In law enforcement use a “consent extraction” means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key. Since iOS 26.4 it does not. Stolen Device Protection is on by default, and away from familiar locations it requires Face ID or Touch ID before the “Trust This Computer” prompt. The passcode still unlocks the device and confirms Trust. SDP adds a second requirement on top. An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.
This article maps technical requirements against legal ones. The subject is not linear: the same iPhone, passcode and authority produce different outcomes depending on build, location, clock and jurisdiction.
In practice, the same English word can mean four different situations.
The label travels with the evidence. If your report says consent and the defence shows it was one of the other three, you have created an argument the method never required. Record the mechanism, not the shorthand: the notice, the order number, the warrant clause, what the person was told and when. In United States v. Brown, 125 F.4th 1186 D.C. Cir. 2025, ambiguity about what the agent said to the suspect did real work in the outcome.
So, three different terms instead: consent extraction, compelled-credential extraction, compelled-biometric extraction.
Multiple factors can affect this.
| Credential | What it does | Limitations |
|---|---|---|
| Passcode | Unlocks the device. Confirms the Trust prompt. Required for Developer Mode on iOS 16 and later, with confirmation after restart. Required after every reboot. | With SDP active away from a familiar location, the passcode alone is no longer sufficient. |
| Face ID or Touch ID | With SDP on and the device away from a familiar location, satisfies the extra check before the Trust prompt and other actions. | Supplements the passcode requirement; the passcode remains required. |
| Existing pairing record | Lets you connect without a new Trust handshake, so the SDP pairing check never fires. | Leaves the device locked; USB Restricted Mode still requires an unlock. Ends on reboot and expires 30 days after last use on iOS 11 and later. |
A quick note: reports that iOS 18.2 allows the “Trust This Computer” prompt to be confirmed with Face ID instead of the passcode trace to a single beta observation posted 5 November 2024. No Apple documentation confirms it. Testing shows the passcode is still required to establish pairing.
For the purpose of data extraction (that is, pairing to a new workstation), SDP adds a credential. The passcode fires everywhere, at home and away, with SDP on or off. The biometric fires only away from familiar locations and only when SDP is on. Familiar locations are Significant Locations the phone has learned, in practice home and work. SDP adds a second credential; it does not move the first.
Compelled-decryption statutes were drafted for one credential, the passcode.
RIPA s.49 reaches a “key.” France’s art. 434-15-2 reaches a convention secrète de déchiffrement, a secret decryption convention. Singapore’s CPC s.40 reaches decryption information. These are knowledge words written for the era when knowing the code was the whole problem. The UK backs s.49 with up to two years under s.53, five where national security or indecent images are involved. France provides three years and a €270,000 fine, and the Court of Cassation settled in November 2022 that a phone PIN qualifies where the device is encrypted, which is every modern phone.
None of that covers a face. The jurisdictions that criminalised digital silence built a lever for exactly the credential SDP has made insufficient alone.
One exception: Australia’s s.3LA of the Crimes Act, inserted by the Cybercrime Act 2001, allows a magistrate to order a specified person to provide passwords, PINs, or biometric access, with a maximum of ten years for refusal in serious federal matters. Australia legislated for the two-credential world twenty-five years early. Hong Kong is the other route: Article 43 Implementation Rules as amended by L.N. 27 of 2026, in force 23 March 2026, empower officers to require “decryption assistance” from a specified person, read as covering biometric unlocking along with passwords and keys. Refusal carries a year and HK$100,000, with a heavier penalty for a wrong password. Authorisation comes from a senior officer rather than a court.
Germany and the Netherlands cannot compel a passcode from a suspect. Germany’s StPO protects the right to silence in the digital realm, reinforced by the Federal Constitutional Court’s 2008 recognition of a fundamental right to confidentiality and integrity of IT systems. Dutch art. 125k allows a decryption order but excludes the suspect. Both nevertheless permit forced biometric unlock. The Hoge Raad held on 9 February 2021 that handcuffing a suspect and pressing his thumb to the sensor does not breach privilege, reasoning from Saunders and Jalloh that a fingerprint exists independently of the suspect’s will. The Bundesgerichtshof reached the same result on 13 March 2025 in 2 StR 232/24, relying on §81b StPO and describing the body as a natural key, subject to a court order covering the phone search and a proportionality assessment.
SDP adds, in Germany and the Netherlands, a factor those states can obtain, on top of a factor they never could. It changes nothing for them. It is a problem only for jurisdictions that could already compel a passcode.
The doctrinal line is not passcode versus biometric. It is whether the state orders the suspect to act or acts on the suspect’s body.
The American split is quite narrow. In United States v. Payne, 99 F.4th 495 9th Cir. 2024, officers took a parolee’s thumb and used it. The Ninth Circuit held the act non-testimonial: no cognitive exertion, like a blood draw. In Brown, the D.C. Circuit held a compelled thumbprint unlock testimonial and suppressed the results. The D.C. Circuit noted that in Payne police did not instruct the man to open his phone. In Brown an agent told him to, and compliance with the instruction was the testimonial act.
The implication is uncomfortable: under this reading American police are on safer ground applying more physical force, not less.
The same distinction appears in three other systems.
Four jurisdictions lead to a single conclusion: the state may act on one’s body, but may not order one to act.
Touch ID is manipulation. You take the hand, press the finger, and it works whether or not the owner cooperates. Face ID is different. With Require Attention on, the default, Face ID needs open eyes directed at the device. A suspect who shuts their eyes cannot be overcome by force; they can only be told to open them, and being told to open them is the mode Brown found testimonial. On a Face ID iPhone with SDP active and an uncooperative owner, the second credential may be legally unavailable in some jurisdictions and physically unavailable in all of them.
