September 19, 2026:


Britain’s highest surveillance court heard arguments on Thursday that the Home Office can no longer sustain its official silence on a secret order compelling Apple to weaken the end-to-end encryption protecting iCloud data for roughly 35 million UK users — silence that lawyers challenged as ‘farcical’ in court given that the US government, unnamed UK officials, and even an independent parliamentary commissioner have all publicly confirmed the order’s existence.
The September 17 hearing before London’s Investigatory Powers Tribunal (IPT) was a preliminary case-management session focused entirely on transparency — not on whether the underlying order, known as a Technical Capability Notice (TCN), is lawful. That question will not be heard until at least 2027, leaving UK Apple users in the meantime with iCloud backups, photos, notes, and reminders protected by weaker encryption than users everywhere else in the world.
Every iPhone, iPad, and Mac user in the United Kingdom who relies on iCloud is affected by this dispute in a direct, practical way: since February 21, 2025, they have been unable to enable Advanced Data Protection (ADP), Apple’s strongest tier of cloud security.
ADP is the architectural mechanism at the center of the fight. Under standard iCloud encryption, Apple holds decryption keys on its servers. With ADP enabled, those keys exist only on a user’s trusted devices — Apple itself cannot access the content, and neither can law enforcement even with a valid warrant. Ten categories of data are affected by the UK blackout: iCloud Backup, iCloud Drive, Photos, Notes, Reminders, Safari Bookmarks, Siri Shortcuts, Voice Memos, Wallet Passes, and Freeform. The full ADP category list is documented on Apple’s support page.
That is the reason compliance with the secret TCN would require what critics call a backdoor. If Apple were to let the UK Home Office retrieve content from ADP-protected data, it would have to either hold a copy of the decryption key — destroying the architecture — or create a new mechanism capable of bypassing a system specifically designed to prevent any such bypass. Apple has stated publicly, and has reiterated in legal proceedings, that it has “never built a backdoor or master key to any of our products or services and never will.”
The September 17 IPT session was called to resolve procedural questions: how to consolidate Apple’s second legal challenge with the parallel complaints brought by civil liberties organizations Privacy International and Liberty, and whether the Home Office’s “neither confirm nor deny” (NCND) policy on TCNs is legally sustainable in this case.
Ben Jaffey KC, the barrister representing Privacy International and Liberty, told the tribunal directly that it was not. “That horse has long bolted,” he said. “There comes a point in which the plea of NCND is ridiculous and logically unsustainable.”
Jaffey set out the case for why: the original order was confirmed to the Times newspaper by Home Office sources within hours of The Washington Post’s initial February 2025 report, according to Jaffey’s argument in court; a post by then-US Director of National Intelligence Tulsi Gabbard on X in August 2025, which attracted more than 3 million views, stated that the UK had agreed to drop a demand for Apple “to provide a back door that would have enabled access to the protected encrypted data of American citizens”; the Investigatory Powers Commissioner, Lord Leveson, referenced the Apple case by implication in his December 2025 annual report; and the court itself received a letter dated September 11, 2026, from US Senator Ron Wyden and Representative Warren Davidson noting that Apple had confirmed to Congress that, if it had received a TCN, it would be barred by UK law from telling Congress whether such a notice existed. “The fact that Apple even needed to ask permission confirms there is a TCN,” Jaffey told the court.
Apple’s barrister, Daniel Beard KC, added that the government’s argument — that proceeding on “assumed facts” to preserve NCND would have no meaningful consequences — was “just wrong.”
The government’s barrister, Neil Sheldon KC, defended the NCND stance. Even if some individuals had read press reports and drawn their own conclusions, he argued, many others had not, and confirming or denying the TCN’s existence would let people engaged in terrorism or online child abuse know which platforms remained outside lawful interception. Abandoning NCND in one high-profile case would make it harder to maintain across others.
The Investigatory Powers Tribunal will now rule on the NCND question before any substantive hearing on the legality of the TCN itself begins.
