Photo by ALEXANDRE LALLEMAND on Unsplash
Find the answers to all the questions you have regarding the UK's secret Technical Capability Notice (TCN) powers, Apple, and our fight against them.
Photo by ALEXANDRE LALLEMAND on Unsplash
In March 2025, PI (together with three co-claimants including Liberty) filed a complaint against the UK Government. We’re challenging their use of dangerous, disproportionate and intrusive surveillance powers to undermine the privacy and security of people all over the world. Here, we answer some key questions about the case and the recent events that led to this development.
Note: This post was last updated on 4 August 2026.
On 7 February 2025, the Washington Post reported that the UK Government had demanded Apple – maker of iPhones, iPads and MacBooks – make changes to how data is managed by their iCloud service. The implication was that the UK Government wanted to be able to request access to read the data that people have stored on iCloud, even if the user had chosen to protect it with end-to-end encryption, and no matter where in the world they were.
If true, this is an unacceptable government intrusion into our private communications and data. Not only is it a threat to the privacy and security of users all over the globe, but it’s almost impossible to get to the bottom of what exactly is going on: the UK Government’s behaviour has been shrouded in secrecy.
The lack of transparency about something that impacts the safety, security and privacy of users not just in the UK but potentially worldwide is alarming. We need to act now to challenge such disproportionate secretive powers.
Yes and no. As these orders remain secret, we do not really know what has been issued or withdrawn.
In October 2025, the FT reported that the UK had indeed withdrawn its first notice and issued a second one targeting “British users”. It’s totally unclear who might count as a “British user” - could it be residents, citizens, or simply anyone within the UK’s borders?
In any case, any secret TCN, whatever its scope, that requires a company to undermine its provision of end-to-end encrypted services poses a threat to online security around the world. It risks the creation of insecure weak points that hackers can exploit, and emboldens other states to force companies to hand over private data and communications.
Here’s what we know at the time of writing:
Despite the potentially enormous impact, there is no public information about what Apple have or have not actually been required to do. We don’t even know for certain that the above events are all connected, although our working assumption is that they are.
The implication is that the UK Government wants Apple to undermine the security of data that users have asked to and expect to be safely encrypted so that the UK can access that data in the future. This has global implications, even if only targeted at some users. That’s because weakening encryption for anyone creates technical and/or legal weaknesses that can (and will!) be exploited by hostile actors.
What is clear is that end-to-end encryption is under threat. The potential scope of this intrusion into people’s private lives and consequent undermining of data security is immense.
E2EE is a form of encryption that is even more protective of privacy than regular encryption. It ensures that only the “ends” of the communication (the person who sends an encrypted message and the intended recipient) have access to the right “key” that can decrypt the message, allowing it to be read.
With so much of our lives now taking place in the digital realm, communication security tools (such as E2EE) are incredibly important to the protection of human rights, including the right to privacy. E2EE gives us access to safe and private spaces for personal development where we can store our information and communicate without interference. It protects us from criminals. It protects us from unnecessary and disproportionate surveillance. And it gives us control over access to our sensitive data.
While E2EE often refers to communication services (like Signal and WhatsApp), it can also be used to describe data storage services, like iCloud. When it comes to such services, E2EE relates to who can read the encrypted data. In standard encryption, the data storage provider may have a key that allows them to do so. With E2EE, only the user holds the key and can decrypt the data.
Apple’s Advanced Data Protection (ADP) uses E2EE to provide stronger protection to user data stored on iCloud. When ADP is used, Apple does not have a key and so cannot decrypt data its customers have stored. Decryption key(s) are stored only on the user’s trusted devices. Some types of data on Apple’s services (for example passwords and health data) are already protected by E2EE by default, but users have to opt-in to ADP to have it applied to all data they store on iCloud.
In 2016, the UK passed the Investigatory Powers Act (IPA), one of the most intrusive surveillance laws in the world. The IPA allows spy agencies, like MI5, MI6 and GCHQ, to carry out mass surveillance. It also gave the government the ability to issue various forms of notice that can be used to force companies to provide or facilitate access to telecommunications data in support of government surveillance.
The UK claims these powers are needed to tackle crime and for national security reasons. We think they can be dangerous for both our privacy and, as is the case here, for the security of the internet as a whole.
