Britain Quietly Built Two Tiers of Encryption. You're Probably in the Weak One.
In this article
Bottom line: In February 2025, Apple withdrew its strongest iCloud encryption, Advanced Data Protection (ADP), from new UK users after the Home Office served it a secret Technical Capability Notice under the Investigatory Powers Act.
The notice reportedly demanded access to encrypted cloud backups. Later reporting said a revised order targeted only British users' data.
If you're in the UK, your cloud backups sit in the tier Apple can open when legally compelled, and a demand for weaker encryption can be limited to one country's citizens.
I turned on Apple's Advanced Data Protection the week it launched, felt smug for about ten seconds, and never thought about it again. That's the problem.
Most of us treat encryption like plumbing: we assume it's there, and we only notice when it's gone.
For UK users, it's gone. In February 2025, Apple stopped offering ADP to new British customers. Existing users were later told they'd have to switch it off.
This isn't really a story about one feature. It's about a country establishing that the strength of your privacy depends on your postcode.
What Actually Happened
Here's the short version, as reported by the Washington Post and later confirmed in Apple's own behavior.
The UK Home Office issued Apple a Technical Capability Notice (TCN) under the Investigatory Powers Act 2016, as amended in 2024.
A TCN legally obliges a company to build or keep the ability to hand over data on request.
The recipient can't publicly discuss it, and the law's structure means it must comply while any appeal is pending.
The reported target was ADP, the opt-in setting that gives iCloud backups, photos and notes true end-to-end encryption.
With ADP on, Apple doesn't hold the keys, so it can't read your data even when a court asks. Without ADP, Apple holds the keys and can hand things over.
Apple's response was blunt. It pulled the feature from the UK rather than build a way in. It also challenged the order at the Investigatory Powers Tribunal.
Then the politics got messy. In August 2025, US Director of National Intelligence Tulsi Gabbard said the UK had agreed to drop the demand.
Later reporting, including from the Financial Times, said the Home Office had issued a fresh notice that focused on British users' data instead.
I can't independently verify what's been served since then, and by design nobody outside the process can. That secrecy is itself part of the story.
The Contrarian Reframe: This Was Never About Apple
The mainstream take is "government versus Big Tech," with Apple as either hero or hypocrite. I think that framing misses the point, and it flatters the wrong people.
Apple is a company that decided where to draw a line. It can do that because it has billions in revenue and a brand built on privacy. What about the messaging app with twelve employees?
The cloud storage startup? They don't get to pick a fight with the Home Office.
The real story is precedent. If a government can demand that a company keep a door open, and forbid the company from saying so, encryption becomes a policy setting instead of a mathematical property.
Math doesn't care about borders. Policy does.
Here's the part everyone underrates. Once encryption varies by country, every company has to build for it.
That means geofenced security, region-specific code paths and legal teams deciding who gets which cryptography. Each fork is a new place for bugs to hide.
Weaker encryption for one country's citizens is not a local problem. Whatever access exists is an access point, and access points have a habit of outliving the intentions of the people who requested them.
The Framework: The Three Tiers of Privacy
I've started thinking about digital privacy as three tiers. Not all data, and not all people, are in the same one.
Tier 1: Math-Protected
This is data where the provider truly can't read it. It's end-to-end encrypted, the keys live on your device, and the company has nothing useful to hand over. Signal is the standard example.
ADP, where available, is another.
The defining property is that the protection doesn't depend on anyone's good behavior. A subpoena gets you ciphertext.
Tier 2: Policy-Protected
This is data the company can read but promises to guard. Standard iCloud backups live here, as do most email and most cloud storage.
The protection is a promise, backed by terms of service, company ethics and legal process.
Policy protection is fine until the policy changes. That could be a new law, a new owner or a new government.
This is where UK users' cloud backups now sit, and it's where most of the world's already sit.
Tier 3: Geography-Protected
This is the new tier, and the one I think matters most. Here, your protection depends on where you are.
The same account, the same device and the same company give you different cryptographic rights in London than in Dublin.
I call this the postcode problem. Two people can buy the same phone on the same day. One gets math, and the other gets a promise.
The uncomfortable thing is that most people are in Tier 2 without knowing it. They never opted into Tier 1, and now some can't.
Why "I Have Nothing to Hide" Fails at the Technical Level
I get this pushback constantly, so let me answer it without the usual civil-liberties speech. Assume you really have nothing to hide from your government.
You still have something to hide from everyone else.
An access mechanism built for lawful requests has to exist somewhere: in a system, a process, a set of credentials, or a team of employees. Those are attack surfaces.
Criminals, foreign intelligence services and bribed insiders all target exactly that kind of thing, and they only need to win once.
You may trust the Home Office. Do you trust every system, contractor and credential that would sit between it and your photos? That's the actual ask.
There's also a scope issue. iCloud backups aren't a narrow slice of life. They hold messages, health data, location history, photos of your kids and your documents.
Backup access is close to full-device access, which is why security researchers treat it as the crown jewel.
What This Means If You're in the UK
Let's get practical, because a lot of readers are asking "so what do I do?"
If you use iPhone and iCloud:
- Check whether your backups are end-to-end encrypted. If you're in the UK and never had ADP on, assume they aren't.
- Consider turning off iCloud Backup and using a local, encrypted backup to a computer you control. It's less convenient, but the keys stay with you.
- Store the truly sensitive stuff (legal documents, medical records, source material if you're a journalist) somewhere encrypted with keys only you hold.
If you run a business or a team:
- Ask what your vendors actually encrypt, and who holds the keys. "Encrypted at rest" often means the vendor can still decrypt it.
- Ask whether any of your data is held under UK jurisdiction, because that changes what a legal demand can reach.
- Write down which tier each category of data lives in. Most companies I've talked to have never done this.
If you build software:
- Watch client-side and end-to-end design closely. If your architecture means you can't read user data, you can't be compelled to. That's a legitimate design choice, and increasingly a legal-risk strategy.
- Notice that services like WhatsApp and Signal have both publicly said they'd rather withdraw from the UK than break encryption, in response to the Online Safety Act's scanning provisions. That's the same fight on a second front.
The Timeline Problem
Here's what worries me most. It's now September 2026, roughly nineteen months after the first reports.
The pattern since then has been secret orders, partial denials, revised orders and a tribunal process that mostly happens out of public view.
A democracy can't meaningfully debate a policy it isn't allowed to know about.
The TCN system creates a situation where citizens learn about their own surveillance rules from leaks and corporate product changes.
Apple pulling a feature was, weirdly, the most transparent moment in the whole saga. It was the only way the public found out anything was happening.
That should bother you regardless of your politics. Tomorrow's government will inherit the same powers, and it may be one you like even less.
The Bigger Picture
I keep coming back to a simple thing. Encryption is one of the few places where ordinary people got a genuinely equal tool.
A teenager with a free messaging app has the same math protecting them as a defense contractor does. That's rare.
Two-tier encryption breaks that equality. It says the strength of your privacy is a privilege granted by geography, by regulation, and by whether your provider is big enough to fight.
Apple could walk away from the UK market's advanced encryption. Most companies can't afford to make that call, and most users never get a vote on it.
I don't think the answer is to pretend governments have no legitimate investigative needs. They do, and the tension is real.
But "build the door and trust us with the key" has never worked out the way its authors promised, and it usually gets proposed right before something goes wrong.
I turned on Advanced Data Protection and forgot about it, and I suspect a lot of people did the same.
What I've learned is that privacy you don't think about is privacy that can be taken without you noticing.
So here's my question for you: do you actually know which tier your most sensitive data lives in, and if you found out it was the weakest one, what would you change first?