From the ICO to the Information Commission
Written by Mark Farrell
The ICO’s transition to the Information Commission on 30 September 2026 is more than a rename. Here’s what’s actually changing in how the regulator is governed, resourced and expected to act.
With the Information Commissioner’s Office (ICO) transition to the “Information Commission” under the Data (Use and Access) Act (DUAA) 2025 set to be confirmed on 30 September 2026, it is an appropriate moment to look at what this change actually means for the regulator.
The transition is a structural evolution that will not change the fundamental role and responsibilities of the regulator. The DUAA amends references to “Information Commissioner” to the “Information Commission,” so all existing functions transfer over. The commencement regulations also ensure that actions taken by, or in relation to, the Information Commissioner before 30 September 2026 will continue to have effect after the transfer to the Information Commission.
It is fair to classify the transition as more administrative than substantive, especially from the perspective of organisations. For organisations, the change may involve nothing more than updating documentation to refer to the Information Commission. However, the transition represents more than a rebrand. The way the regulator is constituted, governed and held to account is genuinely changing.
The narrative around the DUAA changes often focuses on the perspective of organisations, reduction in regulatory burden, simplification of certain requirements and greater flexibility to process personal data. But what is the view from the regulator’s side, and what, if anything, can those subject to its authority expect to change?
Towards Board Governance
Moving from a governance structure built around a corporation sole (the Information Commissioner) to a body corporate (the Information Commission) modernises the UK’s data protection regulator, bringing it into alignment with other domestic regulators such as Ofcom and the Competition and Markets Authority (CMA).
Whilst the Information Commissioner had the final say in decision making, the Information Commission will operate with a board comprising the Chair of the Information Commission, a chief executive officer, and other non-executive and executive members who will share decision-making responsibilities.
In July 2026 the appointment of seven Non-Executive Members to the Information Commission Board was announced, Laurie Benson, Maggie Carver, Stephen Cohen, Sukhvinder Kaur-Stubbs, Gary Kildare, Hilary Newiss and Scott McPherson, alongside the launch of recruitment for the Chair of the Information Commission. The appointments are intended to give the new Board a wider range of skills and experience across business, technology, regulation, governance and public service, embedding strategic leadership and oversight within a collective governance structure.
The impact of this structural change will be to make the regulator less personality-led and more framework-led. A corporation sole should, in theory at least, offer decisiveness, but as we have seen, it is also liable to make regulatory tone and emphasis dependent on one individual’s instincts, leading to data protection laws “varying with the length of the Commissioner’s foot.”
Data protection regulation in the current age requires not just authority, but governance, oversight and expertise. A board structure brings all three, as well as greater resilience, continuity in strategy and a broader range of perspectives. Having a wider range of views factored into the regulator’s approach aligns with the formal expansion of the ICO’s regulatory priorities under the DUAA.
Beyond Protecting Personal Data
The DUAA introduces a fresh strategic framework for the regulator when carrying out its functions, built around a principal objective supported by several other key areas. The primary duty remains to secure an appropriate level of protection for personal data, alongside a new additional requirement to promote public trust and confidence in the processing of personal data.
The other factors set out in the DUAA, which the Commission must have regard for when carrying out its tasks and responsibilities, are not new priorities as such but existing areas of focus for the ICO that now gain formal recognition and reinforcement within the Commission’s overall remit, including:
- The desirability of promoting innovation
- The desirability of promoting competition
- The importance of the prevention, investigation, detection and prosecution of criminal offences
- The need to safeguard public and national security
- The fact that children merit specific protection with regard to their personal data
This broadening of the regulatory remit reflects the fact that the data protection regulator’s role is no longer confined to data breaches and individual rights, but increasingly involves supervision across emerging areas of public concern such as artificial intelligence, children’s data, biometrics, online tracking, cross-regulatory coordination and the relationship between data protection, competition and innovation.
Alongside this expanded focus is a duty for the Commission to consult other regulators on economic growth, innovation and competition, which will presumably take place through the existing DRCF (Digital Regulation Cooperation Forum), which brings together the ICO, the Financial Conduct Authority (FCA), Ofcom and the CMA.
This signals a move away from data protection being treated as a standalone compliance issue and toward a more joined-up regulatory model, in which privacy, competition, innovation and online safety are assessed alongside one another. In practice, this increases the likelihood of coordinated regulatory expectations, shared intelligence and scrutiny across regulators, meaning organisations may face a more consistent but also more demanding regulatory environment.
The Commission will be held accountable for this new remit by greater transparency requirements introduced by the DUAA, which require it to publish an annual analysis of its performance and report on regulatory action, including the nature of investigations, time taken and powers used. Requiring the regulator to explain not only what it prioritises but how efficiently it uses its powers and resources is intended to create a more publicly accountable institution.
Alongside factoring these considerations into its decision making, the Information Commission will also have a range of DUAA changes to oversee, each motivated by these same considerations. The changes around automated decision making and the scientific research exemption clearly reflect the promotion of innovation and competition. The recognised legitimate interest for sharing data for crime prevention and national security reflects the crime-based objective, and children’s data reforms, which embed children’s higher protection considerations more firmly into regulatory expectations, reflect the associated aim.
This combination of new regulatory considerations also shows up in the regulator’s prominent priorities for 2026, which include the AI and biometrics strategy, and the Children’s Code and its enforcement guidance. This broader remit will clearly come to permeate the Information Commission’s work across the board. So how is it likely to show up in future enforcement action?
The Enforcement Forecast
The ICO’s recent enforcement track record has remained broadly aligned to the primary objective of protecting personal data, data rights and upholding public trust, with many headline sanctions relating to data security breaches, including the Capita, Advanced Computer Software, 23andMe and LastPass fines.
