
· Analysis · 11 sources · opinion
Apple's new UK privacy fight doesn't touch the lock on your spare parts
Apple is back at the UK's Investigatory Powers Tribunal over a government demand for encrypted iCloud backups. Apple's own documentation shows Activation Lock, which governs whether a salvaged iPhone part will calibrate, sits outside that dispute entirely.
The short answer
Apple filed a fresh complaint with the UK’s Investigatory Powers Tribunal in July 2026, contesting a government demand that it retain the technical capability to hand over encrypted iCloud backups for UK accounts. That dispute concerns a specific, named list of iCloud content categories protected by a setting called Advanced Data Protection: backups, photos, notes and similar. It has nothing to do with Activation Lock, the separate system that decides whether a salvaged iPhone part will calibrate in another phone. Apple’s own published breakdown of what Advanced Data Protection covers does not list Find My or Activation Lock anywhere in it, in either its protected or unprotected form.
Where this comes from
This is a reading of Apple’s own technical documentation and legislation, checked against this week’s news coverage. The story broke via the Financial Times; that article sits behind a paywall I could not get past from here, so the facts below rest on three independent outlets that reported the filing separately - iClarified, AppleInsider and MacRumors - plus Apple’s own support pages, the Investigatory Powers Act itself, and independent repair-industry reporting from iFixit. No manufacturer was contacted and nothing was tested for this piece.
What Apple actually filed
Apple submitted a complaint to the Investigatory Powers Tribunal (IPT) in July 2026 over a “technical capability notice” (TCN) - a formal demand issued under section 253 of the Investigatory Powers Act 2016, which lets the Secretary of State require a company to maintain the capability to meet obligations that can include “removing electronic protection from communications or data” (legislation.gov.uk). This is Apple’s second run at the same underlying demand.
The background, corroborated across iClarified, AppleInsider and MacRumors:
- Early 2025: the UK government issued Apple a TCN covering iCloud accounts worldwide. Apple challenged it at the IPT and, rather than build the access demanded, withdrew Advanced Data Protection for new UK users. Apple’s own support page on the withdrawal is dated 23 September 2025 and says: “We are deeply disappointed that our customers in the UK will no longer have the option to enable Advanced Data Protection (ADP)… we have never built a backdoor or master key to any of our products or services and we never will” (Apple Support).
- August 2025: the UK dropped the worldwide version of the order, reportedly after diplomatic pressure from Washington.
- October 2025: the UK issued a narrower TCN, covering UK accounts only.
- July 2026: Apple filed this month’s complaint against that narrower notice.
Neither Apple nor the Home Office is legally permitted to discuss the contents of a TCN, which is why the reporting above works from what’s been confirmed rather than from the notice itself. Privacy International and Liberty are separately challenging the legal secrecy regime around TCNs in general, in a parallel case at the same tribunal - a dispute about the process, distinct from Apple’s complaint about this specific notice.
What Advanced Data Protection covers, exactly
Apple publishes the actual list. Without Advanced Data Protection turned on, 15 iCloud data categories are end-to-end encrypted by default regardless - among them Keychain passwords, Health data, Messages in iCloud, and Wi-Fi passwords. Turning Advanced Data Protection on adds a further 10: iCloud Backup, iCloud Drive, Photos, Notes, Reminders, Safari Bookmarks, Shortcuts, Voice Memos, Wallet passes and Freeform (Apple Support).
Find My and Activation Lock do not appear in either list. That’s checkable directly on Apple’s own page - it isn’t an omission I’m inferring, it’s a category simply not present in either column of the table.
The separate lock: Activation Lock and parts pairing
Activation Lock works by a different mechanism entirely. Per Apple’s own Platform Security Guide, a device requests an “activation certificate” from Apple’s activation server, and the lock can also be toggled by a device-management service acting directly with that server (Apple Support). It’s a certificate exchange with a specific server, not a content-encryption category, and Find My’s own location data is separately protected by device-generated keys synced only between a user’s own devices - already end-to-end regardless of any account setting.
In April 2024, Apple extended Activation Lock to individual iPhone parts, specifically to stop stolen or lost phones being broken up for components. Its own announcement: “If a device under repair detects that a supported part was obtained from another device with Activation Lock or Lost Mode enabled, the calibration for that part will be restricted once it’s installed in the new phone” (Apple Newsroom). iFixit, which tracks parts pairing closely, had previously reported that “the system that enables parts pairing is a totally separate system from the one Apple uses to lock stolen devices” - true before the 2024 change linked them, and the two remain distinct systems even now that a locked part can block calibration elsewhere. Its later reporting on refurbishers’ experience of the change was blunt: “You cannot use an Activation Locked device as a parts machine” once a component carries the lock (iFixit).
What it means for you
If you repair, refurbish or salvage phones for parts, this month’s IPT complaint is not a case to watch for changes to Activation Lock enforcement. It’s also not the same fight as the parts-pairing bans working through Colorado and Oregon law: those restrict what a manufacturer’s pairing software can refuse to do. Activation Lock is a separate, anti-theft system, and neither this case nor those state laws currently reach it. On the public record, the two systems don’t overlap: the TCN dispute is about UK government access to a defined set of iCloud content categories, and Activation Lock is a separate authentication check against Apple’s own activation servers that has nothing to do with that list. Whichever way this case goes, it doesn’t touch whether a salvaged screen or battery will calibrate in another phone.
What has actually changed the parts-locking picture is the 2024 extension of Activation Lock to individual components, which is unrelated to this litigation and has been in effect since iOS 18. If you’re dealing with locked parts, that’s the change that matters, not this case.
It’s worth being precise about the limits of that reassurance too. This is about the current dispute, not a permanent guarantee - a future, differently scoped notice could in principle target other systems. Nothing in the reporting on this case suggests that’s happening, and it isn’t something this piece can responsibly speculate about beyond noting the possibility exists.
OpinionA judgement on the facts above, not a finding. It rests only on what is quoted on this page.
My view
In my view Apple is right to keep fighting this. A government that tried for worldwide access, backed down only when another government’s diplomatic pressure made it costly, and then came back with a narrower version of the same demand hasn’t abandoned the underlying ask - it’s resized it to what it can get away with. The stated justification for technical capability notices generally is investigating terrorism and child exploitation, but that doesn’t explain why the mechanism has to be a capability that removes encryption for every UK account holder’s backups rather than a targeted, court-supervised route aimed at a specific suspect. A backdoor built to satisfy one government’s notice doesn’t stay built for just that notice.
Opinion, based on the evidence set out above.