Apple is facing a £2 billion lawsuit in the United Kingdom over App Tracking Transparency, the privacy framework that dramatically changed how iPhone and iPad apps can track users for advertising.
The proposed collective action, filed September 3, 2026, at the UK Competition Appeal Tribunal, accuses Apple of using privacy rules to place third-party app developers at a competitive disadvantage while subjecting its own services to different standards.
The case does not argue that Apple should eliminate tracking controls or give developers unrestricted access to user data. Instead, the central allegation is that Apple designed and implemented its privacy system in a way that imposed tougher consent requirements on competitors than it imposed on itself.
That distinction is becoming increasingly important as privacy regulation, competition law and digital advertising converge. Regulators are no longer examining only whether companies obtain consent. They are also looking at who controls the consent mechanism, how choices are presented, whether similar processing receives similar treatment and whether privacy controls can be used to favor one participant in a digital ecosystem over another.
The Claim Against Apple
The action is being brought by ATT Collective Action Limited on behalf of thousands of UK app developers. Its director, Ann Pope, spent a decade as a senior antitrust official at Britain’s Competition and Markets Authority before leaving the regulator in 2024.
The claim alleges that Apple used its position as the operator of iOS and the App Store to impose App Tracking Transparency requirements that restricted third-party developers’ ability to collect and use data for advertising.
According to the claimants, the problem was not simply that developers had to ask users for permission. They argue that Apple subjected third-party apps to a consent framework that did not operate in an equivalent way for Apple’s own advertising and data practices.
That allegedly created an advantage for Apple’s advertising ecosystem while reducing the ability of independent developers to monetize their applications through personalized advertising.
The claim seeks approximately £2 billion in damages for losses allegedly suffered by UK developers.
Because the case has been filed as a proposed collective action before the Competition Appeal Tribunal, significant procedural questions remain before damages could ever be awarded. The allegations will need to survive the tribunal process, and Apple has made clear that it disputes the underlying theory of the case.
What Is App Tracking Transparency?
Apple introduced App Tracking Transparency, commonly known as ATT, with iOS 14.5 in April 2021.
The framework generally requires an app to obtain permission before tracking a user across apps and websites owned by other companies. ATT also controls access to Apple’s Identifier for Advertisers, or IDFA, which historically played an important role in mobile advertising, attribution and audience measurement.
For users, ATT turned a technical advertising issue into a highly visible privacy choice. Rather than allowing tracking to occur in the background, participating apps have to present an Apple-controlled permission request before engaging in conduct that falls within Apple’s definition of tracking.
The change had an immediate effect on the mobile advertising ecosystem. Developers and advertising companies that relied on cross-app behavioral data had to redesign attribution systems, targeting models and monetization strategies.
Apple has consistently defended ATT as a privacy feature intended to give users meaningful control over whether their activity is tracked across companies.
In responding to the UK allegations, Apple has maintained that it is subject to the same ATT requirements as other developers and that the framework gives users a straightforward mechanism for controlling tracking.
The Lawsuit Focuses on Alleged Self-Preferencing
The legal dispute gets more complicated when the distinction between first-party and third-party data enters the picture.
ATT primarily regulates tracking across companies. Apple, however, operates a large integrated ecosystem that includes the App Store, Apple ID, Apple devices and numerous first-party services.
Critics have argued that Apple can combine certain information within that ecosystem without triggering the same ATT process imposed when a third-party developer wants to track activity across unrelated companies.
This has led competition authorities to examine whether Apple created a privacy architecture that protects consumers while simultaneously giving Apple a structural advantage over companies that depend more heavily on third-party advertising data.
That question sits at the center of the UK case.
Ann Pope has argued that consumer privacy can be protected without allowing a platform operator to impose materially different rules on businesses that depend on its ecosystem.
France Already Fined Apple €150 Million Over ATT
The UK lawsuit does not arrive in isolation.
In March 2025, France’s Autorité de la concurrence fined Apple €150 million after finding that the implementation of App Tracking Transparency constituted an abuse of Apple’s dominant position in mobile application distribution on iOS and iPadOS.
Importantly, the French authority did not conclude that ATT’s underlying privacy objective was illegitimate.
Instead, it found problems with the way Apple implemented the framework.
The French regulator said the system created excessive complexity for users of third-party applications, including multiple consent dialogs, and found that the interaction between those requests could disadvantage application publishers and advertising providers.
