Apple filed a legal complaint with the UK’s Investigatory Powers Tribunal (IPT) in July 2026, challenging a government order demanding access to encrypted iCloud backups, the Financial Times first reported. The case is about Apple and iCloud, but the legal mechanism behind it — a technical capability notice, or TCN — applies to any company operating in the UK, Google included. And Google’s Android backups have been end-to-end encrypted by default since Android 9.
If the UK government succeeds in forcing Apple to weaken its Advanced Data Protection (ADP) encryption for iCloud, the same legal tool could compel Google to do the same for Android backup data stored in Google Drive. That is what makes this an Android story, not just an Apple one.
What happened and the backstory
The UK Home Office first issued a secret order in early 2025 demanding backdoor access to encrypted iCloud backups — covering both UK and US customers. That demand was dropped after diplomatic pressure from Washington, but Apple had already responded in February 2025 by disabling ADP entirely for UK users, meaning their iCloud data lost its end-to-end encryption protection.
The government then issued a second, narrower TCN in late 2025, this time targeting only UK-based users. Apple is now challenging that order through the IPT rather than simply complying or pulling another feature.
TCNs are issued under the UK’s Investigatory Powers Act 2016 and allow security services to compel companies to provide access to customer data — including encrypted data — during investigations into terrorism and child sexual abuse material. Both Apple and the Home Office are legally restricted from publicly discussing TCN specifics, which is why the case has played out through court filings rather than press conferences. Apple declined to comment to TechCrunch.
The Android connection
Google has offered end-to-end encrypted Android backups since Android 9 Pie, released in 2018. When a device has a lock screen set, the backup encryption key is protected by the user’s PIN, pattern, or password — Google itself cannot decrypt the data. The encryption runs through Google’s Titan security module on its servers, and neither Google nor the module holds the key.
This is architecturally similar to Apple’s ADP. A TCN targeting Google would face the same technical reality: either Google builds a mechanism to bypass its own encryption (a backdoor), or it pulls the feature from UK users entirely, as Apple did with ADP in 2025. Neither outcome is good for users.
A separate IPT challenge to TCN powers, brought by Privacy International and the civil liberties group Liberty, is already scheduled for hearings in December. The outcome of both cases could set a precedent that reaches well beyond Apple and iCloud — any encrypted cloud service operating in the UK, including Google’s Android backup infrastructure, would be affected by how the tribunal rules on whether these demands are lawful.
For Android users, the practical takeaway is straightforward: your encrypted backups are only as protected as the legal framework around them. If the UK’s approach succeeds, other governments will notice.
Sources: MacRumors, TechCrunch







