Apple has filed a fresh Apple UK iCloud access challenge, asking the Investigatory Powers Tribunal to review the British government’s authority to demand access to encrypted iCloud backups of UK users. The company confirmed the filing, first reported by the Financial Times, but declined to discuss its arguments or the reported demand’s terms.
The dispute concerns a reported Technical Capability Notice, or TCN, issued under the Investigatory Powers Act. The notice’s contents are not public. The Financial Times reported that it sought access to encrypted cloud backups belonging to British users and did not extend to US users.
That scope matters. Britain reportedly abandoned an earlier demand covering both UK and US customer data last year after a dispute with Washington, then issued the narrower notice. Apple is now challenging the government’s power to issue such notices, according to the Financial Times.
What does the UK want from Apple’s encrypted iCloud backups?
A TCN can require a company to maintain a technical ability to assist UK authorities. In this case, reporting describes a demand involving data protected by encryption. The government does not confirm or deny individual TCNs, and the law restricts recipients from publicly acknowledging or detailing them. That leaves the precise technical requirement, and Apple’s complete legal case against it, undisclosed.
The Home Office said it supports encryption and privacy protections, while arguing that law enforcement may need proportionate access to communications in cases involving terrorism, serious crime and child sexual abuse. It said the Investigatory Powers Act includes safeguards and independent judicial oversight.
Apple’s established position is that it has not made, and will not make, a backdoor or master key for its products. Whether the reported notice would require either is a characterization contested in the wider encryption fight, rather than a detail revealed in public filings.
Why Advanced Data Protection is part of the case
The backdrop is Apple’s Advanced Data Protection, an optional iCloud setting that uses end-to-end encryption for protected data. With that setup, the encryption keys are held on the user’s devices rather than by Apple, so Apple cannot read the protected content. Encryption works by turning readable data into ciphertext that requires the right key to unlock.
Apple removed Advanced Data Protection from the UK in January 2025 after receiving the earlier TCN. The new complaint does not restore the feature for British customers; it begins another legal test of the state’s power to compel access capability from a provider whose service was designed to deny the provider that access.
Privacy International and Liberty have already brought separate complaints about TCNs before the tribunal. Privacy International said it did not know the substance of Apple’s claim, but welcomed the filing. The group told the Financial Times that a case-management hearing on how the related challenges should proceed was scheduled for next month.
This story draws on original reporting from The Record.