Bye bye ICO, hello IC: What’s changed beyond the name

Measured Collective
5 min read · Sep 30, 2026

On 30 September 2026 the Information Commissioner’s Office formally became the Information Commission. The change was made under the Data (Use and Access) Act 2025 and gives the UK’s data protection regulator a new governance structure. Its functions and powers are unchanged, and it will still be known as the ICO, which now stands for the Information Commission’s Office.

This article covers what the change means, what the ICO and government have said about it, and the enforcement cases that have shaped the regulator’s year so far.

What has changed

Until now the ICO was a “corporation sole”, meaning its legal powers were held by one person, the Information Commissioner. From 30 September those powers moved to the Information Commission, a corporate body run by a board of executive and non-executive members who share responsibility for decisions. Ofcom and several other UK regulators already work this way.

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. On 14 September 2026 Stephanie Peacock, Parliamentary Under-Secretary of State at the Department for Digital, Culture, Media and Sport, confirmed in a written statement to the House of Commons that the transition would take effect on 30 September, under regulations the government had made to commence the relevant sections of the Act (SI 2026/1015).

The regulator’s duties under UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR) stay the same, as do the maximum fines it can issue.

Who runs it

Paul Arnold is Chief Executive Officer and sits on the board as its executive member. Seven non-executive members, appointed in July, took up their roles on 30 September: Laurie Benson, Maggie Carver, Stephen Cohen, Sukhvinder Kaur-Stubbs, Gary Kildare, Hilary Newiss and Scott McPherson. Their backgrounds are set out on the ICO’s Information Commission Board page.

There is no permanent chair yet. According to the ICO’s 30 September announcement, one of the board’s first decisions was to appoint Maggie Carver, a former deputy chair of Ofcom, as Deputy Chair. She will carry out the chair’s responsibilities until the Department for Digital, Culture, Media and Sport (DCMS) completes its recruitment, which the ICO expects to finish in spring 2027. Whoever is appointed chair will hold the title of Information Commissioner.

The previous Information Commissioner, John Edwards, resigned on 19 June 2026 following an independent workplace investigation.

What the ICO and government said

In its announcement on 30 September, the ICO said the new board would scrutinise, challenge and support the delivery of its priorities. It also confirmed it has opened a new head office on Oxford Road, Manchester.

In the same announcement, Paul Arnold said: “Today is the beginning of an important new chapter for our organisation.” He added that the ICO’s day-to-day work continues, including guidance for organisations and holding them to account when people’s information rights are not respected.

Stephanie Peacock, quoted in the announcement as Digital Government Minister, said the Commission would continue to provide independent oversight of data protection while bringing a wider range of expertise to the regulator.

The ICO is also preparing a new corporate strategy, which it says will focus on AI, cyber resilience, children’s privacy and public services.

ICO enforcement in 2026

ICO enforcement has already resulted in some large fines this year. On 24 February the ICO fined Reddit £14.47 million for processing the personal information of children under 13 without effective age checks (our coverage). In May it fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 after a cyber attack exposed the personal information of 633,887 people (our coverage). These are just two examples.

We’ll be keeping an eye on whether the new board and new powers, such as the power to compel a witness to attend an interview, in force since 5 February 2026, lead to tougher action. It is likely to be a while before this shows in published cases, because ICO investigations take a long time to reach a penalty. The South Staffordshire fine, for example, related to an attack discovered in 2022.

What organisations need to do

No action is legally required. As the Data Protection Network points out, references to the Information Commissioner in legislation are now read as references to the Information Commission, so existing contracts and policies remain valid. You may want to update the regulator’s name in privacy notices and other public documents at their next review.

This year’s cases point to three practical areas to check:

  • If your website or app may be used by children, asking users to state their age is unlikely to satisfy the ICO, and a DPIA covering risks to children is expected. The ICO made both points in its Reddit decision.
  • Large security fines have turned on well-established controls such as patching, access restrictions and network monitoring, as in the South Staffordshire case.
  • Admitting failings early and settling can reduce a penalty substantially. The ICO applied a 40% reduction to South Staffordshire’s fine for its early admission of liability.

Separately, since 19 June 2026 organisations have been required under the Data (Use and Access) Act to have a process for handling data protection complaints, as the ICO confirmed in its commencement statement. Our guide to what changed on 5 February 2026 covers the wider reforms.

What to watch

The main open questions are who is appointed chair, what the final corporate strategy contains, and whether the new board changes how the ICO uses its enforcement powers.

Sources