IT Pro Expert
Search
IT · 27 Feb 2025 · 16 min read

Apple removes advanced data protection - Here is a Workaround Solution to Fix this iCloud Invasion

Apple icloud advanced data protection solution workaround fix alternative

In January 2025 the Home Office secretly ordered Apple to break its own encryption. Apple pulled Advanced Data Protection from the UK rather than comply, and more than eighteen months later British users still cannot turn it back on. Here is where the case actually stands, what you lost, and what you can do about it.

How we got here

  1. January 2025 — the secret order

    The Home Office issues a Technical Capability Notice under the Investigatory Powers Act 2016. Its reported scope is blanket access to Advanced Data Protection content for any Apple user worldwide — not assistance with a named suspect. Under the Act, merely confirming such a notice exists is an offence.

  2. February 2025 — it becomes public

    The Washington Post reveals the order. It has no known precedent among major democracies: a demand for standing capability to read fully encrypted material held by a foreign company on behalf of the entire world's users.

  3. February 2025 — Apple withdraws the feature

    Rather than build the access, Apple removes Advanced Data Protection for UK users. New users cannot enable it; existing users are required to turn it off. Apple's position is that it has never built a back door or master key and never will.

  4. March–April 2025 — the tribunal

    Apple complains to the Investigatory Powers Tribunal, the only UK court that can hear certain national-security cases. In April the tribunal refuses the government's request to keep even the bare details of the case secret, noting how much had already been said publicly.

  5. August 2025 — the worldwide demand is dropped

    Following intervention from the US administration, the UK withdraws the global element of its demand. This is presented as a resolution. It is not.

  6. Autumn 2025 — a second, narrower notice

    The Home Office issues a replacement notice, this time targeting the encrypted data of British users only. The principle is unchanged; only the geography is.

  7. July 2026 — Apple challenges again

    Apple files a fresh complaint at the tribunal against the rewritten notice. The tribunal is hearing it alongside cases brought by Privacy International, Liberty and two private individuals, in public, using agreed "assumed facts" rather than classified detail.

A demand narrowed from everyone in the world to everyone in Britain is not a concession. If you live here, it is the same demand.

What Advanced Data Protection actually protected

Apple's iCloud encryption comes in three tiers, and most coverage blurs them together. Knowing which is which tells you exactly what you lost — and what was never protected in the first place.

Protected only when ADP is on

With ADP disabled, Apple holds keys to all of this and can be compelled to produce it:

  • Device backups (including Messages held inside them)
  • iCloud Drive files
  • Photos
  • Notes and Reminders
  • Safari bookmarks
  • Siri Shortcuts
  • Voice Memos
  • Wallet passes

End-to-end encrypted regardless

These categories stay end-to-end encrypted whether ADP is available or not:

  • iCloud Keychain passwords and passkeys
  • Health data
  • Payment information
  • Screen Time, Maps favourites and Siri information

Never end-to-end encrypted

Even with ADP switched on, iCloud Mail, Contacts and Calendars are not — for interoperability with the wider email and calendar world. That was true before this order and remains true now.

Eight workarounds that do not work

Every one of these comes up whenever this subject is raised. None of them solves the problem, and several of them leave people worse off because they believe they are protected when they are not.

"Switch to Android"

Doesn't work. The same law reaches Google. A Technical Capability Notice can be served on any provider with a UK nexus, and Google One backups and Google Photos sit under keys Google controls. You change which company receives the notice, not whether one can be served.

"Move to Google Drive or Dropbox"

Doesn't work. Swapping one large cloud provider for another achieves nothing at all. If the provider holds the keys, the provider can be compelled to hand over what those keys unlock.

"Change my account region to another country"

Doesn't work. Setting your App Store or account country to somewhere else does not move you, your data, or the company holding it beyond the reach of an order. It just breaks your billing.

"iCloud is still encrypted without ADP"

Misses the point. It is encrypted — with keys Apple holds. That is precisely the difference Advanced Data Protection made, and precisely why its removal matters. Encryption that someone else can unlock on request is a filing cabinet with a spare key at the front desk.

"iMessage and WhatsApp are encrypted, so I'm fine"

Doesn't work. The messages in transit are protected. The backup is the weak point, and that is where investigators look. WhatsApp does now offer an end-to-end encrypted backup and you should enable it if you keep one at all — but turning the backup off entirely is the stronger answer.

"I use a VPN"

Irrelevant here. A VPN protects traffic in transit between you and the VPN provider. It does nothing whatsoever about data already sitting in a cloud account under someone else's keys. Useful for other things; useless for this.

