Apple Withdraws Advanced Data Protection in the UK
On February 21, 2025, Apple announced it can no longer offer Advanced Data Protection (ADP) to new users in the United Kingdom. Existing UK users who have the feature enabled will eventually be required to disable it. The decision followed a UK government demand for a technical capability that would have created a backdoor into end-to-end encrypted iCloud data.
Apple stated it remains “gravely disappointed” and reaffirmed that it has never built — and will never build — a backdoor or master key into any of its products or services.
What Advanced Data Protection Actually Protected
ADP was an optional feature that extended end-to-end encryption to additional iCloud categories, including:
iCloud Backup
iCloud Drive
Photos
Notes
Reminders
Safari Bookmarks
Siri Shortcuts
Voice Memos
Wallet Passes
Freeform
With ADP enabled, only the user could decrypt that data — not even Apple. Without it, those categories fall back to Standard Data Protection, meaning Apple holds the encryption keys and can access the data when presented with a valid legal request.
What Remains Fully Protected
Important default end-to-end encryption is unaffected in the UK and worldwide:
iMessage and FaceTime communications
iCloud Keychain
Health data
Payment information and other categories that have always been end-to-end encrypted by default
Why Apple Made This Decision
The UK government issued a Technical Capability Notice under the Investigatory Powers Act requiring Apple to provide access to encrypted data. Rather than weaken its encryption architecture or create a backdoor that could affect users globally, Apple chose to withdraw the optional ADP feature from the UK market.
Cyber Misfits’ Perspective
At Cyber Misfits, we see this as a clear example of the ongoing tension between strong encryption and government access demands. End-to-end encryption remains one of the most effective defenses against data breaches, unauthorized surveillance, and cyber threats.
Organizations and individuals should continue to prioritize strong encryption wherever available, carefully evaluate the data protection settings of the platforms they use, and maintain layered security controls. We help Oklahoma businesses and public-sector clients implement practical, resilient cybersecurity measures that protect sensitive information even as the regulatory landscape evolves.
— The Cyber Misfits Team