Featured Article : Apple Stops Advanced Data Protection Feature in the UK

Apple has announced the removal of its Advanced Data Protection (ADP) tool from customers in the United Kingdom, following a contentious dispute with the UK government over user data access.

Debate Ignited

The decision, which sees one of the world’s leading tech companies bowing out of a security standoff, has ignited debates over digital privacy, national security, and the future of encryption standards in the UK and beyond.

What is the Advanced Data Protection Tool?

Advanced Data Protection is Apple’s most robust encryption feature, providing end-to-end encryption for users’ iCloud data, including photos, notes, and backups. With ADP enabled, only the account holder can access this information, not even Apple itself can decrypt the data. The feature, introduced globally in late 2022, was designed to offer users greater control and protection against data breaches and cyber-attacks.

However, unlike standard encryption, which allows Apple to access certain user data when presented with a valid legal request, ADP closes off even this possibility. This heightened level of security made it particularly attractive to privacy-conscious users, but it has now become the focal point of a growing dispute between Apple and the UK government.

The UK’s Demand for Access (A ‘Back Door’)

Apple’s decision follows a demand from the UK government, issued under the Investigatory Powers Act 2016 (IPA), which compels companies to provide data access to law enforcement agencies when legally requested. While Apple has long opposed creating “backdoors” into its systems, arguing that any intentional vulnerability could be exploited by cybercriminals, the UK’s insistence on access led to an impasse.

The UK government has not officially confirmed issuing a formal notice under the IPA, maintaining its policy of not commenting on operational matters. However, some media commentators have suggested that UK government pressure has been escalating behind the scenes, and may now have prompted Apple to withdraw ADP for UK customers entirely.

Apple’s Disappointment

In a strongly worded statement, Apple has expressed deep disappointment at having to disable ADP for UK users, and has said: “As we have said many times before, we have never built a backdoor or master key to any of our products, and we never will.”

The company has also highlighted the broader implications of weakening encryption, arguing that such actions would endanger all users by creating vulnerabilities exploitable by malicious actors or cybercriminals. Apple’s stance reflects a broader concern shared by many cybersecurity experts and privacy advocates who fear that undermining encryption in one country could set a dangerous global precedent.

What This Means for UK Apple Users

Apple’s decision essentially means that any Apple user in the UK now attempting to enable ADP will simply receive an error message. Existing users who had previously activated the feature will also see it disabled in the coming weeks.

It seems that while some forms of encryption remain intact (i.e. iMessages, FaceTime communications, and sensitive health data stored on iCloud) and will continue to be protected by end-to-end encryption, while other data types (such as full device backups and photos stored in iCloud) will no longer enjoy the same level of security in the UK. Under standard encryption, Apple retains the ability to access these files and could be compelled to share them with law enforcement upon receipt of a valid warrant.

Security vs. Privacy

The UK government’s push to weaken end-to-end encryption has sparked fierce opposition from privacy campaigners and cybersecurity experts. For example, Professor Alan Woodward, a cybersecurity specialist at the University of Surrey, has been quoted as describing the move as “an act of self-harm” by the government, adding: “All the UK government has achieved is to weaken online security and privacy for UK-based users.”

However, the UK government claims its perspective has been driven by concerns around national security and child protection. This view is supported by some relevant organisations. For example, Rani Govender, policy manager for child safety online at the NSPCC, has been quoted as arguing that encryption could allow offenders to operate undetected, saying: “End-to-end encryption allows offenders to groom and manipulate children and build communities where they can share vile child sexual abuse material without detection.”

It seems, therefore, that the tension between privacy and protection is a delicate balance for tech firms operating under diverse international legal frameworks.

International Backlash and Global Ramifications

Apple’s withdrawal of ADP in the UK has drawn sharp criticism from global privacy advocates and even US lawmakers. For example, Democrat Senator Ron Wyden (from Oregon) has been quoted as calling the move a “dangerous precedent” that authoritarian governments could exploit to justify similar demands in their own jurisdictions.

