ICO Becomes the Information Commission: What It Means for UK Data Protection

30 September 2026 marks an important change for data protection regulation in the UK.

From today, the Information Commissioner’s Office transitions to the Information Commission, following reforms introduced by the Data (Use and Access) Act 2025.

But despite the change, organisations shouldn’t expect the familiar ICO name to disappear. The regulator has confirmed that, as the Information Commission’s Office, it will continue to be known as the ICO. Its existing regulatory functions and responsibilities will also continue.

So, is this essentially a change of name?

Not quite.

The transition changes the governance structure behind the UK’s data protection regulator and sits within a much broader evolution of the UK’s regulatory approach to personal information.

For organisations, the important question is therefore not simply“What is the ICO called now?”

It is:

What does the Information Commission mean for the future of data protection in the UK?

What is changing at the ICO?

Historically, the UK’s data protection regulator has been legally structured around the Information Commissioner as a single statutory office holder.

That model has now changed.

The office of Information Commissioner is replaced by the Information Commission, with the functions previously exercised by the Information Commissioner transferred to the new Commission. The Commission can also continue work started under the previous structure.

The structural change introduces a Commission with a board and new governance arrangements. Seven Non-Executive Members were appointed to the Information Commission Board ahead of today’s transition. [ico.org.uk]

The intention is to move towards a more modern regulatory governance model, providing greater resilience and a wider range of perspectives in the regulator’s strategic direction.

However, from the perspective of most businesses, there is an important point of continuity:

The ICO isn’t disappearing.

The organisation has confirmed that the Information Commission’s Office will continue to be known as the ICO, and its existing regulatory functions and responsibilities remain in place.

For businesses already dealing with the ICO, that should make the transition considerably less disruptive.

Does this mean the UK GDPR is changing?

The creation of the Information Commission should not be confused with the replacement of the UK’s existing data protection framework.

Organisations remain subject to the UK GDPR, Data Protection Act 2018 and other applicable information rights legislation, as amended by the Data (Use and Access) Act 2025.

The wider legislation has introduced important changes to UK data protection and privacy law, but the establishment of the Information Commission itself primarily changes the structure through which regulatory functions are exercised.

There is also explicit provision for continuity. References in UK law to the Information Commissioner are generally to be taken to mean the Information Commission, and work already commenced by the Information Commissioner can continue under the new Commission. [ico.org.uk]

In other words:

Your organisation’s data protection responsibilities have not disappeared because the regulator’s structure has changed.

Privacy notices still matter.

Data subject rights still matter.

DPIAs still matter.

Lawful bases still matter.

Security still matters.

And being able to demonstrate accountability still matters.

Why does the move to the Information Commission matter?

This is where the change becomes more interesting.

Looking only at the new name risks missing the wider direction of UK data protection regulation.

The Government describes the reforms as providing the ICO with a clearer strategic framework, while strengthening transparency and accountability. Importantly, the Commission’s principal objective combines securing an appropriate level of protection for personal data with promoting public trust and confidence in the processing of personal data.

The framework also requires the regulator to consider areas including:

  • the desirability of promoting innovation;
  • the desirability of promoting competition;
  • crime prevention, detection, investigation and prosecution;
  • public and national security; and
  • the particular protection required for children’s personal data.

That matters because it illustrates something increasingly important about the direction of privacy regulation.

Good data protection isn’t about preventing organisations from using data.

It is about organisations being able to use data responsibly, transparently and with appropriate governance.

For GRC Hub, we think that’s an important distinction.

What does the Information Commission mean for organisations?

For most businesses, there is no reason to panic or launch a wholesale privacy remediation programme purely because the regulator has changed structure.

There are, however, some sensible actions organisations should take.

1. Review references to the Information Commissioner

Organisations are likely to have references to the Information Commissioner, Information Commissioner’s Office or ICO throughout their privacy documentation.

These could appear in:

  • privacy notices;
  • employee privacy notices;
  • data protection policies;
  • data breach procedures;
  • Subject Access Request procedures;
  • data protection complaints procedures;
  • Data Protection Impact Assessments;
  • Records of Processing Activities;
  • contracts and Data Processing Agreements; and
  • internal compliance training.

There is no reason to indiscriminately rewrite every document overnight. The legislation provides for continuity between the existing Information Commissioner and the new Information Commission.

Instead, organisations should incorporate terminology changes into their normal policy and documentation review cycle.

2. Don’t mistake regulatory reform for deregulation

Perhaps the biggest mistake organisations could make is to interpret the current direction of UK data protection reform as meaning that privacy matters less.

That isn’t what is happening.

The Government’s stated intention behind the wider reforms includes both enabling more effective use of data and modernising and strengthening the ICO, while maintaining high standards of protection.

There is certainly an increased emphasis on innovation.

But responsible innovation requires good governance.

For organisations adopting AI, automation and increasingly data-intensive technologies, questions such as these are becoming more important:

What personal information are we using?

Why are we using it?

Do we actually need it?

What is our lawful basis?

What risks does the processing introduce?

Have we properly considered individuals?

Can we demonstrate how we reached our decision?

Good privacy governance should enable organisations to answer those questions without unnecessarily preventing innovation.

3. Pay particular attention to data protection complaints

One area privacy leaders should be watching carefully is complaints handling.

Data protection complaint volumes received by the regulator increased from 39,721 in 2023/24 to 42,881 in 2024/25, according to figures published as part of the ICO’s consultation on its approach to complaint handling.

At the same time, organisations themselves are facing new requirements around having processes specifically for handling data protection complaints. The ICO has indicated that it expects more complaints to be resolved directly between individuals and organisations without regulatory involvement.

This has an important practical implication.

