access into its products.
The company has argued more broadly that any such tool, once built, poses a security risk to all users, not just those targeted by a specific request.
It withdrew UK customers’ access to Advanced Data Protection, an optional iCloud security feature that encrypts data so thoroughly that even Apple cannot read it, after receiving the original order in February 2025.
Advanced Data Protection is an opt-in feature that adds end-to-end encryption on top of iCloud’s standard encryption, covering things like device backups, photos and notes.
Apple can restrict who is offered it by account region and country settings, the same way it restricts other region-specific features.
Technical capability notices remain shrouded in secrecy by law: companies that receive one cannot confirm its existence, and the government routinely declines to comment on individual cases, citing national security.
That secrecy is itself central to the objections raised by campaign groups, who argue that surveillance powers of this scale should face more public scrutiny than the current legal framework allows.