The broader concern appears to be that once a tech company concedes to one government’s demands for weakened encryption, it becomes increasingly difficult to resist similar pressures from other nations, including those with less regard for human rights and privacy.

Competitors and Market Impact

Apple’s decision could also have repercussions across the wider technology sector. Competitors like Google, Meta (formerly Facebook), and WhatsApp (which also rely on end-to-end encryption) may now face mounting pressure from governments to implement similar data access measures. WhatsApp head Will Cathcart has warned that any weakening of encryption standards would compromise user security worldwide, saying: “If the UK forces a global backdoor into Apple’s security, it will make everyone in every country less safe.”

Also, the decision could erode consumer trust among UK users who are particularly conscious of (and value) their data privacy. Tech-savvy consumers may seek alternatives that continue to offer uncompromised encryption features, potentially benefiting companies headquartered in jurisdictions with stronger privacy protections.

The Future of Encryption in the UK

For now, it seems that, despite its current disappointment, Apple remains hopeful that it will be able to reinstate ADP in the UK in the future. In its official statement, the company highlighted its commitment to user privacy, saying: “Enhancing the security of cloud storage with end-to-end encryption is more urgent than ever before.”

However, the ongoing dispute highlights the growing tension between governments seeking broader surveillance powers and technology firms defending user privacy. As the legal and ethical debate continues, UK consumers are left grappling with the uncomfortable reality of diminished digital protections in an increasingly interconnected world.

What Does This Mean for Your Business?

Apple’s removal of Advanced Data Protection (ADP) in the UK is a significant moment in the ongoing global debate over privacy, security, and governmental oversight. While the decision may seem like a straightforward technical adjustment, its broader implications touch upon issues of individual privacy rights, corporate responsibility, and the balance of power between governments and multinational technology firms.

At its core, this move by Apple highlights the increasing pressure technology companies face when navigating conflicting legal frameworks across different jurisdictions. Apple’s steadfast refusal to implement backdoors, despite mounting governmental pressure, aligns with its long-standing commitment to user privacy. However, by disabling ADP for UK users, Apple has effectively signalled that even the most privacy-focused companies must sometimes yield to local laws and regulatory demands, no matter how much they contradict the company’s own policies.

For UK businesses and organisations, this development raises immediate and pressing concerns. Companies that handle sensitive data (such as those in finance, healthcare, or legal sectors) may now find themselves at greater risk of data breaches or unauthorised access. With the most robust form of encryption disabled, organisations may need to reconsider their data protection strategies. This could mean investing in alternative security measures or exploring third-party services that still offer uncompromised encryption. Also, businesses that work internationally may find the regulatory discrepancy between the UK and other regions increasingly difficult to navigate, potentially leading to compliance headaches and increased operational costs.

On the international stage, the ripple effects of Apple’s decision may be far-reaching. Other governments, especially those with poor human rights records, could view this development as an opportunity to justify their own demands for weakened encryption. In this light, the UK’s stance may inadvertently contribute to a global erosion of digital privacy standards, emboldening authoritarian regimes to push for similar concessions from tech companies.

For consumers, the removal of ADP is a reminder of the fragile nature of digital privacy in an age of heightened governmental surveillance. Those in the UK who value strong encryption protections may begin to seek alternatives, potentially favouring services or platforms based in countries with stricter privacy laws. This shift could have longer-term consequences for Apple’s market share in the UK and could drive innovation among competitors aiming to fill the void left by ADP’s removal.

Tech News : Ryanair Third-Party Data Protection Inquiry

What happens to data gathered as part of Ryanair’s extra ID verification requirement (from customers who don’t book directly through its website), has led to an inquiry being launched by Ireland’s Data Protection Commission (DPC).

Why ID Verification? 

For travellers booking flights through third-party websites or online travel agents (OTA), rather than directly through Ryanair, the Irish low-cost airline requires them to complete a Customer Verification Process. The reason, given by Ryanair, is that third-party agents sometimes provide incorrect or incomplete passenger information, e.g. fake contact or payment details, which can interfere with Ryanair’s ability to communicate important flight details directly to passengers.

