Technical Capability Notices Under the Investigatory Powers Act: What They Can Actually Compel a Company to Do
In January 2025 the Home Office reportedly served Apple with a notice demanding it build a way for UK authorities to access iCloud data protected by Advanced Data Protection, Apple's opt-in end-to-end encryption for backups. Apple didn't comply and didn't confirm the notice existed, because confirming it exists is itself an offence. Instead it pulled Advanced Data Protection from the UK entirely in February 2025 and took the matter to the Investigatory Powers Tribunal. Reporting since then suggests the original worldwide demand was dropped in August 2025 after pressure from the US, and that a narrower notice covering UK users' data followed in its place, which Apple is still challenging, with a case management hearing listed for September 2026 and a substantive hearing in December.
Most of what's known about this case comes from leaks and journalism, not from anything either party was legally able to say. That opacity is not incidental. It's the point of the power being used, a technical capability notice under section 253 of the Investigatory Powers Act 2016. I've written before about data retention notices under the same Act, which force ISPs to log and store communications data. TCNs are a different instrument entirely: they don't ask a company to hand over data it already has, they ask it to build and maintain the ability to comply with a future demand, and to keep quiet about having been asked.
What section 253 actually lets the Secretary of State require
Section 253 lets the Secretary of State give a "relevant operator", a definition broad enough to cover postal and telecommunications operators of any size, a notice imposing "applicable obligations" for the purpose of securing that the operator has the capability to provide assistance in relation to a future warrant or authorisation. It's forward-looking by design: a TCN isn't itself a demand for data, it's a demand that the plumbing exist so that a later, separate authorisation can be actioned quickly and without the operator being able to say no on technical grounds.
The obligations a notice can specify include:
- providing facilities or services of a specified description
- maintaining apparatus, including equipment the operator owns or runs
- the removal of "electronic protection applied by or on behalf of that operator to any communications or data"
- the security of postal or telecommunications services the operator provides
- the handling or disclosure of information
The obligations that can actually be imposed are set out in more detail in secondary legislation, the Investigatory Powers (Technical Capability) Regulations 2018, made after consultation with the Technical Advisory Board and affected industry as required by section 253(6). The notice itself then specifies the concrete steps the operator must take and a reasonable timeframe for taking them, per section 253(7).
The double lock, and why it doesn't do what it sounds like
TCNs go through the same "double lock" as interception warrants under the Act: the Secretary of State decides the notice is necessary and proportionate, and a Judicial Commissioner has to approve that decision before it takes effect. Under section 254, the Commissioner reviews the Secretary of State's conclusions on necessity and proportionality applying ordinary judicial review principles, and must give written reasons if they refuse.
It's worth being precise about what this buys you. Judicial review principles ask whether the decision-maker acted lawfully, rationally and proportionately given the material in front of them, not whether the Commissioner would have made the same call on the merits. It's real independent scrutiny, considerably more than a rubber stamp, but it's not the same as an adversarial hearing where the operator gets to make its case before the notice is issued. The operator finds out when the notice arrives.
The gag clause
This is the feature that makes TCNs unusual even by the standards of investigatory powers law. Section 255(8) provides that a person given a relevant notice, or anyone employed or engaged for the purposes of that person's business, must not disclose the existence or contents of the notice to any other person without the Secretary of State's permission. That covers telling your users, telling a journalist, telling a regulator in another country, and, on a strict reading, telling your own shareholders. The Act enforces the duty through civil proceedings rather than a specific criminal offence, giving the Secretary of State the option of an injunction against a threatened or actual breach.
The practical effect is that a company served with a TCN cannot simply announce it's fighting one. That's why nearly everything reported about the Apple case has come from unnamed sources rather than statements from Apple or the Home Office, and why Apple's tribunal hearings have reportedly been held partly in secret. You end up in the odd position of a law firm, a journalist, or a Member of Parliament being able to describe the shape of a notice they've heard about, while the one party who could confirm the details in full is legally barred from doing so.
Where the Apple dispute actually turns
The interesting legal question in the Apple case isn't whether a TCN can require encryption to be weakened in the abstract, it's what "electronic protection applied by or on behalf of that operator" means when the whole design point of Advanced Data Protection is that Apple doesn't hold the keys. Apple built the system, ships the client, and operates the iCloud infrastructure the encrypted blobs sit in, so there's a reasonable argument that protection Apple engineered and rolled out to its users counts as protection applied "on behalf of" the operator even though Apple itself can't decrypt the result. Apple's evident position is that a scheme specifically designed to keep the operator out of the loop shouldn't be treated as something the operator can simply be told to reverse. The Act doesn't spell out an answer to that either way, which is exactly the kind of question a tribunal, not a phone call, is for.
Whatever the outcome, the underlying instrument only works on operators the UK can compel. It has always been notable that Apple, a US company with no obligation to prioritise UK compliance over commitments elsewhere, chose to withdraw a feature rather than build a backdoor, and that the pressure that reportedly moved the Home Office off its original worldwide demand came from another government rather than from litigation. A domestic ISP facing a TCN doesn't have that leverage.
What this means if you're the operator on the receiving end
If your company is a "relevant operator" under the Act, which in practice can mean anyone providing a telecommunications or postal service to UK users, a TCN is not a request you can quietly decline on the basis that compliance is technically inconvenient. The Technical Capability Regulations exist precisely to normalise the expectation that certain classes of operator maintain the relevant capability as a condition of operating, and by the time a notice arrives the "is this feasible" conversation is meant to have already happened through the Technical Advisory Board consultation process, not at your desk.
What you can do, per the Act itself, is refer the notice back for review before complying, and challenge it through the Investigatory Powers Tribunal, which is the route Apple has taken twice now. What you cannot do, absent the Secretary of State's permission, is tell your users you've received one. For a company whose entire product pitch rests on a promise about what it can and can't see, that silence is arguably the more consequential half of the power.