Summary
- Apple is challenging a fresh UK technical capability notice reportedly directed at encrypted data belonging to British users.
- The notice and most details of the tribunal proceedings remain secret, limiting public scrutiny of the required technical change.
- The dispute places lawful access powers against the security model of services where providers do not hold customers’ decryption keys.
Apple has filed a new legal challenge against a UK government demand reportedly seeking access to encrypted iCloud backups belonging to British users, reopening a dispute over whether state access powers can require a provider to alter the security architecture of its services.
The company lodged its complaint with the Investigatory Powers Tribunal in July, according to reporting by the Financial Times, Reuters, and the Guardian. The challenge concerns a fresh technical capability notice issued under the Investigatory Powers Act.
The reported notice is narrower geographically than an earlier demand, applying to UK users rather than seeking access to data associated with customers in other countries, including the United States. Its precise terms are not public, and the Home Office generally does not confirm or deny the existence of individual notices.
Technical capability notices can require communications and technology providers to maintain capabilities needed to give effect to lawful interception or data-access warrants. Recipients face restrictions on disclosing the notices, while challenges are heard by the tribunal responsible for reviewing the use of investigatory powers by public authorities.
Apple confirmed that it had brought the new case but has not published the filing. The company has repeatedly said it will not build a backdoor or master key into its products and services. The Home Office maintains that it supports strong encryption while also requiring lawful access in investigations involving terrorism, serious crime, and child sexual exploitation.
The disagreement centres on Advanced Data Protection, Apple’s optional system for extending end-to-end encryption across additional categories of iCloud information. When the feature is enabled, the decryption keys are controlled by the customer’s trusted devices rather than retained by Apple, limiting the company’s ability to recover or disclose the protected content.
A provider cannot produce readable data it is technically unable to decrypt. Meeting a demand for access to such material could therefore require a change to key management, software behaviour, account recovery, or another part of the service’s architecture. Apple and privacy groups describe such changes as backdoors because the access capability would weaken the boundary created by end-to-end encryption.
The government’s position is that investigatory powers contain legal safeguards and are used where necessary and proportionate. The secrecy around technical capability notices, however, makes it difficult to test publicly whether a proposed capability would be limited to particular accounts, could be reused at scale, or would create a security weakness available to other actors.
Apple stopped offering Advanced Data Protection in the UK during the earlier dispute. Existing legal proceedings have also raised questions about the geographic scope of UK notices and whether a domestic order can require a global technology company to change services used across several jurisdictions.
The latest notice reportedly excludes American users, reducing one source of diplomatic friction without resolving the underlying engineering issue. A capability designed only for UK accounts would still need to distinguish users, jurisdictions, keys, and service configurations inside infrastructure that is otherwise operated across borders.
That creates consequences beyond consumer privacy. Organisations increasingly depend on end-to-end encrypted cloud services for commercially sensitive information, executive communications, regulated data, and incident-response material. Procurement decisions rely partly on whether a provider can access customer content and whether national authorities can compel changes to that assurance.
The case also arrives as European governments continue debating lawful access to encrypted communications, while technology providers are expected to demonstrate secure-by-design development and resistance to unauthorised access. A mechanism created for lawful purposes remains a security capability whose design, control, auditing, and potential misuse would have to be assessed.
Privacy International and Liberty are pursuing related challenges, and a case-management hearing is expected to determine how the proceedings will be coordinated. The tribunal has not yet ruled on the legality of the new notice.
Until more of the case becomes public, the order’s exact technical demands, safeguards, and intended operating model remain unknown. The litigation will decide not simply whether data can be obtained in a particular investigation, but how far UK powers can reach into the architecture of encrypted cloud services.