"I delete things off my phone"

Doesn't work. Deleting a photo from the handset does not remove it from backups already taken, and providers retain deleted items for a period regardless. If it was ever synced, assume a copy exists.

"I'll just not back up anything"

Right instinct, wrong ending. Turning cloud backup off is genuinely the first step — but stopping there means one dropped phone costs you every family photograph you own. Turn the cloud backup off and put a backup you control in its place.

What to do instead

  • Turn off every cloud backup and sync on the phone, as set out at the top of this page — device backup, photos, drive and per-app backups including WhatsApp.
  • Put a UniFi NAS on your own network as the destination for photos and files, running offline or with access locked down. This is the piece that replaces iCloud.
  • Automate the photo backup. UniFi Drive 4.0 added automatic local photo and video backup from iPhone and iPad through the licence-free UniFi Endpoint app — no subscription and no third-party cloud in the path. For Android, or for finer control over albums and formats, PhotoSync does the same job to a network target.
  • Use ProtonDrive where you need genuine cloud access — files that must be reachable from anywhere, or shared with someone else.
  • Use Proton Docs for documents and notes instead of iCloud Notes or Google Docs. End-to-end encrypted, and enough for most everyday writing.
  • Use Signal for anything sensitive, on both phone and desktop.
  • Use ProtonMail for personal and domain email, remembering that full end-to-end protection only applies between Proton users.
  • Use ProtonPass as your password manager, on desktop and phone.
  • Run proper anti-malware such as ThreatDown. Endpoint compromise defeats every other measure on this list.
  • Install fewer apps, and read the permissions. Some apps carry data-sharing arrangements you would not agree to if asked plainly.
  • Be ruthless about browser extensions. An extension can read every page you visit. Stolen sessions and saved credentials are traded on the dark web in bulk, in what are known as stealer logs.

Storage you actually control — without a science project

We used to point people at self-hosted NextCloud for this. In practice it asks too much: a server to maintain, updates to keep on top of, and a support burden that lands on whoever in the household is least able to refuse. Most people set it up, fall behind on patching, and end up with something less safe than what they left.

The setup we now recommend has no server administration in it at all.

A UniFi NAS at home

A UNAS unit on your own network holds the photos and files. It can run fully offline — reachable only from inside the house — or with tightly controlled remote access if you need it. You own the disks and the keys, and there is no third party to serve a notice on.

Automatic photo backup

UniFi Drive's photo backup copies photos and videos straight from an iPhone or iPad to your own drive. PhotoSync covers Android and anything needing more control. Either way it runs in the background, like iCloud did — just to hardware in your hallway.

Proton for what must be online

ProtonDrive and Proton Docs handle the files you need from anywhere and the documents you want to write and share. End-to-end encrypted, Swiss-based, and a clean privacy record so far.

A second copy, always

One box is one point of failure. Keep an encrypted external drive updated periodically and stored elsewhere, or a second unit. A private backup that only exists once is not a backup.

The device settings almost nobody turns on

Everything above is about who holds the keys to your data in the cloud. This section is about the other half of the problem: what happens when someone has your unlocked phone in their hand, or has watched you type the passcode. Both platforms have added serious protections for exactly this, and most people have never opened the menu.

Be clear about what these do and do not achieve. They defeat a thief, an opportunist, or someone who has shoulder-surfed your PIN. They do not stand between a cloud provider and a lawful order — that is what the rest of this page is for.

On iPhone

Stolen Device Protection

The "away from home" feature. When the iPhone is somewhere it does not recognise as familiar — not home, not work — sensitive actions demand Face ID or Touch ID with no passcode fallback: viewing iCloud Keychain passwords and passkeys, using saved payment cards, turning off Lost Mode, erasing the device. Changing Apple Account security settings, adding or removing a trusted device or recovery contact, or turning the feature itself off adds a one-hour security delay and a second biometric check — enough time to mark the phone as lost. Since iOS 26.4 Apple turns this on for everyone rather than leaving it buried. Check it under Settings → Face ID & Passcode, or Settings → Privacy & Security.

Lockdown Mode

Apple's hardest setting, for people plausibly targeted by sophisticated or state-grade attackers — journalists, campaigners, senior executives, anyone in a contentious dispute. It strips out the attack surface most commonly exploited: most message attachment types, link previews, some web technologies, wired connections to a locked device, and unsolicited invitations. Things will break, and that is the trade. Settings → Privacy & Security → Lockdown Mode.