Technical Capability Notices - TCNs – are secret orders issued under the IPA that can compel a company to make changes to their services in order to facilitate the UK’s use of its investigatory powers. TCNs can be issued to a company in any jurisdiction, so long as they have sufficient connection to the UK (eg through providing services to UK users, as is the case for Apple). A TCN can require a company to make a wide range of changes to its services, including the ‘removal of electronic protection’ (such as encryption). Changes like that can reduce security and threaten privacy.
TCNs (and other similar notices) are not made public, and recipients of them are not allowed to release information about them. As such, the only information available about the purported Apple TCNs is that which has been leaked to the press. The result is a situation where privacy and security measures of digital services providers (here ADP) are compromised without the users of those services being aware of what is really going on.
TCNs have been the focus of our attention for a while - ironic, given everything regarding TCNs is secretive.
We don’t know for sure because the text of it is secret. The UK Government have not responded to requests to publish it (including by Members of the UK Parliament), and Apple are legally prevented from doing so.
Nevertheless, our understanding based on what has been publicly reported so far is that the UK Government is, at a minimum, requiring Apple to be able to provide access to encrypted data that users have stored on iCloud.
In effect, that would compel Apple to either create a secret backdoor to allow the UK Government to access the data of Apple users, or to surreptitiously switch off ADP without telling its users. Either approach is fundamentally problematic.
International laws like the European Convention on Human Rights (ECHR) prohibit the UK from violating our rights to privacy and freedom of expression, unless the government has legitimate reasons to do so and any measures they adopt for that purpose satisfy fundamental principles like legality, necessity and proportionality.
This is likely not the case here. TCNs that demand companies indiscriminately undermine the security and data of billions of people (not just those in the UK but everyone in the entire world) can never be necessary or proportionate.
Russia has previously attempted to impose similar decryption orders upon Telegram. In 2024, the European Court of Human Rights, the international body which hears ECHR complaints against governments, found that the Russian measures were so disproportionate that they impaired the very essence of the right to privacy.
It seems likely this was because of pressure from the US Government. President Donald Trump described the UK’s actions as being like something “that you hear about with China” and in August 2025, Tulsi Gabbard, Director of National Intelligence, posted that “the UK has agreed to drop its mandate … that would have enabled access to the protected encrypted data of American citizens”.
But in any case, the new notice is just as concerning because:
It also raises important questions as to what the scope of the purportedly narrowed TCN is actually now intended to be. Does it target UK citizens anywhere in the world? Or users with an Apple account first registered in the UK? Or anyone who is (even temporarily) connected to the internet from within the UK’s borders?
If you are an iCloud user in the UK and you want to turn on the ADP feature: Bad news! Apple says they will no longer offer ADP for new UK users.
If you are an iCloud user in the UK and you already had the ADP feature turned on before 19 February 2025, Apple may ask you to disable it at some point or risk losing access to your iCloud account.
If you are an iCloud user outside the UK: you can keep using the ADP feature or turn it on, if you haven’t done so already. Apple have expressed no intention to remove ADP for non-UK based customers.
If you are a human rights defender, activist, journalist or member of a vulnerable group that relies on the ADP feature to protect yourselves from oppressive regimes: Apple continues to claim that they will never build a backdoor into their systems.
But the threat is bigger!
While the UK Government seems to have come for Apple today, tomorrow it may be other big tech companies, such as Google and Microsoft, and the day after it could be Signal, your VPN provider, Proton or others. This kind of sweeping measure has a chilling effect on the ecosystem. Developers worry that the data they send to iCloud isn’t secure, potentially pushing data to less safe locations. And do keep in mind, just because you aren’t an iCloud user doesn’t mean that there is no data about you on iCloud as your friends and contacts who use iCloud may be saving it there.
Under the IPA, Apple is legally prevented from making any public comment about a TCN issued to it. Again, we have to piece together parts of the puzzle.
A few weeks after news of the first TCN emerged, Apple announced that they would withdraw the availability of ADP for new users in the UK (those already using ADP have been given “a period of time to disable the feature themselves to keep using their iCloud account”). ADP remains available to users elsewhere in the world.