The authority was particularly concerned about smaller app developers that depend on advertising revenue and lack the extensive first-party data available to vertically integrated technology platforms.
That distinction is critical. A privacy mechanism can have a legitimate privacy purpose and still face scrutiny if regulators believe its design creates unnecessary or discriminatory competitive effects.
Germany Forced Changes to Apple’s Consent Experience
Germany pursued a similar line of inquiry.
The Bundeskartellamt, Germany’s Federal Cartel Office, opened an investigation into ATT after raising concerns that Apple’s rules for third-party applications differed from the standards applied to Apple’s own services.
The German authority specifically examined the language, presentation and number of consent requests shown to users.
It concluded preliminarily that Apple’s own consent interfaces could make users more likely to permit Apple’s processing while ATT prompts could steer users toward rejecting data processing by third parties.
In August 2026, Apple agreed to modify the framework following the German investigation.
The changes include making consent dialogs more visually and linguistically neutral, removing potentially discouraging language or symbols from prompts shown for third-party applications and giving developers greater flexibility to coordinate Apple’s ATT request with consent required under data protection law.
Apple was given four months to implement the changes after the German decision takes effect, with commitments scheduled to remain in place for seven years and subject to monitoring.
Apple has continued to defend ATT and has said it believes the framework provides users with clear and effective control over their information.
Privacy Interfaces Are Becoming a Competition Issue
For privacy professionals, one of the most interesting aspects of the Apple dispute is the increasing regulatory attention being paid to the architecture of consent itself.
Consent systems are no longer treated simply as compliance notices.
The wording of a button, the order in which choices appear, the number of screens a person encounters, the availability of an equally prominent rejection mechanism and the treatment of first-party versus third-party processing can all influence user behavior.
Those design decisions can create privacy risk. They can also create competition risk when the entity designing the interface controls access to a market.
Apple occupies an unusual position because it simultaneously operates the platform, establishes privacy rules for applications distributed through that platform, offers its own services and participates in advertising.
The UK claim asks whether that combination allowed Apple to make privacy rules that disproportionately affected competitors.
The Case Does Not Mean ATT Is Going Away
It would be a mistake to interpret the growing litigation around ATT as a rejection of consent-based tracking controls.
European regulators have repeatedly acknowledged the legitimacy of giving users greater control over behavioral advertising and cross-service tracking.
The dispute is about implementation.
A platform can require consent while still facing questions about whether the consent process is neutral, proportionate and consistently applied.
That principle extends beyond Apple.
Companies increasingly build privacy controls into browsers, operating systems, advertising systems, consent management platforms and application marketplaces. Those systems can determine which companies receive data, which technologies execute and which businesses can monetize users through advertising.
As those controls become infrastructure, regulators are likely to examine them as both privacy mechanisms and potential competitive bottlenecks.
What Businesses Should Take From the Apple ATT Dispute
The Apple litigation also provides a broader lesson for organizations designing consent experiences of their own.
Privacy compliance should not depend solely on whether a consent box technically exists. Organizations need to understand what happens before the user makes a choice, what happens afterward and whether the underlying technologies actually behave consistently with that decision.
That includes identifying trackers, pixels, SDKs, advertising technologies and other data flows; determining when those technologies activate; maintaining records of consent; and ensuring that withdrawing or denying permission produces the intended technical result.
The interface matters, but so does the infrastructure behind it.
For organizations operating multiple brands, applications or advertising systems, consistency also matters. Applying one privacy standard to outside companies while allowing materially different treatment for an organization’s own comparable processing can create regulatory questions that extend beyond traditional privacy law.
Apple’s Privacy Strategy Faces a New Test
ATT became one of Apple’s most recognizable privacy initiatives after its 2021 launch. It also changed the economics of mobile advertising and forced companies throughout the industry to rethink how they collect, share and monetize user information.
Five years later, regulators and private litigants are examining the other side of that transformation.
The question is no longer simply whether users should have greater control over tracking. There is broad regulatory support for that principle.
The harder question is whether the company controlling the privacy framework can design that framework in a way that treats its own data practices differently from those of businesses that depend on its platform.
The £2 billion UK claim puts that question directly before the Competition Appeal Tribunal.
If the case proceeds, it could provide one of the clearest tests yet of where privacy engineering ends and unlawful self-preferencing begins.