Apple’s iCloud data security overview names 15 data categories as end-to-end encrypted by default, rising to 25 once Advanced Data Protection is turned on. Apple’s own platform security guide, describing the same feature, states 14 and 23. The two Apple pages do not agree on the count, though both list the same kind of exceptions and the same reasons for them.
Available since iOS 16.2, iPadOS 16.2 and macOS 13.1, Advanced Data Protection is a setting Apple describes as extending end-to-end encryption, meaning Apple states it holds no key and cannot access the protected data, to most of iCloud. What follows is the named, itemized table from Apple’s iCloud data security overview, which is the more detailed of the two documents.
Key facts, as Apple documents them
| Item | What Apple publishes |
|---|---|
| Available since | iOS 16.2, iPadOS 16.2, macOS 13.1 |
| Categories always end-to-end encrypted (iCloud data security overview) | 15 |
| Categories end-to-end encrypted with Advanced Data Protection on (same page) | 25 |
| Same two figures, per Apple’s separate platform security guide | 14 and 23 |
| Named permanent exceptions | iCloud Mail, Contacts, Calendars |
| Where it is turned on | Settings, tap the Apple ID banner, then iCloud, then Advanced Data Protection |
The 15 categories Apple lists as always end-to-end encrypted
Apple’s iCloud data security overview lists these as end-to-end encrypted whether or not Advanced Data Protection is turned on: Passwords and Keychain, Health data, Journal data, Home data, Messages in iCloud, Payment information, Apple Card transactions, Maps, QuickType Keyboard learned vocabulary, Safari, Screen Time, Siri information, Wi-Fi passwords, W1 and H1 Bluetooth keys, and Memoji.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
What Advanced Data Protection adds
With standard data protection, Apple’s table shows the following categories encrypted with keys Apple itself holds in its data centers. Turning on Advanced Data Protection moves them to end-to-end encryption instead: iCloud Backup, including device and Messages backups, iCloud Drive, Photos, Notes, Reminders, Safari Bookmarks, Shortcuts, Voice Memos, Wallet passes, and Freeform. Apple lists Apple Invites separately, with a specific note: an unpublished invitation is end-to-end encrypted under Advanced Data Protection, but once published, most of its data reverts to standard protection unless the host and every participant have Advanced Data Protection turned on, and some elements, including the time, date, city-level location and any shared poster image, stay under standard protection regardless.
The three categories that never get end-to-end encryption
| Category | Apple’s stated reason |
|---|---|
| iCloud Mail | Needs to interoperate with the global email system; Apple notes its native mail clients support optional S/MIME encryption instead |
| Contacts | Built on CardDAV, an industry standard with no built-in support for end-to-end encryption |
| Calendars | Built on CalDAV, the same limitation as Contacts |
Freeform carries its own separate caveat beyond that list: when a board is shared using Send a Copy, Apple states it is stored in an unencrypted state for as long as the sharing link stays active, regardless of the account’s encryption setting, so that anyone holding the link can open it.
Where this applies on current hardware
Advanced Data Protection is an Apple ID setting rather than a device feature, so it applies the same way across an iPhone, iPad and Mac signed into one account, including the iPhone 18 Pro and any device updated to iOS 27 after Monday, September 14. It will also cover the iPhone Duo once that device ships in October, since Advanced Data Protection is tied to the Apple ID rather than to any one iPhone. Apple requires at least one recovery contact or a personal recovery key before the setting turns on, since it states it cannot help recover the protected data without one.
What Apple has not said
Apple has not published why its iCloud data security overview and its platform security guide state different totals for the same feature, or which figure is current. It has also not published a single combined table naming all 25 categories in one place; the number is stated directly, while the itemized list has to be assembled from the always-encrypted table and the Advanced Data Protection table read together.
As of Saturday, September 12, 2026, the setting itself, and the itemized table behind these figures, can be checked directly at Apple’s iCloud data security overview, and turned on from Settings, the Apple ID banner, iCloud, then Advanced Data Protection.