As recently as 2024 Apple made clear to the UK Parliament that it would “never build a backdoor into its products” and that TCNs could have the result of forcing companies like Apple “to publicly withdraw critical security features from the UK market, depriving UK users of these protections.” That seems to be exactly what’s happened now. A reasonable presumption could be that Apple doesn’t want to undermine the effectiveness of ADP and so has taken the option to stop offering it in the UK.
Apple also had issued a legal challenge to the TCN regime.
On 13 March 2025, the Investigatory Powers Tribunal (IPT) held a secret hearing between Apple and the UK Government. Journalists and PI staff tried to attend but were refused entry 🤷
On 7 April 2025, the IPT released a summary public judgment of the full secret judgment (which was made available only to Apple and the Home Office). In the summary judgment, the IPT rejected a claim by the Home Office that it would be “contrary to the public interest” for any information about the case to be in the public domain.
The Government’s position seems to be to try to turn back time by preventing anyone - Apple, the IPT, journalists - from saying anything about the case.
The next publicly available information about the Apple case was its reported dismissal in October 2025 due to a “change in circumstances”. This occured shortly after the FT reported that Apple had received a second legally binding ‘Technical Capability Notice’ requiring it to weaken its ADP service for iCloud for only “British users”.
In August 2026, Apple reportedly submitted a new challenge to the UK’s technical capability notice powers.
The Investigatory Powers Tribunal (IPT) was established to provide oversight of the use of government surveillance powers in the UK. Individuals and organisations can apply to it on a range of matters, and PI has been involved in a number of cases before the IPT.
The IPT is permitted to scrutinise challenged actions in secret, restricting the public’s ability to raise legal objections and understand what’s going on. This only exacerbates our concerns about the lack of transparency in this case.
We believe that when surveillance powers are exercised with widespread and potentially damaging consequences, there is a strong public interest in the exercise of these powers and the IPT’s decision-making around them being public.
Since 2003, the IPT has operated on the basis that its hearings should be open to the public where possible. That makes sense for a democratic society that respects the principle of open justice. However, the Tribunal has retained the power to decide to hold hearings in secret.
While it might sometimes be reasonable for certain parts of hearings to be held behind closed doors (for example to protect someone’s identity or if operational details are being discussed), that can hardly apply to the entirety of these proceedings! The details have already been reported on around the world.
As we mentioned at the start, PI has filed a legal challenge to TCNs before the IPT - together with Liberty and two individuals as our co-claimants. We’re seeking greater transparency about the TCN regime, as well as arguing that targeting and seeking to undermine privacy and security measures in a way that potentially affects millions of users is an unlawful and disproportionate use of the surveillance powers granted under the IPA, and a violation of the human rights of those affected.
Extreme surveillance powers - including TCNs - need to be subject to very strict safeguards and very close scrutiny. We don’t think the standards demanded by democracy and human rights have been met here. The manner in which the UK Government has purportedly exercised this TCN is a major concern for us.
The TCN and its challenge have been of significant interest to a number of other actors, including the BBC and other members of the press, telecommunications operators big and small, US senators, and members of the Global Encryption Coalition. Both WhatsApp and a group of smaller companies wanted to intervene in both legal challenges, but were rejected by the IPT.
Now that Apple has re-initiated a challenge to the TCN regime, their claim may be managed with ours. A hearing to determine the that management will be held in September 2026.
We are now expecting our case to be heard towards the end of 2026. We have requested that it is heard with full transparency in open court.
Beyond the intricacies of the Apple situation, we hope our complaint shines a light on a secretive and dangerous surveillance measure that shouldn’t exist in a democratic society.
To keep up to date on the case and all our work, you can sign up to our mailing list - don’t worry, you can choose the topics you are most interested in… and we take proper care of your data!
Any support you can give us through a donation would be most appreciated. For context, the last time we went to the IPT, it took us 8 years of work. We want to see these cases reach the finish line, and we need funding to achieve that.
To reiterate however, to really ensure that we don’t sleepwalk into a world of ubiquitous state and corporate surveillance, it is essential that people put pressure on governments and corporations - so if there’s one thing you can do, it’s make your voice heard!
We will continue to challenge the UK Government’s exercise of this power and invite you to voice your concerns if you feel the same, such as by writing to your MP.