Skip to content
Phone SeizedThey have your phone?
Menu

Phone SeizedWhat is on your phoneWhat lives in the cloud and with your carrier, not on the phone

What lives in the cloud and with your carrier, not on the phone

Applies to: England & Wales · Scotland · Northern Ireland · Australia · United States. The law differs materially between jurisdictions this site covers — do not apply this page outside the one named here. Law also varies by state and territory in Australia — this page does not describe every state or territory. Law also varies by state, and by federal circuit, in the United States — this page does not describe every state or circuit.

What you must do, what you can refuse, and what they can do

Every claim below links to the law it comes from, with the wording quoted so you can check it yourself.

Lawful to refuse — but it costs you

Not an offence, but it carries a penalty or an inference.

  • Apple's own law enforcement guidelines state that for iOS 8.0 and later, Apple is unable to perform an iOS device data extraction because the data typically sought is encrypted and Apple does not hold the encryption key.

    Apple, "Legal Process Guidelines — Government & Law Enforcement within the United States", published October 2025, Apple
    For all devices running iOS 8.0 and later versions, Apple is unable to perform an iOS device data extraction as the data typically sought by law enforcement is encrypted, and Apple does not possess the encryption key.

    Read it at apple.comquote checked 2026-09-08

  • Apple's own law enforcement guidelines state that content in a customer's iCloud account, as it exists there, may be provided in response to a search warrant issued on probable cause, or the customer's consent.

    Apple, "Legal Process Guidelines — Government & Law Enforcement within the United States", published October 2025, Apple
    iCloud content, as it exists in the customer's account, may be provided in response to a search warrant issued upon a showing of probable cause, or customer consent.

    Read it at apple.comquote checked 2026-09-08

  • With Advanced Data Protection enabled, the number of iCloud data categories using end-to-end encryption rises to 25, including iCloud Backup, Photos and Notes.

    Apple, "iCloud data security overview" (support.apple.com/en-gb/102651), as fetched 2026-09-08
    With Advanced Data Protection, the number of data categories that use end-to-end encryption rises to 25 and includes your iCloud Backup, Photos, Notes and more.

    Read it at support.apple.comquote checked 2026-09-08

  • Apple states it does not hold the encryption keys for Advanced Data Protection categories and cannot help recover that data if the account holder loses access.

    Apple, "iCloud data security overview" (support.apple.com/en-gb/102651), as fetched 2026-09-08
    Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account.

    Read it at support.apple.comquote checked 2026-09-08

  • In the United States, the Supreme Court held in Carpenter v. United States that accessing seven days of historical cell-site location information from a carrier constitutes a Fourth Amendment search.

    Carpenter v. United States, 585 U.S. 296 (2018)
    It is sufficient for our purposes today to hold that accessing seven days of CSLI constitutes a Fourth Amendment search.

    Read it at law.cornell.eduquote checked 2026-09-08

  • US Customs and Border Protection's own directive states that passcodes obtained during a border inspection may not be used to access information that is only stored remotely, rather than on the device itself.

    CBP Directive No. 3340-049B §5.3.2 (eff. 1 Jan 2026)
    Passcodes or other means of access obtained during a border inspection will only be utilized to facilitate the inspection of devices and information subject to border search. Passcodes or other means of access may not be utilized to access information that is only stored remotely.

    Read it at cbp.govquote checked 2026-09-08

What Apple says it can and cannot hand over

Some of what investigators want is never on the phone at all — it sits with the maker or the carrier, in the cloud state described in What a full extraction contains. Apple’s own legal-process guidelines to US law enforcement state: “For all devices running iOS 8.0 and later versions, Apple is unable to perform an iOS device data extraction as the data typically sought by law enforcement is encrypted, and Apple does not possess the encryption key.” That sentence is about the device. Apple’s account-held iCloud content is a separate question, and the same guidelines state: “iCloud content, as it exists in the customer’s account, may be provided in response to a search warrant issued upon a showing of probable cause, or customer consent.”

Advanced Data Protection narrows that again

Where Advanced Data Protection is switched on, Apple states the number of iCloud data categories using end-to-end encryption “rises to 25 and includes your iCloud Backup, Photos, Notes and more,” and that for those categories, “Apple doesn’t have the encryption keys for these categories, and we can’t help you recover this data if you lose access to your account.” So the same account-held content that Apple says it can hand over under a warrant, without Advanced Data Protection, becomes content Apple itself states it cannot decrypt once it is switched on.

Carrier records: a US example

A mobile carrier holds records about a phone independently of anything on the device or in the maker’s cloud — the historical record of which cell towers it connected to. In the United States, the Supreme Court held in Carpenter v. United States that “accessing seven days of CSLI constitutes a Fourth Amendment search,” while stating its decision was “a narrow one” that did not reach real-time location data or tower dumps. That is a US constitutional holding about carrier records, not a technical fact about the phone itself, and it does not extend to the other jurisdictions this site covers.

The US border adds a boundary of its own

US Customs and Border Protection’s own directive draws a line specifically at the border between what is on the device and what is only reachable remotely: “Passcodes or other means of access obtained during a border inspection will only be utilized to facilitate the inspection of devices and information subject to border search. Passcodes or other means of access may not be utilized to access information that is only stored remotely.” See Passcode vs biometrics and Before a border for what else that directive covers.

Last reviewed 2026-09-08. Next review due 2026-12-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.