Secret encryption-breaking orders with no transparency reporting or parliamentary notification
Technical Capability Notices and National Security Notices under the Investigatory Powers Act 2016, as amended in 2024, are secret and gag their recipients. The January 2025 Apple order, Apple's withdrawal of Advanced Data Protection, and the replacement UK-only order of September 2025 became known only through leaks. No aggregate statistics on notices are ever published. The Technical Advisory Board reviewing them draws on government and industry only, and the Intelligence and Security Committee receives no notification. Litigation is the sole scrutiny channel: Apple's and Privacy International and Liberty's tribunal challenge was heard on assumed facts in early 2026 because government contested any open hearing. IPCO oversees notice use, reports nothing about them publicly, and says its resources are shrinking as demand grows.
Orders that can remove encryption from millions of people's data are made, varied and enforced entirely in secret, and the weakened security reaches everyone. Democratic accountability currently depends on leaks to journalists and one under-resourced tribunal case.
An IPA amendment package: mandatory annual publication of aggregate notice statistics, as the US and Germany publish for comparable orders, statutory notification of encryption-affecting notices to the ISC, a standing public-interest cryptography panel feeding Technical Advisory Board reviews, and a duty on IPCO to report on notice oversight. ORG and PI joint letters already sketch the coalition and the drafting.
// State-led: Instrument: IPA amendment mandating aggregate notice statistics, ISC notification and IPCO reporting duties; only Parliament can compel this.
Orders removing encryption from millions are made entirely in secret with no published statistics or ISC notification, and no legislative vehicle is yet moving.