Structural risks
These risks apply to every Apple product. They are legal obligations and corporate
practices that individual products cannot override. A subsidiary cannot opt out of an
FTC consent decree. A company cannot selectively ignore its home country's intelligence
law for one product. These risks set a grade floor of
C — no Apple product
can score better than this, regardless of its own privacy settings.
critical
PRISM participant since 2012
2012-10-01
Apple joined the PRISM programme in October 2012. Despite marketing privacy as a core value, Apple must comply with NSA data collection requests under this programme.
high
Removed Advanced Data Protection in UK
2025-02-21
Apple removed end-to-end encryption (Advanced Data Protection) from iCloud in the UK rather than comply with a government backdoor order under the Investigatory Powers Act. UK users lost access to encrypted backups.
medium
CSAM scanning infrastructure
2021-08-05
Apple built and tested client-side scanning technology for iCloud Photos. Although paused after backlash, the infrastructure exists and could be reactivated by any government mandate.