The ICO Is Now the Information Commission: What Changed on 30 September and What Did Not

7th October 2026

On 30 September 2026, the Information Commissioner’s Office formally became the Information Commission. It is the biggest structural change to the UK’s data protection regulator since it was created, and it has generated plenty of speculation about what it signals. Here is what is actually known.

What happened

Until 29 September, all powers and responsibilities at the ICO were vested in one person, the Information Commissioner. From 30 September, those functions transferred to the Information Commission, a body corporate run by a Board of executive and non-executive members with shared responsibility for decisions. The change was mandated by the Data (Use and Access) Act 2025 and the date confirmed in a written statement to Parliament on 14 September.

Seven non-executive members, appointed in July, took their seats on the day. Paul Arnold is interim Chief Executive, and one of the Board’s first acts was to appoint Maggie Carver, a former deputy chair of Ofcom, as Deputy Chair. A permanent Chair is being recruited. The regulator will still be known as the ICO, now standing for the Information Commission’s Office rather than the Information Commissioner’s Office. In practice the distinction will matter to almost nobody.

Why it was done

The stated rationale is that a board-led structure brings the regulator into line with the FCA and Ofcom, distributes decision-making more broadly, and gives clearer accountability than a model where one individual holds all the authority. Whether a board makes materially different decisions from a single commissioner is something we will only learn over time.

What has not changed

The ICO said in its own announcement that the transition does not change its core responsibilities. It continues to oversee the UK GDPR, the Data Protection Act 2018 and PECR, and if you operate FOIA, EIR or eIDAS Regulation arenas, the ICO will continue to regulate those areas also. Every statutory reference to the Information Commissioner is now read as a reference to the Commission. Your obligations as a controller or processor are exactly what they were on 29 September. The June complaints deadline we covered earlier this year still stands, as does everything else the DUAA introduced.

The new powers are a separate matter

Much of the commentary has run the governance change together with the enforcement powers the DUAA gave the regulator, as though the Board brought the powers with it. It did not. They come from the Act and would apply to whoever held them.

Compelling witnesses.

The regulator can require individuals to attend interviews and provide witness statements as part of an investigation.

Approved person reports.

It can require an organisation to commission a report from an approved third party.

PECR fines aligned with the UK GDPR.

Breaches of the electronic marketing and cookie rules can now attract penalties up to £17.5 million or 4 per cent of global turnover, rather than the previous £500,000 cap, and crucially, Directors and owners of business remain personally liable thus reducing the instance of phoenix companies. 

The ICO consulted on draft procedural guidance for these powers earlier this year and the final version is still awaited. Our guide to preparing for an ICO audit covers the practicalities. It is a sensible moment to check your incident response plan allows for an interview notice, not only a request for documents.

Three things to do

Update your paperwork, without urgency.

Where a privacy notice, policy or contract spells out ‘Information Commissioner’s Office’, change it at the next scheduled review. The abbreviation ICO needs no change, and the statutory reading-across means nothing is wrong in the meantime.

Make sure the board knows.

If data protection only reaches your senior team when something goes wrong, use this as a prompt to brief them on what the regulator can now do.

Watch the first year.

A new Board, a new Chair when appointed, and a forthcoming corporate strategy are where any real change in tone will show. We will cover it when it does.

How Griffin House Consultancy Can Help

Structural change at the regulator is a reasonable prompt to check your own: whether your documentation is current, whether your incident response would hold up under the new powers, and whether the people who would deal with an investigation know it. We help with all three through audits, training and our external DPO service. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533.

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details