Also, Ryanair has long opposed OTAs and third-party websites that sell its tickets without permission, often through “screen scraping” techniques. This practice involves OTAs gathering flight data from Ryanair’s website and reselling tickets, sometimes at inflated prices. Ryanair argues that this is what leads to the incorrect information being given to it, and to poor customer experiences. For example, in July 2024, a US court ruled against Booking.com in a screen-scraping case, reinforcing Ryanair’s stance. The airline, therefore, urges customers to book directly through its site to avoid such issues and ensure proper communication and service.

What Type of ID Verification Does Ryanair Require? 

Ryanair offers travellers two verification options when they attempt to book flights through OTAs and third-party websites. These are:

– Express verification. This (faster option) actually uses facial recognition technology to confirm the traveller’s identity. It costs around €/£0.59 and can be completed in a few minutes with the use of a passport or national ID and a device with a camera.

– Standard Verification. This is the free alternative where travellers submit a signed customer verification form along with their ID. However, this method can take up to seven days to process, so it’s not ideal for last-minute bookings.

Why The DPC Inquiry? 

It seems, however, that aspects of Ryanair’s ID verification requirement have led to scrutiny, particularly concerning the use of facial recognition and compliance with GDPR regulations.

On October 4, Ireland’s DPC announced that it had opened an inquiry into Ryanair’s processing of personal data as part of the Customer Verification Processes in question. Graham Doyle, Deputy Commissioner with the DPC commented: “The DPC has received numerous complaints from Ryanair customers across the EU/EEA who after booking their flights were subsequently required to undergo a verification process. The verification methods used by Ryanair included the use of facial recognition technology using customers’ biometric data. This inquiry will consider whether Ryanair’s use of its verification methods complies with the GDPR.” 

Data Processing  

The DPC said the decision to conduct the inquiry under Section 110 of the Data Protection Act 2018[2], taken by the Commissioners for Data Protection, Dr. Des Hogan and Dale Sunderland, “was notified to Ryanair earlier this week”. The DPC has also said the inquiry is “cross-border [3] in nature” (reportedly, with one other country) and “will consider whether Ryanair has complied with its various obligations under the GDPR, including the lawfulness and transparency of the data processing”. 

Considering Ryanair is an international airline, it’s perhaps not surprising that there’s a cross-border nature to the inquiry. Looking at the wider meaning of DPC’s statement about the inquiry, it looks likely that it will assess whether Ryanair’s data processing practices comply with the GDPR, particularly focusing on key areas like lawfulness (whether Ryanair had a legitimate basis to collect and use passengers’ data) and transparency (whether passengers were adequately informed about how their data would be used). This scrutiny is often triggered when there are concerns over how personal data, including sensitive information such as biometric data, is handled, especially given Ryanair’s use of facial recognition technology during its verification process.

What Does Ryanair Say? 

A Ryanair spokesperson has been (widely) quoted as saying: “We welcome this DPC inquiry into our Booking Verification process, which protects customers from those few remaining non-approved OTAs, who provide fake customer contact and payment details to cover up the fact that they are overcharging and scamming consumers. 

“Customers who book through these unauthorised OTAs are required to complete a simple verification process (either biometric or a digital verification form) both of which fully comply with GDPR. This verification ensures that these passengers make the necessary security declarations and receive directly all safety and regulatory protocols required when travelling, as legally required.” 

What Does This Mean For Your Business? 

The inquiry into Ryanair’s third-party booking verification process not only places the airline under scrutiny but also raises significant questions for the wider aviation industry. As data protection laws like the GDPR continue to evolve, airlines worldwide must carefully consider how they collect, process, and store customer data, particularly when it comes to sensitive biometric information. It’s worth remembering that this case relates to the use of acial recognition just at the booking stage, not at passport control, and with the DPC examining whether Ryanair’s use of facial recognition and other data practices comply with GDPR, this case could set a precedent that impacts other airlines, potentially forcing them to reassess their own data handling processes to avoid similar regulatory challenges.

