Public cautious of UK authorities ‘backdoor’ surveillance following Apple row, ballot reveals
The general public is cautious of UK authorities surveillance powers that require expertise firms to construct “backdoors’ to entry encrypted communications, in line with a ballot of two,000 individuals within the UK by a Washington-based advocacy group.
Solely 12% of these surveyed consider the federal government ought to be capable of concern secret orders to tech firms to permit authorities entry to their non-public information, in line with the ballot commissioned by the Centre for Democracy and Expertise, which campaigns for strict impartial oversight of presidency surveillance.
Carried out after the UK authorities issued a secret order to Apple to entry end-to-end encrypted information saved by customers on the Apple iCloud, the ballot suggests the UK public believes there needs to be higher transparency over using authorities surveillance powers.
Over 90% of the individuals questioned stated they need to have a proper to have non-public conversations on-line and 87% agreed that the federal government ought to have a authorized obligation to inform individuals if their non-public conversations have been accessed.
Tom Bowman, coverage counsel for safety and surveillance on the Middle for Democracy & Expertise, stated the British public discover it “insupportable” that the UK can concern secret orders to tech firms with out people ever being instructed that their communications have been focused.
“If there’s a warrant course of in place that notifies the person, or no less than offers a chance to problem it, that may fulfill loads of the pushback we’re seeing in polling,” he stated.
Governments and regulation enforcement businesses, together with the Nationwide Crime Company, Europol and the 5 Eyes intelligence sharing companions, have campaigned towards using end-to-end encryption, with the UK authorities singling out plans by Meta to introduce end-to-end encrypted messaging on Fb.
Tech firms additionally face strain underneath the UK’s On-line Security Act to limit the distribution of unlawful or dangerous materials, which privateness campaigners say may discourage their use of encryption to guard prospects’ information.
Technical functionality notices
The ballot was performed in April 2026, following revelations that the UK authorities had issued a secret order towards Apple requiring it to supply the potential to entry end-to-end encrypted information and messages saved by its prospects on Apple’s iCloud.
A leak to the Washington Publish in February 2025 revealed that the UK had issued a secret technical functionality discover (TCN) focusing on customers of Apple’s Superior Information Safety (ADP) service wherever on this planet.
ADP, an optionally available service, permits Apple prospects to encrypt information and messages saved on iCloud with their very own encryption keys, making it inconceivable for Apple or anybody else with out entry to these keys to decrypt and skim them.
The order would have made it doable for UK regulation enforcement businesses to use for a warrant, which have to be accredited by an impartial judicial commissioner, to acquire Apple customers’ end-to-end encrypted information on iCloud.
Relatively than comply, Apple withdrew its ADP service from the UK. It stated in an announcement: “As we’ve got stated many instances earlier than, we’ve got by no means constructed a backdoor or grasp key to any of our services or products and we by no means will.”
The order sparked a diplomatic furore, together with protests from the US President’s senior advisor on intelligence and safety, Tulsi Gabbard, and US lawmakers, who complained that the UK’s actions would violate the privateness of Americans and weaken cyber safety.
TCN raises extra questions than solutions
The UK backed down and issued a revised TCN to Apple that it’s reported will solely goal British customers of its Superior Information Safety service, however the transfer raises extra questions than solutions, say privateness campaigners.
“What which means may be very unclear. How are they evaluating who’s a British person? Is that this really somebody with British citizenship? Is that this somebody who’s bodily current in Britain, which signifies that they’re in some way doing a little kind of geofencing,” stated Bowman.
Final 12 months, greater than 100 cyber safety consultants, firms and civil society teams signed a letter warning that the UK’s transfer to create a backdoor into individuals’s private information jeopardises the safety and privateness of hundreds of thousands, undermines the UK tech sector and units a harmful precedent for international cyber safety.
Going darkish
There was a long-running debate on whether or not using encryption means the web has “gone darkish” for regulation enforcement, however Bowman argues that this isn’t the case.
He stated that the general public understands that critical on-line crimes must be addressed, however there are higher methods to do that than permitting regulation enforcement businesses to learn everybody’s messages.
“You’ll find loads of examples the place regulation enforcement have used conventional investigation strategies, reminiscent of going undercover, infiltrating prison organisations and prison syndicates, creating nameless identities on-line to sort out critical crime, and none of that required breaking encryption,” he stated.
It has at all times been doable for individuals to report content material despatched by way of encrypted providers. WhatsApp, for instance, permits customers to report different customers for breaches, robotically sending WhatsApp copies of the final 5 messages that individual despatched.
UK-US Cloud Act settlement in danger
Within the US, strikes by Canada to introduce related powers to the UK’s technical functionality notices have put international surveillance again on the agenda of lawmakers.
They’re involved that Canada, just like the UK, might try to pressure US expertise firms to introduce mechanisms to entry end-to-end encrypted information.
That has centered US lawmakers’ consideration on the US Cloud Act, launched in 2018 to compel US expertise firms to supply information underneath a warrant to regulation enforcement, no matter whether or not the info is saved on servers outdoors the US.
A US-UK settlement underneath the Cloud Act offers UK businesses fast-track entry to information and communications held by US tech firms with out going by way of the sluggish technique of invoking a Mutual Authorized Help Treaty.
The settlement has massively benefited the UK, which between October 2022 and October 2024 issued greater than 20,000 requests to US tech firms, in contrast with solely 63 requests from the US to the UK.
Following the Apple case, some US lawmakers are contemplating amending the Cloud Act to forestall the US from coming into agreements with international locations, such because the UK, which have powers to serve TCNs, or their equal, towards US tech firms.
“I feel within the subsequent calendar 12 months, it’s very doubtless that we’ll see laws launched to reform the Cloud Act,” stated Bowman. “It might be an enormous loss for UK regulation enforcement and intelligence providers,” he added.
Apple filed a brand new authorized declare towards the Residence Workplace in April difficult the house secretary’s powers to concern a technical functionality discover, which is anticipated to be heard alongside a parallel authorized problem by Privateness Worldwide and Amnesty Worldwide.
Caroline Wilson Palow, authorized director and basic counsel of marketing campaign group Privateness Worldwide, which, together with Liberty, has filed a authorized problem towards the Residence Workplace within the Apple case, stated that the general public had been proper to fret about assaults on end-to-end encryption.
“What the federal government is evidencing on this alleged TCN and in any other case is that it has extreme scepticism of end-to-end encryption, and desires to have the ability to entry information simply that folks retailer on-line,” she instructed Laptop Weekly.
She stated end-to-end encryption is important for shielding individuals from hackers and cyber criminals, and that the federal government had different surveillance capabilities obtainable that didn’t contain weakening encryption, reminiscent of gear interference warrants.
“They don’t essentially want to interrupt end-to-end encryption. They may goal the units themselves, the endpoints, and attempt to get entry by way of different lawful processes,” she stated.
Questions raised over Ofcom powers
Questions have additionally been raised over whether or not the communications regulator, Ofcom, which is accountable for implementing on-line security, may require expertise firms to weaken end-to-end encryption sooner or later to guard towards youngster abuse materials.
Ofcom could have powers in future to concern expertise notices that might be used to require expertise firms to put in accredited expertise, reminiscent of client-side scanning, which critics say may introduce backdoor entry into encrypted providers that may weaken safety.
Nonetheless, any accredited expertise should meet minimal requirements of accuracy, and the regulator can solely require firms to put in measures that are “technically possible” – each vital hurdles to beat earlier than it may require firms to bypass end-to-end encryption.

