The Information Commission has officially succeeded the Information Commissioner's Office (ICO) as the UK's data protection regulator today, 30 September 2026. This change aims to modernise the governance of the regulator while maintaining its independent oversight and existing powers to protect personal data.
Previously, the ICO operated as a corporation sole, with all statutory powers vested in the Information Commissioner. These functions now transfer to the Information Commission, a body corporate led by executive and non-executive members who hold collective responsibility for decisions.
Digital Government Minister Stephanie Peacock stated that the new Information Commission will continue to provide strong, independent oversight of data protection. Paul Arnold, interim Chief Executive of the Information Commission, welcomed the new non-executive board members and Deputy Chair, noting it marks a key milestone in the organisation's modernisation.
The new governance model was established by the Data (Use and Access) Act 2025. For individuals and organisations, the transition does not alter the regulator’s role, responsibilities, or powers; it will continue to regulate data protection and freedom of information legislation independently.