Encryption keeps banking apps, NHS records and private messages away from prying eyes. Governments argue that the same protection can hide criminal activity from investigators looking into terrorism, fraud and child abuse. That tension sits at the centre of the encryption debate in the UK, and in 2026, it has moved from theory into live regulation with real deadlines and a live court case attached to it.

Ofcom now has legal powers to order messaging platforms to scan content that would otherwise remain encrypted, though it has not yet exercised them. Separately, Apple has already withdrawn a major privacy feature from British customers rather than comply with a different government order, a decision now being tested at a specialist tribunal. Meanwhile, small businesses running any kind of user-to-user service in the UK have discovered they fall within the scope of the same law that targets Meta, Google and TikTok.

This guide sets out where the encryption debate in the UK actually stands right now, rather than where campaigners feared it might end up. It covers what Ofcom can genuinely do under the Online Safety Act, what the Apple case reveals about the limits of so-called “accredited technology,” what smaller UK organisations need to check in their own compliance, and how the picture changes once Northern Ireland’s position within the Windsor Framework is taken into account.

What Is the Encryption Debate in UK Law?

In legal terms, the encryption debate is not really about whether encryption should exist. Nobody in Parliament or at the Home Office has proposed banning it outright. It is about whether the state can require a company to build a workaround for encryption, and under what conditions that would be lawful.

End-to-End Encryption and the “Going Dark” Problem

UK law currently answers that question through two separate pieces of legislation, each with different powers, targets, and oversight, which is the source of much of the public confusion on the topic. Both routes exist because of end-to-end encryption specifically. End-to-end encryption means only the sender and the recipient can read a message, not the platform carrying it, and not the government, even with a valid warrant.

Law enforcement agencies describe the resulting loss of visibility as “going dark,” since communications that would previously have been available to a phone company or email provider through a warrant are now mathematically inaccessible to anyone except the two people talking. The National Crime Agency has repeatedly argued that encrypted messaging complicates investigations into serious organised crime, child sexual exploitation and terrorism planning. Privacy groups counter that the same protection shields journalists, domestic abuse survivors, whistleblowers and ordinary account holders from those very same threats, and that weakening it for one purpose weakens it for every purpose at once.

Why Regulators Focus on Encrypted Messaging Specifically

Regulators focus specifically on messaging, rather than encryption generally, because messaging apps are where most personal communication now happens, and because illegal content such as child sexual exploitation and abuse material can travel through the same encrypted channels used for everyday conversations. The Internet Watch Foundation has documented hundreds of thousands of webpages containing such material each year, much of it shared or distributed through channels that also carry ordinary private messages, which is precisely the overlap that makes this such a difficult policy area to legislate cleanly.

Cloud storage and file-sharing services face similar scrutiny, since encrypted backups can hide the same content as encrypted messages, even though the public debate tends to focus almost entirely on chat apps. That overlap between ordinary private communication and a narrow category of seriously harmful content is what gave Ofcom its statutory footing to act at all, a power examined in detail in the next section.

The Online Safety Act and Ofcom’s Powers

The Online Safety Act 2023 received Royal Assent in October 2023 and made Ofcom the regulator responsible for services letting users interact with each other or with search results. One chapter touches encrypted communication directly, and it draws far more attention than the rest of the Act combined.

Section 121 and the Technology Notice Power

Most of the Act’s duties concern content moderation, illegal content removal and age checks for services accessible to children, and those duties have already come into force across the sector. Section 121 goes further. It lets Ofcom issue a technology notice requiring a regulated provider to use accredited technology to identify child sexual exploitation and abuse content, or terrorism content, including content shared privately between users rather than posted publicly.

This is the provision often nicknamed the “spy clause” during the Bill’s passage through Parliament. Before issuing such a notice, Ofcom must commission a skilled person’s report under section 122 to assess whether the notice is proportionate, and must then give the provider a formal warning notice under section 123, setting out the proposed requirements and a period within which to respond. As it stands, no provider has been served with a live section 121 notice, and no scanning technology has yet been accredited against the minimum standards of accuracy the government is required to set.

Ofcom’s 2026 Implementation Timeline

Ofcom has published its own account of the technology notice process alongside its consultation documents. It consulted throughout 2024 and 2025 on draft guidance for exercising the technology notice power and on proposed minimum standards of accuracy for any accredited technology, and it has confirmed it will publish its final advice to the Secretary of State, alongside its finished guidance for providers, by April 2026.