The dispute began when the Home Office issued Apple a Technical Capability Notice in January 2025 under Section 253 of the Investigatory Powers Act 2016 — the statute nicknamed the “Snoopers’ Charter” by critics. The notice reportedly demanded that Apple maintain the capability to provide decrypted access to the iCloud data of any Apple user worldwide who had enabled ADP — not targeted access to specific accounts, but blanket capability. The Home Office’s move was first reported by The Washington Post and sparked immediate industry alarm across the UK tech sector.
Apple’s response, on February 21, 2025, was to withdraw ADP from UK users rather than build the access mechanism the Home Office demanded. Existing ADP users were given time to disable the feature themselves. The company then filed its first legal challenge at the IPT.
In April 2025, the IPT rejected blanket secrecy bid by the Home Office, ruling that the bare facts of the dispute could not be withheld from the public. That same period saw a bipartisan group of five US lawmakers — Senators Ron Wyden and Alex Padilla, and Representatives Andy Biggs, Warren Davidson, and Zoe Lofgren — letter urging public encryption hearings to the IPT, arguing that the UK’s demands had barred Apple from exercising constitutionally protected speech under US law and had impaired Congress’s oversight function.
By July 2025, two senior British officials told the Financial Times that the Home Office would likely have to back down on the worldwide scope of the order due to pressure from the Trump administration — including Vice President JD Vance. On August 19, 2025, Gabbard confirmed the UK had agreed to drop worldwide demand for access to non-British users’ data.
Apple did not restore ADP. The reason became clear in October 2025: the Home Office had issued new British-user TCN, this one confined to data belonging to British users. The IPT dismissed Apple’s first challenge — which had targeted the original worldwide TCN — as moot in October 2025 once the revised notice was in place.
Apple filed fresh iCloud encryption claim at the IPT in July 2026. Privacy International learned of the filing through a court order, making it public. A case management hearing was scheduled — and Thursday’s session was that hearing.
One of the sharper arguments made at Thursday’s session cut directly at the internal coherence of the Home Office’s position. Jaffey told the tribunal that in the very Home Office witness statement asserting that ministers and officials had maintained NCND, the facts showed the opposite: within hours of the February 2025 Washington Post report, multiple sources were confirming the TCN’s existence to the Times newspaper. “It is unlikely that Home Office sources would confirm a TCN without having tacit approval,” Jaffey told the court.
He also pointed out that a witness for the Home Office — Lucy Montgomery-Pott, head of the Investigatory Powers Unit in the Homeland Security Group — had sat on a tribunal appointment panel with IPT President Lady Ailsa Carmichael without disclosing her role as a key government witness in the Apple case. The court considered the matter and determined Carmichael did not need to recuse herself, but the procedural tangle illustrated how enmeshed the case had become, as confirmed by Computer Weekly’s reporting on the session.
NCND is not a statute. It is a long-standing government practice — recognized, but not mandated, by UK courts — by which public authorities refuse to acknowledge the existence of sensitive operational facts. Prior courts have held it is “a departure from procedural norms relating to pleading and disclosure” that requires justification on public interest grounds, not automatic deference.
In this case, its application produces a situation that Jaffey called openly embarrassing: Apple cannot legally confirm or deny receiving the TCN; WhatsApp and Google can (and did, in witness statements) confirm they have not received one; the asymmetry itself confirms Apple’s situation to anyone who notices it. “WhatsApp are free to say that because there is no legal constraint on anybody saying they have not received a TCN,” Jaffey observed.
The government’s defense is that NCND must be applied consistently to remain effective — a single departure, even in a case the whole world already knows about, could be used to infer the existence of other orders affecting other companies. Sheldon described the “net effect” on proceedings as limited, since hearings can proceed on assumed facts without the NCND being formally dropped.
The IPT will now determine which view prevails.
This case is not primarily about iCloud. It is about the legal architecture the UK built in 2016 and expanded in 2024, and whether that architecture can compel any company with a sufficient connection to the UK to modify or weaken its security products in secret — without public acknowledgment, without parliamentary debate about the specific order, and without effective legal constraint on its global scope.
