Two-Tier Encryption in the UK – Identical Apple Devices, Different Protection
First reported by Macanorak ·
Your iCloud data encryption level in the UK now depends on when you enabled a specific Apple feature.
In the UK, identical Apple devices now offer different levels of data protection due to a policy change regarding Advanced Data Protection (ADP). Alice, who enabled ADP before February 2025, has her iCloud data end-to-end encrypted. Bill, who missed the window, cannot enable ADP and thus has less protection. This situation stems from a UK government order, reportedly a Technical Capability Notice (TCN) issued in January 2025, compelling Apple to create a method for accessing end-to-end encrypted iCloud data. Apple, adhering to its stance against weakening encryption, could not comply without compromising user security globally. As a result, Apple withdrew the option for new UK users to enable ADP, creating a "two-tier" system. Existing users like Alice retain ADP unless they proactively disable it, while new users or those who missed the initial opt-in window are reverted to standard protection where Apple holds decryption keys. The government's initial demand reportedly sought worldwide access, but was later narrowed to affect only UK citizens.
The UK government's secret order to Apple, forcing the creation of a capability to bypass end-to-end encryption, has resulted in a significant divergence in user data security within the same country. This move by the UK government, ostensibly to enable law enforcement access, highlights a growing global tension between national security demands and the principles of strong, unbreakable encryption. Apple's refusal to build a 'backdoor' and subsequent withdrawal of Advanced Data Protection for new UK users demonstrates the immense pressure tech companies face when complying with government mandates that conflict with their security architectures.
This situation creates a precedent where a government can effectively bifurcate the security offerings of a major tech company for its citizens, not based on user choice but on historical access to a feature. The implications extend beyond Apple, signaling that other services relying on end-to-end encryption, such as messaging apps and cloud storage providers, may face similar demands. The secrecy surrounding the Technical Capability Notice and Apple's subsequent decision illustrates the opaque nature of government surveillance powers and the challenges in maintaining robust digital privacy in the face of such authority.
AI-written summary. May contain errors.