UK Two-Tier iCloud Encryption: Same Device, Different Protection
Original: Two-tier encryption in the UK
Why This Matters
It establishes that governments can quietly split encryption access by jurisdiction without any public legislative debate.
Since February 2025, Apple has blocked new UK users from enabling Advanced Data Protection on iCloud, following a UK government Technical Capability Notice under the Investigatory Powers Act 2016. Users who enabled ADP before the cutoff retain it; everyone else is locked out of Apple's strongest encryption tier.
Alice and Bill both live in the UK, both own identical iPhones, and both pay for iCloud. Only Alice has Advanced Data Protection (ADP) — Apple's end-to-end encryption for most iCloud data — because she switched it on before Apple quietly pulled the feature for new UK users in February 2025. Bill missed the window. He cannot enable it now.
The backstory stretches back more than a decade. Post-Snowden, Tim Cook staked out Apple's position clearly: no backdoors, full stop. The 2015 San Bernardino case sharpened that fight — the FBI sought a court order compelling Apple to build a passcode-bypass version of iOS. Cook called it 'the equivalent of cancer.' The FBI eventually got in via a third party (widely reported to be Cellebrite) and dropped the case.
Fast forward to 7 February 2025: The Washington Post revealed the UK government had issued Apple a Technical Capability Notice (TCN) under the Investigatory Powers Act 2016. A TCN compels a provider to build or maintain the capability to comply with future warrants — it doesn't itself authorize data access, but it ensures the plumbing exists. Recipients are gagged from disclosing the notice without Secretary of State approval. Rather than build what the UK demanded, Apple withdrew ADP for new UK users entirely. Existing users keep their protection; new ones simply cannot get it.