For Ryanair’s competitors, should the DPC find Ryanair’s practices in breach of GDPR, it might prompt a broader review of data collection methods across the industry. Airlines that rely on similar verification processes, or those planning to introduce biometric solutions, may need to quickly adapt to ensure compliance. On the other hand, airlines with more traditional booking and verification systems could use this moment to differentiate themselves by emphasising stronger privacy protections and more transparent data use.

From a customer perspective, the inquiry highlights growing concerns about privacy and the use of personal data in an increasingly digital world. As biometric technology becomes more common in verification and security processes, passengers are becoming more aware of how their data is used and protected. Trust, transparency, and a clear explanation of how personal data is processed may become critical factors in how customers choose which airline to fly with. Airlines that successfully balance security with privacy may gain a competitive advantage, particularly in an industry where reputation and customer loyalty are so crucial.

Ultimately, the outcome of this inquiry may have some far-reaching consequences, not only for Ryanair but for the aviation sector as a whole. This case is a reminder that data protection is now a key pillar of operational strategy, and one that cannot be overlooked in the drive to enhance customer security and streamline digital processes. The industry will be watching closely to see how Ryanair navigates these regulatory waters and what this means for the future of data handling in the aviation world.

Why Microsoft 365 Backup is Essential

In this article, we look at why, as reliance on cloud services like Microsoft 365 grows, ensuring robust data backup has become a critical component of business security and continuity, then we look at some best practices for your 365 backups.

The Misconception – Microsoft 365 Backup Myths 

Many businesses are surprised to learn that they’d been operating under the false assumption that Microsoft 365 automatically provides comprehensive data backup.

In reality, Microsoft 365’s built-in protections, such as retention policies, recycle bins, and versioning, are designed for data retention and compliance rather than comprehensive backup and recovery. For example, email isn’t properly “backed-up” by Microsoft in 365. Instead, the onus is on the business-owner to find their own email backup solution. In fact, Microsoft 365’s backup and recovery default settings only really protect your data for 30-90 days on average (the recycle bin only retains deleted items for 30 days, after which they are permanently deleted).

How Does 365 Handle Email and Other Data? 

While Microsoft 365 doesn’t provide traditional email backup, it does offer several data handling protections, including:

– Data Resilience. Microsoft maintains multiple copies of your data. If a disk fails or a data center issue arises, they can recover data from these copies. However, this isn’t equivalent to a dedicated backup that protects against accidental deletions or malicious activity.

– Retention Policies. You can set retention policies specifying how long emails are kept in user mailboxes. Deleted emails can be retained in a hidden part of the mailbox for a specified period.

– Litigation Hold. For legal purposes, entire mailboxes or specific emails can be put on “Litigation Hold,” ensuring they can’t be deleted or modified. eDiscovery tools allow legal professionals to search for specific data across the environment.

– Email Archiving. Older emails can be moved automatically to an archive mailbox, helping businesses retain critical data without cluttering the primary mailbox.

– Recoverable Items Folder. Deleted emails first go to the ‘Deleted Items’ folder, and if deleted from there, they move to the ‘Recoverable Items’ folder for another 14 days by default (this period can be extended).

Limitations 

That said, despite these features, they aren’t substitutes for a dedicated email backup solution and they have limitations which include:

– Data Loss Protection. They may not protect against all types of data loss, especially if data is deleted before a retention policy is set or if the retention period expires.

– Ease of Recovery. They don’t facilitate easy recovery if a vast amount of critical data is accidentally or maliciously deleted.

– Offsite Backup. They don’t offer a separate, offsite backup in case of catastrophic issues or targeted attacks.

Data Loss Risks in Microsoft 365 

Bearing in mind the limitations of Microsoft 365 and understanding the potential risks associated with data loss in Microsoft 365 is therefore crucial for businesses looking to protect their sensitive information and ensure seamless operations.  While Microsoft 365 may offer many advantages, it’s worth remembering that it’s not immune to data loss, which can occur in several ways.