Only once that guidance and those standards exist can any technology be accredited; until then, a real section 121 notice cannot lawfully be issued. Providers that fail to comply with a notice once one exists face fines of up to £18 million or ten per cent of global annual turnover, whichever is greater, with senior managers personally exposed to criminal liability for information failures in the most serious cases.

The Apple Case and the Limits of “Accredited Technology”

The encryption debate, The Apple Case

While Ofcom’s section 121 power remains theoretical, a separate case has already shown what happens in practice when the government pushes for direct access to encrypted data through a different legal route entirely, one that predates the Online Safety Act by years.

Why Apple Withdrew Advanced Data Protection

In February 2025, the Home Office served Apple with a technical capability notice under the Investigatory Powers Act 2016, reportedly demanding a means to access iCloud data protected by Advanced Data Protection, Apple’s opt-in end-to-end encryption covering backups, photos, and several other data categories. Rather than build that access, Apple withdrew Advanced Data Protection from new UK customers in February 2025 and began removing it from existing users.

Security researcher Professor Alan Woodward told the BBC that the decision left UK Apple customers with weaker data protection than users anywhere else the company operates, describing the outcome as self-defeating for UK cybersecurity rather than a win for law enforcement.

What the Investigatory Powers Tribunal Case Means

Apple challenged the Home Office notice at the Investigatory Powers Tribunal, the specialist court that hears cases involving UK surveillance powers, and the case remains unresolved. Much of the tribunal’s own proceedings are held in closed session because they concern classified national security material, which means the public record of exactly what the Home Office demanded, and exactly what Apple argued in response, remains incomplete even now. The distinction between this case and Ofcom’s powers matters for anyone trying to follow the encryption debate accurately: the Apple order came from the Investigatory Powers Act, a wholly separate statute from the Online Safety Act, aimed at a single named company rather than an entire sector.

Its eventual outcome will shape how far the UK government can compel any technology company to weaken encryption for its global user base, not merely for accounts registered in the UK, which is precisely why the case has drawn international attention from other governments and from US politicians watching how a close ally treats an American technology company’s encryption standards.

Small Business Compliance: What UK Organisations Need to Know

Most coverage of the Online Safety Act understandably focuses on Meta, Google and Apple, since they are the platforms best placed to attract headlines. In practice, the Act applies to any service, whatever its size or revenue, that lets UK users generate content or exchange messages with each other.

Who Does the Online Safety Act Apply To

If a UK-based platform, forum, app or online community allows users to post, comment or exchange messages, it is very likely a regulated service under the Act, regardless of how small its user base is. Ofcom has said that duties are proportionate to a provider’s size and risk profile, so a five-person start-up will not face the same expectations as a global platform, but smaller providers still carry the same underlying illegal content duties as larger platforms, usually without a dedicated legal or compliance team to help them meet those duties.

This catches a wide range of UK businesses that would not describe themselves as social media companies at all, including community forums attached to hobby websites, comment sections on niche publications, and messaging features bolted onto otherwise unrelated apps, all of which now need to treat illegal content duties as a standing obligation rather than an afterthought.

Practical Steps for Smaller Providers

A UK developer running a small messaging feature or community forum should complete an illegal content risk assessment covering their specific service, document the moderation systems already in place, and monitor Ofcom’s published guidance for any sign that their category of service might fall within the scope of a future technology notice. Ofcom’s risk assessment templates are designed to scale down for smaller providers, so completing one does not require the same resources a large platform would need, but skipping the exercise entirely leaves a business unable to demonstrate compliance if Ofcom ever asks.

Reviewing UK cybersecurity law obligations and core data protection duties together, rather than treating them as separate exercises, tends to reveal overlapping requirements around breach reporting and user data handling that a single compliance review can address at once, saving time for a team without a dedicated legal function.

The Northern Ireland Question: UK Law Meets EU Data Rules

The Online Safety Act applies across the whole of the United Kingdom, including Northern Ireland, but Northern Ireland’s continuing position within the Windsor Framework creates a genuine complication that most commentary on the encryption debate overlooks entirely.