Privacy compliance increasingly needs to work operationally, not simply exist on paper.

It’s no longer enough for an organisation to have a beautifully drafted data protection policy sitting on SharePoint.

An organisation needs to know:

  • how a privacy complaint is identified;
  • who receives it;
  • who investigates it;
  • how it is tracked;
  • how correspondence is retained;
  • when the DPO or privacy team becomes involved;
  • how trends and recurring issues are identified; and
  • how the organisation demonstrates what it did in response.

This is exactly where the difference between having privacy documentation and having an effective privacy programme becomes apparent.

4. Look closely at how you manage data subject requests

The same principle applies to Subject Access Requests and other data subject rights.

The regulator’s own consultation highlights the connection between effective organisational complaint management and the wider pressure on regulatory resources.

For many organisations, DSARs have evolved into a significant operational challenge.

Requests may touch multiple systems, email accounts, Teams conversations, HR platforms and third-party applications. Identifying information is often only the start. Organisations then need effective review, redaction, quality assurance and governance before disclosure.

That means organisations should be asking whether their current DSAR processes remain scalable.

Where request volumes are increasing, manually coordinating cases through inboxes and spreadsheets can quickly create unnecessary risk.

A mature data protection framework therefore needs to consider not simply whether an organisation understands the right of access, but whether it can consistently deliver against that right in practice.

5. AI makes strong privacy governance more important, not less

The timing of the Information Commission’s arrival is also significant.

Organisations are deploying artificial intelligence at considerable speed.

Microsoft Copilot, AI-enabled SaaS platforms, automated decision-making tools, recruitment technologies and generative AI increasingly involve questions around personal information.

Meanwhile, the new statutory framework explicitly requires the regulator to consider the desirability of promoting innovation and competition, alongside its principal objective concerning protection and public trust.

This creates an important opportunity for privacy professionals.

Privacy should not be the department that says “no” to AI.

Privacy should help organisations answer:

“How can we do this responsibly?”

That means embedding privacy into AI governance through mechanisms such as:

  • Data Protection Impact Assessments;
  • AI impact and risk assessments;
  • vendor due diligence;
  • data mapping;
  • appropriate contractual controls;
  • human oversight;
  • transparency; and
  • governance around the use of personal information.

Organisations that connect their privacy, information security and AI governance programmes are likely to be much better positioned than those treating each as a separate compliance exercise.

6. Accountability remains fundamental

Perhaps the most important message from all of this is that accountability isn’t going anywhere.

The regulatory structure may be evolving.

The legal framework may be changing.

Technology certainly is.

But organisations still need to be able to demonstrate that appropriate decisions have been taken about personal information.

This means maintaining effective governance around areas such as:

  • Records of Processing Activities;
  • DPIAs;
  • legitimate interest assessments;
  • retention;
  • third-party risk;
  • data breaches;
  • data subject rights;
  • privacy complaints;
  • international transfers;
  • AI governance; and
  • staff training and awareness.

The strongest organisations won’t necessarily be the ones with the largest privacy teams or the longest policies.

They will be the organisations that can evidence that privacy risk is understood, owned and actively managed.

So, what should organisations do now?

The transition to the Information Commission provides a useful opportunity to conduct a simple health check of your existing privacy programme.

At GRC Hub, we’d suggest asking six questions.

1. Governance

Is ownership of data protection clearly defined, and does your DPO or privacy lead have sufficient independence, authority and access to senior leadership?

2. Documentation

Do your privacy notices, policies, RoPAs, DPIAs and supporting procedures genuinely reflect what happens within your organisation today?

3. Data subject rights

Could you confidently identify, coordinate and respond to a complex DSAR across multiple business systems?

4. Complaints

Do you have an effective process for identifying, escalating, investigating and recording data protection complaints?

5. AI

Do new AI systems enter an established governance and privacy assessment process before deployment?

6. Assurance

Most importantly:

If the Information Commission examined your organisation tomorrow, could you demonstrate why important privacy decisions were made?

If the answer to that final question is uncertain, that’s probably where your attention should go next.

The Information Commission: evolution rather than revolution

The establishment of the Information Commission is an important milestone for UK data protection, but it isn’t a reason for organisations to panic.

The regulator has been clear that its existing regulatory functions and responsibilities continue, and that the Information Commission’s Office will continue to be known publicly as the ICO.

The bigger story is the direction in which UK information regulation is moving.

The new strategic framework combines protection of personal information and public trust with explicit consideration of innovation, competition and other wider public interests.

For privacy leaders, that’s an opportunity.

Data protection doesn’t need to be positioned as a barrier to business.

Done properly, it provides the governance organisations need to use data confidently, responsibly and transparently.

And as AI and data-driven services become embedded throughout organisations, that capability is likely to become even more valuable.

How GRC Hub can help

At GRC Hub, we help organisations move beyond paperwork and build practical, proportionate privacy programmes that work in the real world.

Our approach is straightforward:

Assess → Align → Assure

Assess your current privacy environment, risks and maturity.

Align your governance, processes and controls with regulatory requirements and the needs of your organisation.

Assure leadership, customers and stakeholders that those controls are operating effectively.

Whether you need DPO-as-a-Service, independent data protection assurance, support with DSARs and privacy operations, or help bringing privacy and AI governance together, GRC Hub can provide proportionate support based on your organisation’s actual risks.

Want to understand what the changes to UK data protection mean for your organisation?

Speak to GRC Hub about a Data Protection Health Check or DPO-as-a-Service.

The Governance Risk & Compliance Hub - Data Protection and Cybersecurity Specialists Logo.

Governance Risk & Compliance Hub LIMITED

© 2026 All rights reserved