On 30 September 2026, the Information Commissioner’s Office will formally become the Information Commission, completing one of the most significant institutional changes to the UK’s data protection regulator in decades.
For businesses, there will be little immediate disruption. UK GDPR, the Data Protection Act 2018 and the regulator’s existing functions continue to apply, existing investigations and enforcement action will carry across automatically, and even the familiar ICO name is staying.
The more significant change is behind the name. The regulator is moving from a model in which its statutory powers ultimately rested with a single Information Commissioner to a board-led corporate structure with collective responsibility for its decisions. It comes alongside wider reforms under the Data (Use and Access) Act 2025 designed to make the regulator more accountable and give it stronger tools for investigating organisations. Over the longer term, the new Commission could have a more substantial effect on the way data protection regulation is supervised and enforced.
What is the Information Commission?
The Information Commission is created under the Data (Use and Access) Act 2025. On 30 September, the office of the Information Commissioner will formally be abolished and its functions transferred to the new body corporate. The Government has stressed that the regulator’s existing statutory functions and responsibilities remain in place.
However there is an important difference in the new body that concerns governance. Until now, the ICO has operated as what is known as a “corporation sole”. In legal terms, powers and responsibilities are vested in one office-holder, the Information Commissioner. The new Information Commission has a corporate board containing executive and non-executive members, with collective responsibility for strategic leadership and decision-making.
The legislation allows the Commission to have between three and 14 members. It provides for a chair, other non-executive members, a chief executive and potentially additional executive members. So far as practicable, non-executive members must outnumber executive members. The chair will continue to hold the title of Information Commissioner.
The transition also follows the resignation of former Information Commissioner John Edwards in June 2026. Edwards stepped down after an independent workplace investigation concluded that there was a case to answer and that his behaviour had fallen short of the standards expected of a public official. Edwards acknowledged occasions of poor judgement and inappropriate attempts at humour that had caused offence, while disagreeing with aspects of the investigation. His resignation did not prompt the move to the Information Commission: the new board-led structure had already been established by the Data (Use and Access) Act 2025 and preparations for the transition were well underway before the investigation. His departure did, however, affect the leadership of the new body, as Edwards had been expected to become its chair. The Government subsequently launched a recruitment process for a new chair.
There is one slightly confusing aspect to the change: the ICO is not really disappearing as a brand. The regulator has confirmed that, as the Information Commission’s Office, it will continue to be known as the ICO. Businesses should therefore expect to continue seeing “ICO” on regulatory guidance, communications and other material after 30 September.
What do businesses need to do now?
Very little. There is no major effort or change required for 30 September. The commencement regulations contain broad continuity provisions. Anything already done, or in the process of being done, by or in relation to the Information Commissioner is treated as having been done by or in relation to the Information Commission. That includes legal proceedings. The Data (Use and Access) Act also provides that existing references to the Information Commissioner in legislation and other documents are to be read as references to the Information Commission where appropriate.
Businesses therefore do not need to reissue contracts, restart regulatory processes or amend every policy before the transition date. There is, however, some sensible housekeeping to do.
Organisations should identify public-facing documents that formally refer to the “Information Commissioner” or “Information Commissioner’s Office”. Privacy notices are the most obvious example, particularly where they explain an individual’s right to complain to the regulator. Cookie policies, data protection policies and complaints procedures may contain similar language.
Businesses should not need to make widespread changes to policies or privacy notices. The regulator has confirmed that it will continue to be known as the ICO after 30 September, now as the Information Commission’s Office. Existing references to the Information Commissioner are also protected by statutory continuity provisions and are to be treated as references to the new Information Commission where appropriate.
Organisations may nevertheless want to update the full name of the regulator when policies and privacy notices next come up for review. For example, a reference to the “Information Commissioner’s Office (ICO)” could become the “Information Commission’s Office (ICO)”. There is no reason to change references that simply say “ICO”, and businesses should not treat 30 September as a deadline for rewriting documentation.
Will the Information Commission be a tougher regulator?
The more interesting question is what happens after the paperwork has been updated. The ICO has faced criticism over the effectiveness and speed of its enforcement. Parliamentary scrutiny has included questions about delays in responding to complaints and the extent to which enforcement activity is translating into meaningful regulatory action. In 2024, for example, the ICO received 41,271 data protection complaints and issued two monetary penalty notices under UK GDPR during the same calendar year. Criticism has also been voiced about enforcement in particular areas such as children’s data.
The creation of the Information Commission is a wider attempt to strengthen the regulator’s governance, transparency and ability to demonstrate its effectiveness. The Data (Use and Access) Act now requires the regulator to publish an annual analysis of its performance using key performance indicators, alongside an annual report on regulatory action covering matters including investigations, the time they take and the powers used. These measures are expressly intended to increase transparency and strengthen accountability to Parliament.
The regulator has also acquired stronger investigatory tools. Since February 2026, it has been able to issue interview notices compelling relevant individuals to attend interviews and answer questions. It can also require an organisation under an assessment notice to commission and pay for an independent report where specialist or technical evidence is required. The ICO has said that these powers are available for serious cases and that it will use them where necessary.
None of this guarantees a sudden increase in fines from 30 September. The transition itself does not change the Commission’s underlying UK GDPR enforcement functions or the maximum penalties available under that regime. The Government has also placed responsible innovation and economic growth alongside the protection of personal information within the regulator’s wider strategic framework.
There are nevertheless clear indications that the new model is expected to demonstrate its effectiveness more visibly. A regulator required to publish performance metrics, report more systematically on investigations and regulatory action, operate under board-level scrutiny and equipped with stronger evidence-gathering powers will face greater pressure to show what its interventions are achieving. For businesses, that makes the Information Commission worth watching well beyond the change of name.