The public is wary of UK government surveillance powers that require technology companies to build “backdoors’ to access encrypted communications, according to a poll of 2,000 people in the UK by a Washington-based advocacy group.
Only 12% of those surveyed believe the government should be able to issue secret orders to tech companies to allow government access to their private data, according to the poll commissioned by the Center for Democracy and Technology, which campaigns for strict independent oversight of government surveillance.
Conducted after the UK government issued a secret order to Apple to access end-to-end encrypted data stored by users on the Apple iCloud, the poll suggests the UK public believes there should be greater transparency over the use of government surveillance powers.
Over 90% of the people questioned said they should have a right to have private conversations online and 87% agreed that the government should have a legal obligation to tell people if their private conversations have been accessed.
Tom Bowman, policy counsel for security and surveillance at the Center for Democracy & Technology, said the British public find it “intolerable” that the UK can issue secret orders to tech companies without individuals ever being told that their communications have been targeted.
“If there is a warrant process in place that notifies the user, or at least provides an opportunity to challenge it, that would satisfy a lot of the pushback we are seeing in polling,” he said.
Governments and law enforcement agencies, including the National Crime Agency, Europol and the Five Eyes intelligence sharing partners, have campaigned against the use of end-to-end encryption, with the UK government singling out plans by Meta to introduce end-to-end encrypted messaging on Facebook.
Tech companies also face pressure under the UK’s Online Safety Act to restrict the distribution of illegal or harmful material, which privacy campaigners say could discourage their use of encryption to protect customers’ data.
Government issued secret technical capability notice
The poll was conducted in April 2026, following revelations that the UK government had issued a secret order against Apple requiring it to provide the capability to access end-to-end encrypted data and messages stored by its customers on iCloud.
A leak to the Washington Post in February 2025 revealed that the UK had issued a secret technical capability notice (TCN) targeting users of Apple’s Advanced Data Protection (ADP) service anywhere in the world.
ADP, an optional service, allows Apple customers to encrypt data and messages stored on iCloud with their own encryption keys, making it impossible for Apple or anyone else without access to those keys to decrypt and read them.
The order would have made it possible for UK law enforcement agencies to apply for a warrant, which must be approved by an independent judicial commissioner, to obtain Apple users’ end-to-end encrypted data from iCloud.
Rather than comply, Apple withdrew its ADP service from the UK. It said in a statement: “As we have said many times before, we have never built a backdoor or master key to any of our products or services and we never will.”
The order sparked a diplomatic furore, with protests from the US president’s senior advisor on intelligence and security, Tulsi Gabbard, and US lawmakers, who complained that the UK’s actions would violate the privacy of American citizens and weaken cyber security.
TCN raises more questions than answers
The UK backed down and issued a revised TCN to Apple that it is reported will only target British users of the Advanced Data Protection service, but the move raises more questions than answers, say privacy campaigners.
“What that means is very unclear,” said Bowman. “How are they evaluating who is a British user? Is this actually someone with British citizenship? Is this someone who’s physically present in Britain, which means that they are somehow doing some sort of geofencing?”
Last year, more than 100 cyber security experts, companies and civil society groups signed a letter warning that the UK’s move to create a backdoor into people’s personal data jeopardises the security and privacy of millions, undermines the UK tech sector and sets a dangerous precedent for global cyber security.
Is the internet going dark for law enforcement?
There has been a long-running debate on whether the use of encryption means the internet has “gone dark” for law enforcement, but Bowman argues that this is not the case.
He said the public understands that serious online crimes need to be addressed, but there are better ways to do this than allowing law enforcement agencies to read everyone’s messages.
“You can find plenty of examples where law enforcement have used traditional investigation methods, such as going undercover, infiltrating criminal organisations and criminal syndicates, creating anonymous identities online to tackle serious crime, and none of that required breaking encryption,” he said.
It has always been possible for people to report content sent through encrypted services. WhatsApp, for example, allows users to report other users for breaches, automatically sending WhatsApp copies of the last five messages that person sent.
UK-US Cloud Act agreement at risk
In the US, moves by Canada to introduce similar powers to the UK’s technical capability notices have put foreign surveillance back on the agenda of lawmakers.
They are concerned that Canada, like the UK, may attempt to force US technology companies to introduce mechanisms to access end-to-end encrypted data.
That has focused US lawmakers’ attention on the US Cloud Act, introduced in 2018 to compel US technology companies to provide data under a warrant to law enforcement, regardless of whether the data is stored on servers outside the US.
A US-UK agreement under the Cloud Act gives UK agencies fast-track access to data and communications held by US tech companies without going through the slow process of invoking a Mutual Legal Assistance Treaty.
The agreement has hugely benefited the UK, which between October 2022 and October 2024 issued more than 20,000 requests to US tech companies, compared with only 63 requests from the US to the UK.
What the government is evidencing in this alleged TCN and otherwise is that it has severe scepticism of end-to-end encryption, and wants to be able to access data easily that people store online Caroline Wilson Palow, Privacy International
Following the Apple case, some US lawmakers are considering amending the Cloud Act to prevent the US from entering agreements with countries, such as the UK, that have powers to serve TCNs, or their equivalent, against US tech companies.
“I think in the next calendar year, it’s very likely that we will see legislation introduced to reform the Cloud Act,” said Bowman. “It would be a huge loss for UK law enforcement and intelligence services,” he added.
Apple filed a new legal claim against the Home Office in April challenging the home secretary’s powers to issue a technical capability notice, which is expected to be heard alongside a parallel legal challenge by Privacy International and Amnesty International.
Caroline Wilson Palow, legal director and general counsel of campaign group Privacy International, which, along with Liberty, has filed a legal challenge against the Home Office in the Apple case, said that the public were right to worry about attacks on end-to-end encryption.
“What the government is evidencing in this alleged TCN and otherwise is that it has severe scepticism of end-to-end encryption, and wants to be able to access data easily that people store online,” she told Computer Weekly.
She said end-to-end encryption is essential for protecting people from hackers and cyber criminals, and that the government had other surveillance capabilities available that did not involve weakening encryption, such as equipment interference warrants.
“They don’t necessarily need to break end-to-end encryption. They could target the devices themselves, the endpoints, and try to get access through other lawful processes,” she said.
Questions raised over Ofcom powers
Questions have also been raised over whether the communications regulator, Ofcom, which is responsible for enforcing online safety, could require technology companies to weaken end-to-end encryption in the future to protect against child abuse material.
Ofcom will have powers in future to issue technology notices that could be used to require technology companies to install “accredited technology”, such as client-side scanning, which critics say could introduce backdoor access into encrypted services that would weaken security.
However, any accredited technology must meet minimum standards of accuracy, and the regulator can only require companies to install measures which are “technically feasible” – both significant hurdles to overcome before it can require companies to bypass end-to-end encryption.
A Gartner survey of 2,500 executive leaders has found that almost half (45%) say publicity of ChatGPT has prompted them to increase artificial intelligence (AI)…
Table of Contents Accessibility, past and present The role of AI in accessibility Accessibility means usability for everyone A graphical user interface (GUI) is the…
If the UK’s digital economy is to enjoy a prosperous future, the nation’s electricity grids need to be urgently upgraded to ensure the datacentres underpinning…
Three years after going public with its plan to open its first European datacentre in Dublin, Ireland, TikTok has confirmed the site is now operational…