What happened

On 30 September 2026 the Information Commission replaced the Information Commissioner as the UK's statutory data protection regulator. The organisation continues to present itself as the ICO, now formally the Information Commission's Office.

The change is structural rather than cosmetic. The old regulator was a corporation sole, which meant its statutory powers and responsibilities were vested in one person, the Information Commissioner. Those functions have now transferred to a corporate body overseen by executive and non executive board members. The new structure was created by the Data (Use and Access) Act 2025, which received Royal Assent in June 2025. The government says the change modernises governance without altering the regulator's existing functions.

The transition follows a difficult period. Information Commissioner John Edwards resigned in June 2026 after an independent workplace investigation into his conduct, saying his position had become untenable and that attempts at humour had been inappropriate and caused offence. He had stepped back from his duties in April, and the watchdog removed his remaining responsibilities after the investigation found there was a case to answer. Paul Arnold, who had taken on Edwards' statutory responsibilities, is interim chief executive. Seven non executive members have joined the new board and appointed Maggie Carver as deputy chair; she performs the chair's duties while the government recruits a permanent chair, a process not expected to finish until spring 2027. The regulator has also moved its headquarters from Wilmslow to Oxford Road in Manchester.

Why this is a GRC story

How a regulator is governed matters to everyone it regulates. Corporation sole concentrates authority, and with it the risk that one person's conduct becomes the institution's problem, which is close to what happened here. A board with executive and non executive members spreads statutory responsibility and adds oversight. In practice that tends to produce a more committee shaped regulator, less dependent on the judgement of a single individual and more likely to codify its positions.

Continuity matters more than the rebrand. The Information Commission retains responsibility for data protection and freedom of information regulation, together with the existing powers, guidance and public services. Enforcement decisions and complaint handling should look familiar. That said, a regulator in transition tends to be deliberate about its first major acts, and the interim leadership arrangement now runs for months rather than weeks.

A new strategy is on the way. The regulator has said AI, cyber resilience, children's privacy and public services will be among the areas singled out for attention. Those named priorities are a reasonable forecast of where guidance, reviews and enforcement attention will fall next.

What to watch

Watch the chair recruitment. If a permanent chair does not arrive until spring 2027, the regulator will run on an interim basis for another two quarters, and strategy published in that window may be revisited once the permanent leadership is in place.

Watch how the priorities become work. If AI and children's privacy move from strategy language into audits, sector reviews or enforcement, that is the point at which the new governance structure starts to look different in practice from the old one. Organisations handling UK personal data should keep records of processing, assessment discipline and children's data controls current, because those are the areas the regulator has already named.

Attribution: Analysis based on The Register's reporting and the ICO's announcement of the transition. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News