Apple Withdraws Advanced Data Protection in the UK

On February 21, 2025, Apple announced it can no longer offer Advanced Data Protection (ADP) to new users in the United Kingdom. Existing UK users who have the feature enabled will eventually be required to disable it. The decision followed a UK government demand for a technical capability that would have created a backdoor into end-to-end encrypted iCloud data.

Apple stated it remains “gravely disappointed” and reaffirmed that it has never built — and will never build — a backdoor or master key into any of its products or services.

What Advanced Data Protection Actually Protected

ADP was an optional feature that extended end-to-end encryption to additional iCloud categories, including:

  • iCloud Backup

  • iCloud Drive

  • Photos

  • Notes

  • Reminders

  • Safari Bookmarks

  • Siri Shortcuts

  • Voice Memos

  • Wallet Passes

  • Freeform

With ADP enabled, only the user could decrypt that data — not even Apple. Without it, those categories fall back to Standard Data Protection, meaning Apple holds the encryption keys and can access the data when presented with a valid legal request.

What Remains Fully Protected

Important default end-to-end encryption is unaffected in the UK and worldwide:

  • iMessage and FaceTime communications

  • iCloud Keychain

  • Health data

  • Payment information and other categories that have always been end-to-end encrypted by default

Why Apple Made This Decision

The UK government issued a Technical Capability Notice under the Investigatory Powers Act requiring Apple to provide access to encrypted data. Rather than weaken its encryption architecture or create a backdoor that could affect users globally, Apple chose to withdraw the optional ADP feature from the UK market.

Cyber Misfits’ Perspective

At Cyber Misfits, we see this as a clear example of the ongoing tension between strong encryption and government access demands. End-to-end encryption remains one of the most effective defenses against data breaches, unauthorized surveillance, and cyber threats.

Organizations and individuals should continue to prioritize strong encryption wherever available, carefully evaluate the data protection settings of the platforms they use, and maintain layered security controls. We help Oklahoma businesses and public-sector clients implement practical, resilient cybersecurity measures that protect sensitive information even as the regulatory landscape evolves.

— The Cyber Misfits Team

Previous
Previous

New Presidential Memorandum Expands Private Sector Role in Fighting Cybercrime

Next
Next

Stargate AI Project: America’s $500 Billion AI Investment