Cross-Border Messaging and the Windsor Framework

Northern Ireland businesses that exchange personal data with counterparts in the Republic of Ireland must comply with both UK law and EU data protection rules, since the Republic remains bound by the EU GDPR rather than the UK’s version. A Belfast-based company scanning messages to comply with a future Ofcom technology notice would need to check that the same scanning process does not itself breach EU rules governing personal data flowing to or from an Irish counterpart, an assessment that has no settled precedent yet.

Legal firms and financial services companies operating on both sides of the border are particularly exposed, since client communications often cross the border as a matter of routine business rather than as an occasional exception, and any future scanning requirement would need to apply consistently to conversations that technically sit under two different legal regimes at once.

Diverging From the EU’s Proposed Chat Control Regulation

The European Union has separately proposed a Chat Control regulation that would require scanning of private messages across EU member states to detect child sexual abuse material, though it has not yet been adopted in its current form. If Chat Control is eventually adopted with different technical requirements to the UK’s section 121 regime, cross-border organisations in Northern Ireland could face two incompatible scanning obligations for the same conversation, depending on which side of the border each participant sits, a scenario that has received very little practical attention from either government so far.

What Happens Next in the Encryption Debate

The Encryption Debate, Ofcom, what's next

Nothing about the encryption debate in the UK is settled at present. Ofcom’s own implementation timetable, the pending Apple tribunal case and continuing pressure from messaging providers all point toward further developments before 2026 ends, each capable of shifting the picture in a different direction.

Signal, WhatsApp and the Threat to Leave the UK

Signal and WhatsApp have both indicated they would rather withdraw from the UK market than build scanning capability into their end-to-end encryption, and Signal’s president has previously said the organisation would exit rather than compromise the protocol that underpins its service. Neither has done so, and Ofcom has not yet issued a section 121 notice to either provider, but the credible threat of an exit by major providers continues to shape how cautiously Ofcom is drafting its own guidance ahead of the April 2026 deadline. Losing either service in the UK market would be a visible political cost for any government, giving Ofcom every incentive to proceed carefully rather than test the threat directly.

What UK Users Can Do Now

For the moment, end-to-end encrypted messaging remains entirely legal to use in the UK, and no provider has been forced to weaken it for UK users specifically. Anyone following the direction of the encryption debate can track Ofcom’s published consultations directly, review the privacy settings on the messaging apps they already rely on, and understand what end-to-end encryption actually protects and what it does not before assuming any single app is automatically more private than another.

It is also worth remembering that encryption only protects the content of a message, not the metadata around it, meaning who a person contacts and when remains visible to a provider even when the words themselves are unreadable. Readers who want the wider rights-based case for encryption, rather than the regulatory mechanics covered here, can also see our companion piece on encryption, privacy and security in the UK.

FAQs

The questions below cover the points readers most often ask about the encryption debate and how Ofcom’s powers under the Online Safety Act work in practice, based on the current state of the law rather than on proposals that have not been enacted.

Can Ofcom force WhatsApp or Signal to scan my messages?

Ofcom has the legal power under section 121 of the Online Safety Act to issue a technology notice requiring this, but it has not used that power against any provider to date, and its final guidance on how the power would be applied is not expected before April 2026 at the earliest. Even once that guidance exists, a notice would still need to survive the skilled person’s report and warning notice stages before taking effect.

Is end-to-end encryption illegal in the UK?

No. Using encrypted messaging apps such as Signal, WhatsApp, or iMessage remains entirely lawful for UK residents. The encryption debate concerns whether providers can be compelled to build scanning capability into that encryption, not whether individuals are permitted to use it.

Why did Apple remove Advanced Data Protection from the UK?

Apple withdrew the feature from UK customers in February 2025 after the Home Office issued a technical capability notice under the Investigatory Powers Act, rather than building a means for the government to access encrypted iCloud data. That case is legally separate from Ofcom’s Online Safety Act powers and remains under challenge at the Investigatory Powers Tribunal.

Does the Online Safety Act apply to small UK businesses?

Yes. Any business running a service that lets UK users post content or message each other is very likely within scope, whatever its size or turnover. Duties scale with risk and size, but the core data protection and cybersecurity obligations still apply to the smallest providers just as they do to major platforms.

How does Northern Ireland fit into the encryption debate?

Northern Ireland must follow the Online Safety Act like the rest of the UK, but its data flows with the Republic of Ireland remain separately governed by the EU GDPR under the Windsor Framework, creating a potential conflict if UK and EU scanning requirements for encrypted messages ever move in different directions.