Skip to content
← All news
4 min read

Apple is suing the UK again over its iCloud backdoor order

A rewritten Technical Capability Notice demands access to UK users' encrypted iCloud data. Apple's second Investigatory Powers Tribunal complaint will be heard in public, alongside Privacy International and Liberty.

Apple pulled encryption from the UK rather than break it. Now it is back in the tribunal.

Apple has filed a second legal challenge against the UK government's demand for access to encrypted iCloud data, taking a rewritten surveillance order back to the Investigatory Powers Tribunal. The Financial Times reported the filing on August 3, 2026. It is the latest round in a fight that has already changed what Apple ships in the UK: the company withdrew its strongest iCloud encryption from British users rather than build a way in.

The order Apple is fighting

The instrument is a Technical Capability Notice, a classified order under the UK's Investigatory Powers Act that can compel a company to provide the technical means to hand over user data, encrypted or not. The original notice reportedly targeted Apple's Advanced Data Protection, the opt-in feature that end-to-end encrypts iCloud backups, photos, and messages so that Apple itself cannot read them. Apple's response in early 2025 was to pull ADP from the UK entirely and challenge the notice; the government then rewrote the order to cover UK users specifically, and the new complaint, filed in July, challenges the rewritten version.

The fight is going public

TCNs are designed to be secret; recipients are normally barred from confirming they exist. This one will get its hearing in the open. The tribunal has confirmed it will hear Apple's case alongside challenges from Privacy International, Liberty, and two individuals, in public, using assumed facts in place of classified specifics, with a case management hearing expected next month. However it lands, it will produce precedent on whether a government can order a platform to weaken end-to-end encryption, from a tribunal that usually works in the dark.

Why a build studio cares

End-to-end encryption is a property software either has or does not; there is no version that opens for one government and holds against everyone else, which is why Apple removed the feature rather than modify it. That is the precedent that reaches us: what a platform can promise users is being set in this tribunal, and every product that stores user data on someone's platform inherits the outcome. The honest caveat is that the reporting chain is thin in places, the filing itself is not public and the details rest on the FT's sourcing, though Apple's earlier withdrawal of ADP from the UK is a matter of record.

Next step: read TechCrunch's report and CNBC's coverage. If your product makes privacy promises and you want the architecture to actually back them, write to us at hello@gattyworks.com.

ApplePrivacy LawEncryptionAppleUKEncryptioniCloudPrivacyLawInvestigatoryPowersActE2EESurveillanceDataPrivacyTechPolicy

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.