Recognising these risks is the first step in implementing effective backup strategies to safeguard your data. With this in mind, below are some of the key data loss risks that businesses should be aware of when using Microsoft 365:

– Accidental deletion. Users may, for example, inadvertently delete important emails, files, or records. Without a proper backup, recovery may be impossible after the recycle bin period expires.

– Malicious deletion. Disgruntled employees or cyber-attacks can lead to intentional data deletion. For instance, in a 2023 survey (Ponemon Institute), 59 per cent of organisations reported insider attacks, underscoring the very real risk of malicious deletion by former employees or hackers. It’s worth remembering here how important it is to have an effective employee offboarding procedure to avoid this happening in the first place.

– Internal and external security threats. Phishing attacks, ransomware, and other cyber threats can compromise data integrity. In 2023, for example, the UK’s National Cyber Security Centre (NCSC) reported a 15 per cent increase in ransomware attacks targeting businesses, emphasising the need for secure data backups.

– Legal and compliance issues. Compliance with regulations such as GDPR necessitates maintaining data integrity and availability. Failure to do so can result in hefty fines. For example, the UK Information Commissioner’s Office (ICO) fined British Airways £20 million in 2020 for a data breach that compromised customer information. Also, in a more recent high-profile case, the ICO fined TikTok an eye-watering £12.7 million in April 2023 for various breaches of UK data protection law. Although these relate to large turnover businesses which may contribute to the larger fines, the key point is that they help highlight the fact that there is a real legal and financial risk of inadequate data protection, a cause of which may be an inadequate backup, e.g. of 365.

Limitations of Microsoft 365’s Built-in Protection 

While Microsoft 365 offers several data protection features, they have significant limitations. As previously mentioned, retention policies and recycle bins, for example, provide limited recovery windows and are not designed for long-term data protection. Once data surpasses the retention period, it is permanently lost.

Similarly, versioning allows recovery of previous document versions but does not protect against complete file deletion or data corruption.

These native tools are not full, automated backup solutions, and businesses relying solely on them risk permanent data loss in critical scenarios.

The Benefits of a Dedicated Microsoft 365 Backup Solution 

So, why invest in a dedicated (third-party) Microsoft 365 backup solution?

Comprehensive data protection ensures that all data (including emails, files, and collaborative documents) is regularly backed up and easily recoverable. This means that if an important email or document is accidentally deleted or maliciously removed, you can quickly restore it without disrupting your business operations.

Also, dedicated backup solutions offer quick and reliable recovery. Unlike relying on native tools, which can be cumbersome and time-consuming, dedicated backups enable faster data restoration, thereby minimising downtime and ensuring business continuity.

It’s worth remembering that these solutions can actually enhance security. Many third-party backup providers offer advanced encryption and security measures that go beyond Microsoft’s native protections. This additional layer of security is crucial in safeguarding sensitive business information from cyber threats.

Also, as previously highlighted, dedicated backup solutions can support compliance with legal requirements. With regulations like GDPR imposing strict data protection standards, having a reliable backup can help ensure that your business meets these requirements, reducing the risk of non-compliance penalties.

In fact, Microsoft itself actually recommends that businesses deploy a third-party backup solution because it recognises the limitations of its own native tools and backup and retention policies. It’s also worth noting here that investing in a separate “point-in-time” backup and restoration solution is something that many businesses value. As the name suggests, this type of solution allows a business to return to a point-in-time before any issues.

Integration with Business Continuity Plans 

Your Microsoft 365 data is a critical component of a comprehensive business continuity plan because ensuring data availability and integrity is essential for seamless business operations, even in the event of data loss incidents. Quick recovery times provided by dedicated backups can help reduce downtime, thereby allowing businesses to resume operations promptly.

