Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Report details security compromises Apple has made to placate China

Credit: Wang GangCredit: Wang Gang

Last updated

A new investigation reveals some of the compromises that Apple has made in China to gain access to the booming market, including storing data on state-owned servers and censoring apps in the country that run afoul of local regulations.

China is a critical region for Apple, both in terms of product and services sales and because of a deep reliance on the country's supply chain. China, in short, helped Apple become the world's most valuable company.

However, The New York Times highlights all of the ways that the Chinese government has pressured Apple to make compromises that conflict with the Cupertino tech giant's stated values and principals.

Despite Apple's strong stance on protecting user privacy, for example, it stores all of its Chinese user data within the country's borders on servers that belong to a state-owned firm. According to security experts, that means it's essentially impossible for Apple to stop the Chinese government from obtaining access to user data.

Additionally, while U.S. regulations prohibit Apple from handing data over to Chinese authorities, the local storage of Apple data creates a loophole that allows it. A Chinese-based firm, Guizhou-Cloud Big Data (GCBD), is actually the legal owner of Apple iCloud customers in China. Because of that, Chinese authorities can demand access to data from GCBD rather than Apple, and the terms shield Apple from legal reprisal in the U.S., according to a person who helped create the arrangement.

Before that arrangement existed, Apple said it never provided data to the Chinese government. After Apple made GCBD the owner of the data, it says that it has provided iCloud contents for an undisclosed number of accounts in nine separate cases.

Apple pushed to keep encryption keys out of the country as part of the original agreement that saw Chinese data stored locally. Less than a year after striking the deal, however, Apple moved the digital keys out of the U.S. and into China, making it easier for Chinese government agencies to obtain user texts, emails and other information.

The company in a statement said it still controls the keys and uses advanced encryption technology — more advanced than solutions used in other countries — to keep them safe.

The compromises also exist on the App Store. According to The New York Times, Apple has an internal team that either rejects app submissions or pulls down apps that it believes could violate Chinese regulations.

Apple uses specialized tools and trains its reviewers to detect topics deemed off-limits in China. That includes mentions of the independence of Tibet or Taiwan, the Tiananmen Square incident, or the Dalai Lama.

Since 2017, about 55,000 apps have disappeared from the App Store in China, according to data provided by Sensor Tower. Some of those apps include foreign news outlets, encrypted messaging apps, and gay dating services, as well as platforms like VPNs that allow users to bypass internet restrictions.

For its part, Apple said it approved 91% of takedown requests, or 1,217 apps, from the Chinese government in a two-year period ending in June 2020. Apple's statistics might not tell the whole story, as its review apparatus could remove apps before they catch the eye of government officials.

In a statement to The New York Times, Apple said it follows laws in China and does everything that it can to protect the security and privacy of its customers' data in the country.

"We have never compromised the security of our users or their data in China or anywhere we operate," Apple said.

It also noted that it only removed apps to comply with Chinese regulations. "These decisions are not always easy, and we may not agree with the laws that shape them, but our priority remains creating the best user experience without violating the rules we are obligated to follow," the company added.

Stay on top of all Apple news right from your HomePod. Say, "Hey, Siri, play AppleInsider," and you'll get latest AppleInsider Podcast. Or ask your HomePod mini for "AppleInsider Daily" instead and you'll hear a fast update direct from our news team. And, if you're interested in Apple-centric home automation, say "Hey, Siri, play HomeKit Insider," and you'll be listening to our newest specialized podcast in moments.



13 Comments

theotherphil 51 comments · 10 Years

I’m not sure why this is even a story. Every company has to follow the local laws of the country it is operating in. This doesn’t stop Apple providing the very best privacy and security that those local laws allow.

FileMakerFeller 1561 comments · 6 Years

I'm reminded of Joel Spolsky's witticism: they're not being asked to walk a fine line, it's a line of negative width.

22july2013 3736 comments · 11 Years

I’m not sure why this is even a story. Every company has to follow the local laws of the country it is operating in. This doesn’t stop Apple providing the very best privacy and security that those local laws allow.

It's not an important story to people who are American, but it is an important story to people who are Chinese or who are concerned about human rights worldwide. I'm concerned about the latter, and I'm sad that Apple hasn't explained its policies for differences in its privacy controls worldwide. It feels like Apple is covering up for China, or for itself, to avoid bad press. I wish Apple would be open about its privacy policies worldwide. Here's what Apple says about Privacy:

https://www.apple.com/privacy/
Privacy is a fundamental human right. At Apple, it’s also one of our core values. 

How can Privacy be a core value if it's ignored in China? I notice there's no footnote on www.apple.com/privacy/ which says this core value is inapplicable in China.

gatorguy 24627 comments · 13 Years

I’m not sure why this is even a story. Every company has to follow the local laws of the country it is operating in. This doesn’t stop Apple providing the very best privacy and security that those local laws allow.

It's a story only because there is no requirement that Apple do business in China if they find the requirements too onerous. Yes Apple is a for-profit, and on balance the money to be made from business there outweighs any compromise of their stated "core values". Profit is profit is profit, no apologies needed.  

If they took major issue with the privacy of Chinese citizens or thought it important enough to make a statement, take a stand, they would. That's not generally what American corporations do, nor what stockholders expect. China won't change just because Apple doesn't like it. They're big but not THAT big. 

radarthekat 3904 comments · 12 Years

gatorguy said:
I’m not sure why this is even a story. Every company has to follow the local laws of the country it is operating in. This doesn’t stop Apple providing the very best privacy and security that those local laws allow.
It's a story only because there is no requirement that Apple do business in China if they find the requirements too onerous. Yes Apple is a for-profit, and on balance the money to be made from business there outweighs any compromise of their stated "core values". Profit is profit is profit, no apologies needed.  

If they took major issue with the privacy of Chinese citizens or thought it important enough to make a statement, take a stand, they would. That's not generally what American corporations do, nor what stockholders expect. China won't change just because Apple doesn't like it. They're big but not THAT big. 

That’s a very jaded and simplistic view of the matter and I suspect you know that.  By pulling out of China based on principal Apple would be ceding critical ground to Chinese technology companies and other technology companies that do business there.  This would strengthen those companies immensely.  Only they would have access to Chinese-made components, China’s manufacturing and assembly factories and workforce and the immense Chinese market.  Apple would be greatly harmed and would diminish as an American competitor to the SE Asian technology juggernauts.  Would this serve America?  


Bigger question: would this serve or further harm privacy for not just Chinese citizens but citizens globally who buy the 85% Android market share smartphones that would be far more subject to Chinese hegemony?  I think the answer is clear.  Apple’s philosophy is to engage and try to create change rather than walk away and give up any opportunity to be a positive influence. By remaining a strong competitor in all markets Apple stays relevant in markets outside China where’s there’s still plenty of battle space to make progress.