“No authority found” means my Google skills were not enough to find a decided case or express power. It does not point either way – just means I didn’t find a definite source.
| Jurisdiction | Passcode | Biometric by order | Biometric by force |
|---|---|---|---|
| United Kingdom | Yes, RIPA s.49 notice | Arguable under the s.56 definition of “key”; untested | No authority found; no express power |
| France | Yes, art. 434-15-2 | Untested | Art. 55-1 CPP covers identification prints, not unlocking; untested. See CJEU C-371/24, 19 March 2026 |
| Australia | Yes, s.3LA | Yes, named in the provision | Not addressed |
| New Zealand | Yes, SSA s.130; separate border regime under Customs and Excise Act 2018 | Probably within s.130 assistance | Not addressed |
| Singapore | Yes, CPC ss.39 and 40; CMA s.39A | Probably within “assistance”; practice is to ask for the PIN | No authority found |
| Hong Kong | Yes, L.N. 27/2026 | Yes, as reported | Not addressed |
| Belgium | Yes, art. 88quater §1 | No, §2 excludes the suspect | Likely permitted on §2 reasoning; untested |
| Germany | No | No | Yes, BGH 2 StR 232/24 |
| Netherlands | No, art. 125k excludes the suspect | No | Yes, HR 9 February 2021 |
| Canada | No, R. v. Shergill 2019 ONCJ 54 | No, OCJ 16 March 2026 | Not addressed; the same reasoning points that way |
| United States | Contested; foregone conclusion doctrine, circuit by circuit | Contested; Brown | Contested; Payne |
| India | Split; Karnataka and Kerala for, Delhi CBI Special Court against | Same split, same reasoning | Kathi Kalu Oghad 1961 supports it; untested for phones |
A note on Canada. Justice Trevor Brown of the Ontario Court of Justice refused a general warrant on 16 March 2026 that would have compelled a target to unlock devices by fingerprint or facial recognition, holding the biometric scan would violate the right to silence and protection against self-incrimination. It is trial-level authority. Bill C-370, which would create judicially authorised unlock orders with a ten-year maximum, is separately in play.
India treats passcode and biometric as one question, on the strength of Kathi Kalu Oghad 1961, which held physical specimens are not testimonial because they do not by themselves incriminate. Everyone else splits them; India mostly does not.
SDP relaxes at familiar locations. That creates an overlap: the place where SDP stands down is generally where you execute a search warrant.
Taking the phone back to the suspect’s kitchen table converts a two-credential problem into a one-credential problem. In the UK, France or Singapore that is the difference between a credential the state can lawfully compel and one for which it may have no mechanism. On-scene extraction at the residence becomes a matter of which law applies.
So, the geography caveats are:
Timing matters a lot; without a known passcode, nothing can be taken for granted.
In every jurisdiction that requires judicial authorisation before a biometric can be taken, authorisation routinely arrives after the credential has expired. That access constraint exists because two systems were designed without reference to each other.
Real consent is limited in a way an order is not.
Someone who agrees to let you look at WhatsApp has not agreed to a full file system image containing the keychain, deleted records, location history, health data and every credential the device has stored. Most true consent cases are victims and witnesses, and a full extraction routinely takes far more than was asked for. Consent can be withdrawn, raising a question about an image already on your storage that most labs have no written answer to.
SDP sharpens this. Where the second credential cannot be compelled, cooperation becomes the only reliable route, and cooperation arrives with limits. The examiner ends up depending on the one form of authority that is scope-bound while using methods that respect scope least.
Record the agreed scope in the person’s own words before extraction, not after. Where the case allows, choose the method that matches the request; an advanced logical extraction that answers the question is better than a full file system image that answers it and forty others.
From iOS 26.4 onward, assume SDP is on until checked. Apple enables it on new setups, restores and updates from 26.4, and 26.4.1 extended it to enterprise and MDM-managed devices on 8 April 2026.
Pairing-free sideloading of the extraction agent shipped in iOS Forensic Toolkit 10.10. The agent installs over a developer-signed distribution path and communicates over a local network link, so no step depends on the USB pairing SDP guards. More on that: Bypassing Stolen Device Protection: Alternative Ways of Installing the Extraction Agent and Sideloading the extraction agent: a Stolen Device Protection workaround.
That removes the biometric requirement. It leaves untouched the passcode requirement, a paid Apple Developer account, physical handling of an unlocked device, and a device not locked down by MDM. It returns the case to a single credential and restores the match between what a s.49 notice or s.3LA order can compel and what the device asks for.
That is a narrow claim. It helps in jurisdictions that can compel a passcode. It does nothing for Germany, the Netherlands or Canada, because the credential they cannot obtain is the one still required. No tool changes that.
It also does not help the person SDP was built to stop. That threat model is specific: someone who watched you type your passcode in a bar, took the phone, and used those two facts to reset your Apple Account. A pickpocket does not enrol in the Apple Developer Program.
SDP was designed against a thief in a bar, and it works against him. Its effect on lawful extraction is a side effect, and a lopsided one. Where the law lets the state compel a memorised code, SDP now asks for something the statute was never written to reach. Where the law protects the code absolutely, SDP asks for the one thing the state was already allowed to take, and changes nothing.
Two consequences follow. First, a device policy written in Cupertino now determines which national laws are effective, and the drafters did not consider that question. Second, the safest route to a biometric in USA, the country with the most developed case law, is to take it by force rather than ask for it. That is where the reasoning has led, and it is worth noticing before it becomes routine.
Finally, everything above is subject to change. Apple revises SDP without announcements, support pages have been edited more than once, and three legal positions changed between this article and the previous ones I wrote on compelled decryption.