Also, robust backup solutions can complement disaster recovery plans, thereby ensuring that data can be quickly restored in emergencies, such as cyber-attacks or natural disasters. In essence therefore, backups are the safety net that allows businesses to bounce back swiftly from disruptions, maintaining operational efficiency and customer trust and perhaps even being the thing that saves the whole business.

Why Employee Training and Awareness Can Help 

Effective data protection extends beyond technology to include employee education. For example, educating staff about the importance of data security and proper handling procedures can be crucial in mitigating risks.

Measures like regular phishing awareness training can significantly reduce the likelihood of successful attacks. For example, a 2022 report (Cofense) found that phishing simulations reduced click rates on malicious emails by 68 per cent. Creating a culture of security within your organisation encourages proactive participation in data protection efforts, making every employee a stakeholder in the company’s security posture.

Regular updates and refreshers keep employees informed about new threats and evolving backup protocols. This ongoing education and training ensures that staff are always aware of best practices and the importance of adhering to them, further strengthening your business’s defences against data loss.

Linking these efforts to your Microsoft 365 backup strategy can help ensure a comprehensive approach to data protection. For example, while technical measures like backups are essential, combining them with a well-educated workforce maximises your organisation’s resilience against data loss and cyber threats. This integrated approach can help ensure that your data remains secure, accessible, and compliant with regulatory requirements, ultimately helping to safeguard your business’s continuity and reputation.

Implementing Microsoft 365 Backup – Best Practices 

Adopting an effective Microsoft 365 backup strategy involves several best practices. For example:

– Selecting the right backup solution is critical. Businesses should choose a provider that offers comprehensive coverage, reliability, and security. Key factors include encryption, automated backups, and ease of data restoration, and whether it’s a “point-in-time” backup solution.

– Once a solution has been selected, setting up and managing backups properly is essential. This involves configuring the backup system to ensure all relevant data is included and regularly monitored to confirm that backups are occurring as scheduled.

– Also, conducting periodic tests and audits of backup systems can help ensure they function as expected and identify potential issues before they become critical problems. Regular testing verifies that data can be restored quickly and accurately, providing peace of mind that your business is prepared for any data loss scenario.

What Does This Mean For Your Business? 

Ensuring the security and integrity of your data is now not just a technical necessity but a business imperative. The increasing reliance on cloud services like Microsoft 365 brings many benefits but also exposes businesses to some significant risks if data protection measures are inadequate.

The potential risks of data loss, e.g. resulting from anything from accidental deletions to malicious cyber-attacks, highlight the necessity of having a robust backup strategy in place. It’s worth noting however, that Microsoft 365’s native tools, while useful, are insufficient for comprehensive data protection. Many businesses have now realised this and have decided that dedicated, third-party backup solutions can provide the necessary depth of coverage, security, and compliance support that they need.

Ensuring data availability is also crucial for business operations. Having a dedicated backup solution can guarantee that data is always accessible, even after accidental or malicious deletion. This can minimise downtime and helps maintain business continuity, ensuring that operations can proceed smoothly without significant interruptions.

Additionally, adhering to data protection regulations like GDPR is essential to avoid legal penalties and protect customer trust. Once again, reliable, regular backups help businesses meet these regulatory requirements, reducing the risk of non-compliance penalties and safeguarding the company’s reputation.

The security enhancements offered by dedicated backup solutions, such as advanced encryption, may also prove to be vital in protecting sensitive business information. These solutions provide an additional layer of security, ensuring that your data remains secure from a variety of evolving and what appear to be ever-more-sophisticated cyber threats.

Implementing a dedicated Microsoft 365 backup solution should therefore be seen as a proactive step towards securing your business’s future. By addressing the gaps in Microsoft’s native protections and integrating comprehensive backup strategies, businesses can safeguard against data loss, ensure regulatory compliance, and maintain seamless operations. In today’s digital landscape, where data is a critical asset, protecting it with reliable backup solutions is not just advisable, it’s essential and investing in a robust Microsoft 365 backup strategy protects your data, fortifies your overall security posture, provides peace of mind, and can deliver a solid foundation for continued growth and success.