TCNs under the Investigatory Powers Act can be served on any telecommunications or internet operator with ties to the UK, regardless of where it is headquartered. Privacy International, which has its own parallel case before the IPT, has warned the case will have far-reaching implications for privacy rights well into the future.
The 2024 amendment to the IPA added a further dimension that the September 17 hearing did not address but that looms over any eventual resolution: the amended law requires covered companies to notify the Home Office before making changes to their services that could affect surveillance capabilities. In practice, this means the Home Office could pre-approve security service changes and object to Apple restoring ADP in the UK even if Apple’s current TCN challenge ultimately succeeds in court — giving the government effective veto power over security improvements it dislikes.
Signal President Meredith Whittaker put the broader stakes plainly when the first TCN became public: “Using Technical Capability Notices to weaken encryption around the globe is a shocking move that will position the UK as a tech pariah, rather than a tech leader. If implemented, the directive will create a dangerous cybersecurity vulnerability in the nervous system of our global economy.”
The UK government has defended the IPA as “world-leading legislation that helps keep people safe while protecting privacy through strong safeguards and independent judicial oversight.”
For UK users, the practical consequence of the dispute is already visible: ADP remains unavailable to new users, and the ten categories of data it would protect remain accessible in principle to Apple — and, with a lawful warrant, to UK authorities — in a way that no user in any other country faces. A substantive hearing on whether this state of affairs can be compelled by law is not expected before 2027.
A Technical Capability Notice is a secret order issued by the UK Home Secretary under the Investigatory Powers Act 2016. Unlike a standard warrant — which asks a company to provide specific data about a specific individual — a TCN requires a company to build or maintain a capability that could be used to respond to future data demands. The company receiving it cannot legally confirm or deny its existence. In Apple’s case, the reported TCN required the company to maintain the ability to access data that its Advanced Data Protection feature is specifically designed to make inaccessible to everyone, including Apple itself. A fuller explanation of the TCN legal regime’s implications is available through Privacy International’s legal action page.
Apple withdrew Advanced Data Protection from new UK users in February 2025 rather than build the access mechanism the Home Office demanded. UK users who had already enabled ADP before that date were eventually required to disable it. Without ADP, ten iCloud data categories — including backups, photos, and notes — are protected by standard encryption, meaning Apple holds the decryption keys and could, in theory, provide access to law enforcement with a valid warrant. Fifteen other iCloud categories that are end-to-end encrypted by default, such as iCloud Keychain, Health data, and iMessage, remain protected regardless. UK users who want end-to-end encryption for their sensitive data can consider switching to locally encrypted backup via iTunes/Finder instead of iCloud, or using separately end-to-end encrypted storage alternatives for particularly sensitive content.
The government has maintained its NCND policy and has not publicly described the specific justification for the Apple TCN. In general terms, it has argued that end-to-end encryption impedes lawful investigations into terrorism, serious crime, and online child abuse, and that the Investigatory Powers Act provides a proportionate, judicially overseen mechanism to address that gap. At Thursday’s hearing, the government’s barrister argued that even if press coverage had led some people to guess the TCN exists, abandoning NCND would help bad actors understand exactly which platforms remain outside the lawful access framework — making it harder to pursue TCN-based capabilities in other cases.
Potentially, yes. The 2024 amendments to the Investigatory Powers Act require companies to notify the Home Office before making changes to their services that could affect surveillance capabilities, and give the Home Secretary the power to object to such changes pending review. This means that even if Apple’s legal challenge succeeds in getting the current TCN declared unlawful, restoring ADP in the UK could trigger a new notification obligation — and a new Home Office objection. The full implications of the 2024 amendment on Apple’s ability to restore end-to-end encryption to UK users have not yet been tested in court. The Electronic Frontier Foundation’s analysis confirms UK still seeking backdoor access through the revised legal framework.