Inactivity reboot

Nothing to enable — it has been automatic since iOS 18.1 and it matters. An iPhone left locked for a period restarts itself, returning to the "before first unlock" state where the data is encrypted at rest and far harder to extract with forensic tooling. It is the difference between a seized phone being readable and being a brick, which is precisely why extraction vendors dislike it.

Lock-screen and passcode hygiene

Switch from a six-digit PIN to a custom alphanumeric passcode — a shoulder-surfed six digits is the root of every theft story in this section. Then, under Face ID & Passcode, turn off lock-screen access to Control Centre, Siri, Wallet, USB accessories and reply-with-message, so a locked phone stays locked. Enable "Erase Data" after ten failed attempts if you keep good backups, require Face ID for Hidden and Recently Deleted photos, and lock individual apps such as banking with Face ID.

On Android

Identity Check

Android's direct equivalent of Stolen Device Protection, and the single most important one here. Outside your trusted locations it forces a biometric scan rather than the PIN before anyone can reach sensitive settings or apps — so a thief who watched you type your PIN still cannot change your password, disable Find Hub or empty a banking app. On a Pixel: Settings → Google → All services → Theft protection → Identity Check. Samsung and others place it under their own security menus.

Advanced Protection

Rolled out to all Android 16 devices during 2026, this is one switch that turns on a whole set: Theft Detection Lock, Offline Device Lock, a 72-hour inactivity reboot, USB Protection while the screen is locked, Failed Authentication Lock, scam detection for chat notifications, and blocking of insecure 2G connections and WEP Wi-Fi. Android 17 extends it further, including cutting off accessibility-service access for apps that are not genuine accessibility tools. Settings → Security & Privacy → Advanced Protection.

Theft, offline and remote lock

Theft Detection Lock uses on-device motion sensing to spot a snatch-and-run and locks the screen instantly. Offline Device Lock locks an unlocked handset that is taken off the network — the standard trick for stopping you tracking it. Remote Lock lets you lock the phone from any browser at android.com/lock using just your number, which is far quicker than logging into an account you may be locked out of. Note that both automatic locks only help if the phone was unlocked when it was taken.

Private Space and 2G off

Private Space creates a sandboxed area for banking, health or any other sensitive apps. Apps inside are invisible to the rest of the system, show nothing on the lock screen, and need separate authentication. Separately, disable 2G in network settings: fake base stations downgrade handsets to 2G precisely because its encryption is trivially broken, and Advanced Protection blocks this for you on supported devices.

The law that makes this possible

This is not a bill and it is not new. The Investigatory Powers Act 2016 — the "Snoopers' Charter" — is in force, and was strengthened by the Investigatory Powers (Amendment) Act 2024, which among other things requires companies to notify the Home Office before making changes that would affect an existing capability. In practice that means a provider can be obliged to hold off on shipping a privacy improvement.

Rights groups have consistently flagged the same features of the regime:

  • Internet connection records retained for up to twelve months — a list of the sites and services a person used, held for everyone regardless of suspicion.
  • Equipment interference — explicit legal authority for agencies to hack devices and networks, on both a targeted and a bulk basis, with targets that can be broadly defined.
  • Bulk interception — a statutory footing for the mass collection practices disclosed by Snowden, including tapping the cables carrying internet traffic in and out of the UK.
  • Compelled capability — companies can be required to maintain technical means to assist, and to remove electronic protection they applied. This is the clause the Apple notice rests on.
  • Limited judicial review — a judge approves warrants, but reviews whether the process was followed and the decision was reasonable, rather than re-taking the decision. Urgent cases can proceed before that review, with urgency decided by the person issuing the warrant.

Why this matters even if you have nothing to hide

The argument for these powers is serious crime and terrorism. The difficulty is that the people running sophisticated criminal operations are not backing their plans up to consumer iCloud accounts — they know the risk, and they use other tooling. What blanket access actually delivers is a searchable record of ordinary people's emails, photographs and documents, available to a widening circle of departments for increasingly routine purposes. AI now makes sifting that material trivial, which changes the calculation: the practical limit on mass surveillance used to be the cost of reading it all, and that limit has gone.

Plenty of people say they do not care about privacy. Rather more of them would object to a stranger reading their family photographs, their medical correspondence and their bank statements, which is the same thing described accurately.

Apple iCloud Advanced Data Protection alternatives and private backup options for UK users

Sources and further reading

Want your data back under your own control?

We supply and set up private storage for households and businesses — UniFi NAS with automatic photo backup, encrypted second copies, and messaging and email that does not depend on someone else's key. It is part of our wider cyber security work.

Talk to us about private storage