Is iCloud Drive private enough for sensitive files?
· 6 min read
Is iCloud Drive encrypted? Yes: your files are encrypted in transit and on Apple’s servers. Under the default setting, Standard Data Protection, Apple holds the keys, so it can decrypt your files to help you recover your account or when legally required to. Turn on Advanced Data Protection and iCloud Drive becomes end-to-end encrypted, with the keys only on your own devices. For a few genuinely sensitive documents, encrypting them yourself before they reach iCloud adds protection that does not depend on any account setting.
Is iCloud Drive encrypted, and who holds the keys
Everything in iCloud is encrypted. The question that matters is who can decrypt it, and Apple offers two answers.
Standard Data Protection is what every account has unless you change it. iCloud Drive, Photos, Notes, device backups and most other data are encrypted, but the keys are stored in Apple’s data centers. That is what lets Apple restore your data after you forget your password, and it also means Apple could be compelled to hand data over. A smaller set of data is end-to-end encrypted even at this level, including passwords in iCloud Keychain and Health data.
Advanced Data Protection moves the keys for most categories, iCloud Drive included, onto your trusted devices only. Apple can no longer read that data, and it can no longer rescue it for you either.
For most people, though, the realistic risk is neither Apple nor a court order. It is someone getting into the Apple Account itself, through a phished password or a reused one. Under standard protection, anyone who signs in to iCloud.com as you can browse your iCloud Drive. Two-factor authentication on an Apple Account, done properly is the first fix, whatever else you decide.
What Advanced Data Protection changes, and what it leaves out
With Advanced Data Protection on, end-to-end encryption extends to iCloud Drive, iCloud Backup (the backups of your iPhone and iPad), Photos, Notes, Reminders, Safari bookmarks, Siri Shortcuts, Voice Memos and Wallet passes, on top of what was already covered.
It also changes how the web works. Access to your data on iCloud.com is off by default; if you turn it on, each web session has to be approved from one of your devices, and that session is briefly given access to the keys it needs.
Some things stay under standard protection even then. Apple lists these, and they are worth checking on its support page because the details can change:
- iCloud Mail, Contacts and Calendars, because they have to work with standard email, contacts and calendar systems.
- Some metadata, such as the dates files were modified and checksums of file data, which Apple uses to sort and de-duplicate storage.
- Anything shared the open way. Sharing with “anyone with the link”, iWork collaboration and Shared Albums in Photos do not use Advanced Data Protection.
That last point catches people out. Turning on the strongest setting and then sharing a folder of scans by public link puts those files back under Apple-held keys.
What Advanced Data Protection requires, and how to turn it on
Apple has built in a few requirements, because with this setting on there is no one to call if you lose access.
- Two-factor authentication on your Apple Account, and a passcode or password on your devices.
- Up-to-date devices. Every device signed in to the account needs a version that supports it: macOS 13.1, iOS 16.2, iPadOS 16.2, watchOS 9.2 or later. Older devices have to be updated or removed from the account.
- A recovery method that is not Apple. Either a recovery contact (someone you trust with an Apple device, who can give you a code but cannot see your data), or a recovery key (a 28-character code you store yourself), or both.
It is not available on every account: Managed Apple Accounts from work or school and child accounts cannot use it. Availability also depends on region; Apple stopped offering it to new users in the UK in 2025, so check Apple’s support page for where you live.
To turn it on in macOS 15 Sequoia, open System Settings, click your name at the top of the sidebar, click iCloud, and scroll to Advanced Data Protection. Click Turn On and follow the steps; it walks you through the recovery contact or key before it lets you finish. On macOS 13 Ventura and 14 Sonoma the steps are the same; the pane under your name is labeled Apple ID rather than Apple Account.
Then store the recovery key properly. If you lose every trusted device, forget their passcodes and lose the recovery key and contact, your data is gone for good. That is the trade.
Encrypt sensitive files before they sync
Advanced Data Protection protects the copy on Apple’s servers. It does nothing for the copy on every device signed in to your account: the family iPad left unlocked, the Mac someone borrows while you are logged in. On standard protection, even the server copy can be decrypted with Apple-held keys. Encrypting the file yourself covers every copy, whichever setting you use.
First, decide whether a file needs to be in iCloud at all. A passport scan or last year’s tax return is rarely needed on a phone. If Desktop & Documents syncing is on, everything you save to those folders goes to iCloud Drive without you choosing it; the switch is in the iCloud Drive options under System Settings, your name, iCloud. Save new documents to your Mac instead of iCloud by default covers keeping a folder local.
If it does need to sync, encrypt it before it goes. An encrypted disk image made in Disk Utility (File, New Image, Image from Folder, with 256-bit AES) syncs as one encrypted file, and Apple only ever stores ciphertext, whatever your iCloud setting. Two cautions: open it on one Mac at a time, because sync cannot merge two edited copies of a disk image, and remember that an iPhone or iPad cannot open a disk image. For a document you need on your phone, a password-protected PDF travels better; password protect a PDF on a Mac shows how.
For files that stay on the Mac, Hushbox locks a file or folder in place from the Finder right-click menu, as an AES-256 encrypted disk image that opens with Touch ID or its password. Lock things before they ever reach a synced folder rather than after: copies made before locking are not changed, and that includes a plain version already sitting in iCloud’s Recently Deleted. The item’s name also stays visible.
Whatever you encrypt, the order matters. If the plain file has already synced, deleting it sends it to Recently Deleted on iCloud.com for about 30 days; remove it from there too.
Questions
Can Apple see my iCloud Drive files? Under Standard Data Protection, Apple holds the keys and could technically decrypt them. With Advanced Data Protection on, iCloud Drive is end-to-end encrypted and Apple cannot read it.
Is iCloud Drive end-to-end encrypted by default? No. Only with Advanced Data Protection turned on. Passwords in iCloud Keychain and Health data are end-to-end encrypted by default, but iCloud Drive is not.
What happens if I lose my recovery key with Advanced Data Protection? If you still have a trusted device and its passcode, or a recovery contact, you can get back in and create a new key. If you lose all of them, Apple cannot recover your data.
Can I turn Advanced Data Protection off later? Yes, in the same place in iCloud settings. Your devices hand the keys back to Apple’s servers and the account returns to standard protection.