However, recent action taken against TikTok and Reddit, centred on proactively protecting children’s data, points to the ICO broadening its focus beyond data security breaches, reflecting the wider regulatory priorities formalised by the DUAA. Children’s data is best viewed not as one priority among many, but as an increasingly cross-cutting theme across all the newly formalised regulatory priorities.
Whether the enforcement picture will change following the increased monetary penalties for PECR breaches, which bring this regime in line with the UK GDPR, is debatable. The clear point to make is that PECR can no longer be treated as a poor relation of the UK GDPR and should attract the same level of compliance focus.
However, there is a valid observation that PECR fines tend to be imposed against cold callers and those operating in flagrant disregard for the requirements, often lacking the financial means to meet fines imposed under the previous £500,000 threshold, let alone fines within UK GDPR limits.
It is likely that the threshold increase is focused on deterrence, with the original threshold not providing enough of one. Whilst it is debatable whether the ICO will issue significantly larger PECR fines than before, it is worth bearing in mind that historically more fines have been issued under PECR than the UK GDPR, partly because PECR breaches are more straightforward for the regulator to evidence.
The overall trend of enforcement action in recent years, despite the ICO’s public sector approach, has been upward, and it is likely to continue on this trajectory, especially given the new enforcement procedural guidance set to replace the 2018 Regulatory Action Policy, which will determine how the ICO operates in view of the expanded powers conferred by the DUAA.
In particular, the introduction of structured settlement procedures akin to those used by the FCA and Ofcom, offering discounts to fines of up to 40% for early resolution before a notice of intent, 30% after notice of intent and 20% after written representations, points to a regulator keen to settle cases quicker, avoid time-consuming litigation and free up capacity for further enforcement. These priorities are also furthered by new evidence gathering powers.
Enhanced Evidence Gathering
The headline new evidence gathering capabilities conferred on the ICO, and soon the Information Commission, under the DUAA are powers to:
- Compel production of specific documents (in force since 19 August 2025)
- Compel a witness to attend an interview (in force since 5 February 2026)
- Request technical reports
These powers strengthen the regulator’s evidence gathering tools in response to investigative challenges. The first clarifies the regulator’s existing power to issue Information Notices, ensuring this expressly includes specific documents. The second allows the regulator to compel anyone working for the controller or processor, currently or previously, to attend an interview, removing reliance on voluntary interviews.
The first two powers are likely to be used primarily to deal with uncooperative respondents. A regulator having to use these powers at all is likely to be treated as an aggravating factor when sanctions and penalties are decided. However, it is the third power that is the most eye-catching, and likely the most impactful for the regulator, data subjects and organisations alike.
For the regulator, the power to mandate production of a report by an approved person, at the cost of the organisation and with specific subject matter, form, manner and date of preparation, should free up capacity to investigate and sanction more organisations. This is especially true given this power is likely to be used for technical and cyber-related matters, which are particularly resource and time intensive for the ICO.
These reports also have the potential to become more easily available to claimants than other internally produced equivalents, and could be highly advantageous for advancing legal claims. This is worth considering given the rise in the UK of collective and representative data breach claims, and the fact that the ICO appears content with data subjects placing increasing pressure on organisations.
Complaints: Lightening the Regulator’s Burden
The overall intention of the DUAA complaints changes (full article here) is not only to increase the obligation on organisations to resolve data protection complaints raised by individuals, but in turn to reduce the burden placed on the ICO by the large volume of complaints made to it directly. This is being achieved by:
- Giving individuals the legal right to raise data protection complaints with organisations directly, where previously they only had the legal right to complain to the ICO
- Requiring organisations by law to facilitate and address data protection complaints made directly to them, rather than this being merely a regulatory expectation
- Allowing the ICO to defer individuals and organisations until the organisation’s own complaints process is exhausted and regulatory involvement is warranted
Alongside the DUAA complaints changes, the ICO has published a new framework on how it handles complaints, aimed at more effectively managing the large and increasing volumes it receives. There is also an intention to further use complaint data, both the ICO’s own and that which it can now also request from organisations following the DUAA, to help identify broader issues with organisational compliance and inform regulatory interventions.
The overall aim of the framework is to focus resources on cases where the ICO can have the biggest impact and where issues align with strategic priorities, reinforcing the message that the regulator cannot act on every complaint. This has long been an aspiration, and the regulator will hope it becomes far more achievable following the DUAA changes. Whether this actually changes the picture for a cross-sector regulator that has tended to become overrun by complaints remains to be seen, though the intention is clearly to free up and better target resources toward key, impactful issues.
Conclusion
The government and the ICO have presented the DUAA as a reform package focused on promoting innovation, supporting growth and making compliance easier for organisations. There is truth in that, the Act relaxes and clarifies certain requirements, for example around scientific research, recognised legitimate interests, cookies and automated decision-making. But the transition to the Information Commission shows that simplification is only half the story.
The other half is a regulator designed to be more strategically oriented, better equipped and more assertive in its regulatory action. Organisations taking advantage of the greater flexibility permitted by the DUAA should be mindful that this freedom comes with a string attached: the regulator is better equipped to investigate and penalise should things go wrong. In that sense, the regulatory environment may have become easier to understand in some areas, but not necessarily easier to navigate.
Ultimately, this is not a shift from more regulation to less, but from an older model of data protection oversight to a newer version that is board-governed, strategically accountable and more appropriately calibrated for the emerging pressures of AI, digital markets, children’s privacy and an increasingly sophisticated enforcement picture. That is the real significance of the move from the ICO to the Information Commission.