Advanced Data Protection (ADP) is an option to enable end-to-end encryption (E2EE) for iCloud-stored data from your Mac, iPhone, or iPad. ADP covers nearly all the data for which Apple previously lacked an E2EE option. (See how to share files with end-to-end encryption for a full definition.)
You can see a full list of the items that are encrypted at rest (on servers using keys Apple possesses) and those with E2EE enabled in iCloud on Apple’s website, both with and without ADP enabled. Without ADP, these items remain encrypted at rest only: iCloud backups, Freeform (Apple’s collaborative drawing tool), iCloud Drive, Apple Invites, Messages in iCloud, Notes, Photos, Reminders, Safari bookmarks, Siri Shortcuts, Voice Memos, and Wallet passes. Enabling ADP adds E2EE to all of them. (Apple Invites has exceptions; see note on the page linked just above.)
Email, contacts, and calendar entries can only be encrypted at rest due to interoperability with third-party services and apps.
I recommend enabling ADP if you qualify, as it provides a strong additional layer of protection for private data that you might consider “local” if you never access it via iCloud.com.
What ADP requires
ADP requires two-factor authentication on your Apple Account, which most accounts already have enabled due to Apple’s nearly mandatory policy. You also have to have passcodes on all of your devices—also, nearly universal. One requirement not everyone will have met: iCloud Data Recovery has to be turned on with at least one active contact or an Apple Account Recovery Key.
All your devices must meet minimum system requirements, which nearly every current device exceeds: macOS 13.1 Ventura, iOS 16.2, iPadOS 16.2, tvOS 16.2, watchOS 9.2, and—yes—HomePod 16.2. If you have any associated Windows computers, they must have iCloud for Windows 14.1 or later installed.
Apple says managed Apple Accounts and accounts set up for children cannot enable ADP.
An Apple Account Recovery Key is entirely unrelated to the FileVault Recovery Key. See where to find your FileVault Recovery Key.
Siri AI, Private Cloud Compute and conversations
Apple introduced Siri AI with iOS 27, iPadOS 27 and macOS 27, a more full-featured chatbot version of Siri on devices that support Apple Intelligence. Conversations with Siri are stored in the new Siri app and synced via iCloud. However, these are end-to-end encrypted sync operations, such as what’s used with Messages and iCloud Passwords. You don’t need to enable ADP, as described next.
To provide these enhanced services, Apple may send portions of your queries to what they call Private Cloud Compute. Private Cloud Compute consists of both servers they own and operate and servers in Google Cloud that Apple controls every component of, even though it’s not Apple hardware or in an Apple data center. You can’t prevent these requests from leaving your hardware, but Apple says all queries are encrypted end to end, untraceable back to you, impenetrable to Apple and any partners (even when debugging servers or code), and so forth. This is covered further in what Apple Intelligence, Siri AI and Visual Intelligence actually are.
Turn on ADP
Start by going to the ADP setting section: System Settings (Mac)/Settings (iPhone/iPad) > Account Name > iCloud > Advanced Data Protection. Tap Turn On Advanced Data Protection or click Turn On.
Apple now lets you turn on ADP:
- Apple warns you that “you will be responsible for your data recovery.” You have to click or tap the Review Recovery Methods option or Set Up next to an Account Recovery button.
- If you have Recovery Contacts, they’re shown. Click or tap Contacts Up to Date if they are or select Update Recovery Contacts if they are not to revise. Then return to step 1.
- If you have a Recovery Key, you must enter it and click or tap Next.
- With your recovery methods approved, enter your macOS account password or device passcode when prompted.
- Finally, you’re told, “Advanced Data Protection is On.” Click Done.
You should also receive an email to your iCloud.com address that tells you ADP was enabled.
If your devices aren’t all running the minimum supported operating system versions, you’ll be told which ones require an update. You can choose to upgrade all devices or remove one or more outdated devices from your account. Go to Settings/System Settings > Account Name, select a device, click or tap Remove from Account, and follow the prompts.
Reach your data on iCloud.com
With ADP enabled, all your data except email, contacts, and calendar entries is encrypted by keys held on your devices. That would appear to count iCloud.com access out. But Apple has a workaround. They allow temporary access using in-browser encryption.
First, you have to let yourself view the data on iCloud.com: go to Settings/System Settings > Account Name > iCloud. On an iPhone or iPad, tap iCloud.com and then Allow Data Access; on a Mac, click Data Access on iCloud.com and enable Allow Data Access. Confirm your choice; in fact, you have to confirm twice.
You can disable non-ADP access via iCloud.com using that setting, too.
With that enabled, here’s how to unlock temporary access:
- Visit icloud.com in a browser and log in.
- Apple shows a banner that explains that ADP is on and how to proceed.
- Select an app, such as Photos.
- Apple sends an access request to trusted devices. (If you don’t see the prompt, you can click or tap Request New Access.)
- On a trusted device, click or tap Allow Access.
- On your trusted devices, a banner appears alerting you that you’ve enabled temporary access.
Data remains accessible for an hour from each request. Each additional data type you want to access may require another permission request and approval unless requested shortly after a previous request.
Data previously unavailable on iCloud, such as Passwords entries and Health data, remains locked on devices.
The Find My exceptions
Until mid-2021, Apple listed Find My (Devices and People) as protected by their keys. When the company started to break out “in transit & on server” and E2EE, it dropped Find My from the iCloud page. Apple then stopped documenting the relationship of Find My with iCloud. That leaves it to me to try to explain.
The Find My Device web app is available at iCloud.com when you log in with two-factor authentication or a passkey. Even if ADP is enabled, you’re not asked to start a secure, device-approved session. Apple uses secure transit and their own keys to pass your location from your devices and those of people in your Family Sharing group who have shared location with you to your iCloud account. There’s no other way for that information to appear.
Apple doesn’t pass information about other people’s location, nor do they provide AirTag and other Find My item positioning, and thus I assume there is device-based E2EE involved in sharing that information among your hardware that Apple doesn’t want to override.
Turn ADP off
Disabling ADP is straightforward. Go to Settings/System Settings > Account Name > iCloud > Advanced Data Protection. Tap Turn Off Advanced Data Protection or click Turn Off. Follow the prompts to confirm you understand you’re removing E2EE protection from many of your synced and stored data.

