DPO Insights

The ICO becomes the Information Commission on 30 September

Praeferre ResearchPraeferre Insights Team
Published
Read time5 min read
DPO Insights

In mid-September 2026 the government and the Information Commissioner’s Office confirmed that the ICO will become the Information Commission on 30 September 2026. The change comes from the Data (Use and Access) Act 2025 and is one of the most significant shifts in how the UK regulates data protection since the office was created. For most organisations nothing needs to change on day one, but it is worth understanding what is different and why it may matter over time.

What is changing

Today the ICO operates as a corporation sole: its legal powers and responsibilities sit with one person, the Information Commissioner. From 30 September those functions transfer to the Information Commission, a body corporate with both non-executive and executive members that takes decisions collectively.

Seven Non-Executive Members of the new Information Commission Board were announced in July and take up their roles on 30 September. According to Freevacy, the change was set out in a written ministerial statement to the House of Commons on 14 September and is brought into force by the Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026. Freevacy also reports that the government has begun public recruitment for a chair of the Commission, and that interim Chief Executive Paul Arnold will serve alongside the non-executive members.

What is not changing matters just as much. The ICO says existing regulatory functions and responsibilities are maintained, that it will continue to be known as the ICO, and that its focus is on continuity of service.

Key points
Date
30 September 2026.
Legal basis
Data (Use and Access) Act 2025.
Structure
From a single Commissioner to a board-led Commission with collective decision-making.
Name in practice
Still referred to as the ICO.

Why a governance change is worth a DPO’s attention

A new structure does not rewrite the UK GDPR, but it can shape how the law is applied. Collective decision-making brings more voices into strategy and priorities, and a board with non-executive members is designed to provide challenge and oversight. Over time, that may influence where the regulator focuses its enforcement effort, how it balances innovation against protection, and how consistently it explains its decisions.

The same week offered a glimpse of the agenda the new Commission inherits. In a blog published on 17 September, ICO Chief Executive Paul Arnold discussed smart glasses and AI-enabled wearables. He highlighted both their benefits, for example for people with visual impairments, and the risk of people being recorded without knowing. He also noted that transparency in physical spaces relies heavily on visual cues such as signs, which do not work for everyone. The ICO said it will commission research into public attitudes to AI and is preparing a consultation on a new code on AI and automated decision-making in 2027.

“The badge on the door stays the same. The way the regulator reaches its decisions does not.”

— Praeferre analysis

What to do now

There is no need for panic, but a little housekeeping will keep your programme accurate.

  1. Update policy references. Where privacy notices, policies, training or contracts describe the regulator, plan to reflect the Information Commission at the next scheduled review. The ICO says it will still be known as the ICO, so there is no need for urgent reprinting.
  2. Keep live matters on track. If you have an open complaint, breach report or investigation, continue engaging as normal and note the date of the transition in your case records.
  3. Brief your board. A short note explaining the change, and why regulator priorities may evolve, helps senior leaders understand the UK landscape after the Data (Use and Access) Act.
  4. Watch the AI agenda. Start preparing for the ICO’s planned AI and automated decision-making code by documenting where you use AI to make or support decisions about people.
  5. Review wearables and recording devices. If staff or visitors use smart glasses or similar devices on your premises, consider whether your policies and signage address them.

Praeferre’s DPO as a Service keeps organisations up to date with UK regulatory change and translates it into practical actions, while our GRC automation platform tracks policy reviews and evidence. Read more on the UK GDPR.

Keep your privacy programme aligned with UK regulatory change, without adding headcount.

Explore DPO service

Common questions

On 30 September 2026, under the Data (Use and Access) Act 2025.

No immediate action is required. The ICO says its regulatory functions are maintained and it will continue to be known as the ICO. Organisations should update policy references at their next review and continue engaging on any live matters as normal.

Powers move from a single Information Commissioner to a Commission with executive and non-executive members that takes decisions collectively.

Sources

  1. ICO governance changes confirmed for 30 September 2026 — Information Commissioner’s Office, 15 September 2026
  2. ICO to transition to Information Commission on 30 September 2026 — Freevacy, 14 September 2026
  3. Enabling technology for good: smart glasses, privacy and a broader challenge for public trust — Information Commissioner’s Office, 17 September 2026