Skip to content
UK ICO Becomes the Information Commission: What Changed on September 30, 2026
  Posted on 03 Oct, 2026
  Tech News

On September 30, 2026, the UK's data protection regulator changed its legal form. The single office of Information Commissioner was replaced by a board-led body called the Information Commission, a change made under the Data (Use and Access) Act 2025. The regulator says it will still be known as the ICO and that its regulatory functions and responsibilities are unchanged, so the practical effect on companies that own websites, apps or custom software is small today, but it is a good moment to check what the regulator plans to focus on next.

This article is a high-level summary for business readers. It is not legal advice. Speak to a qualified data protection lawyer about your own situation.

What was announced

On September 15, 2026, the ICO published a notice stating that the UK Government had confirmed the date of the change: the ICO would become the Information Commission on September 30, 2026. According to that notice, the change comes from the Data (Use and Access) Act 2025 and was brought into force by the Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026. The notice says the Act changes the organization's governance structure while keeping its existing regulatory functions and responsibilities, and that the organization will continue to be known as the ICO.

On September 30, 2026, the regulator published a second statement marking the transition and the opening of its new head office in Manchester. That statement describes the change as a move away from a "corporation sole", where legal authority sat with one person (the Information Commissioner), to collective decision-making by a board.

Key details

ItemWhat the ICO's statements sayStatus
Legal formThe Information Commission, overseen by a board, replaces the single office of Information CommissionerIn effect since September 30, 2026
Name used day to dayThe organization continues to be referred to as the ICOIn effect
BoardSeven non-executive members, appointed in July 2026, took up their roles on September 30, 2026In effect
ChairMaggie Carver, appointed Deputy Chair, is covering the chair's responsibilities in the interim; recruitment of a permanent chair is expected to conclude in spring 2027Interim arrangement
Chief executivePaul Arnold is named as Chief Executive OfficerIn effect
Regulatory functionsExisting functions and responsibilities are maintained; regulation, guidance, advice and public services continueUnchanged
Corporate strategyA forthcoming strategy is described as focusing on areas including AI, cyber resilience, children's privacy and public servicesAnnounced, not yet published

Neither statement sets out any new obligation for businesses or asks organizations to take any action because of the transition.

What this means for your business

The points in this section are our practical interpretation, not statements from the regulator.

The rules you follow have not changed because of this

The ICO describes this as a governance change. The duties that apply to a company processing personal data of people in the UK come from UK data protection law itself, and the September 30 transition does not rewrite those duties. If your website, app or internal system was designed to meet UK requirements on September 29, the transition alone gives no reason to redesign it.

The stated priorities are a useful planning signal

The areas the ICO names for its forthcoming strategy line up closely with decisions software owners are making now: adding AI features, tightening security, and building products that children may use. A strategy is not a rule, and the document has not been published yet, so treat this as an indication of where the regulator's attention may go rather than a list of requirements.

More AI guidance is in the pipeline

Separately from the transition, the ICO's published plan for new and updated technology guidance lists guidance on agentic AI as being in drafting, with a public consultation shown as due to launch in September 2026. The same page lists updated guidance on automated decision-making and profiling as in drafting following a consultation that has closed. We could not confirm on the ICO's site that the agentic AI consultation has opened, so check that page for the current status. For background on how agents differ from chatbots and workflow tools, see our guide to AI agents vs chatbots vs workflow automation.

If your company is in the United States

A US company is not affected by the transition unless UK data protection law already applies to it, for example because it offers a product to people in the UK. Whether it applies is a legal question to raise with counsel. If it does apply, the regulator you deal with is the same organization under a new legal structure.

US regulators have also been tidying their own rulebooks. On September 9, 2026, the Federal Trade Commission announced that it had withdrawn its 2021 policy statement on breaches by health apps and other connected devices. The FTC's release describes the statement as obsolete because the Health Breach Notification Rule, as updated in 2024, now addresses health apps and connected devices directly. The rule itself remains in place, so owners of health and fitness apps should not read the withdrawal as a relaxation of breach notification duties.

What to do now

  • Do not rush to rewrite privacy notices. The regulator says it is still known as the ICO. If your documents name "the Information Commissioner" specifically, ask your legal adviser whether a wording update is worthwhile at your next scheduled review.
  • Keep using existing ICO guidance. The ICO states that its guidance, advice and regulatory work continue.
  • Watch the guidance pipeline if you use AI. If your product makes automated decisions about people or uses AI agents that act on personal data, note the ICO's planned guidance and consider responding to consultations when they open.
  • Review the areas the regulator has flagged. Ask your development team how your software handles security, AI features and any use by children, and where the evidence for those decisions is recorded.
  • Build compliance into new projects early. When you brief a development partner, state which countries your users are in, so data handling requirements are part of the specification and not a late change.

FAQ

Is the ICO being abolished?

No. According to the ICO's statements, the legal entity is now the Information Commission, overseen by a board, but the organization continues to be known as the ICO and keeps its existing regulatory functions and responsibilities.

Do businesses need to do anything because of the change?

The ICO's two statements do not ask organizations to take any action. Your obligations under UK data protection law continue as before. For anything specific to your contracts or notices, take legal advice.

Does this change how the ICO enforces the law or the size of fines?

The ICO's statements about the transition describe a change in governance and say regulatory functions are maintained. They do not announce any change to enforcement approach or penalties, and we have not assumed one.

Conclusion

The move from Information Commissioner to Information Commission on September 30, 2026 changes who governs the UK regulator, not what the law requires of your website, app or software. The more useful signal for software owners is the direction of travel: the ICO has named AI, cyber resilience and children's privacy among the focus areas for its coming strategy, and further AI guidance is planned. If you are planning a new build or adding AI features to an existing product and want data handling considered from the first specification, you can review our development services or get in touch to talk it through. For legal questions, consult a qualified lawyer.

Post Written by
"Entrant Technologies is one of the leading web, software, iPhone & Android app development company which deliver robust results for great brands worldwide. We deliver software solutions that meet the customers and business expectations."
Latest Blogs
 
If you ask three vendors what it costs to build an AI agent, you will probably get three figures that are far apart, and none of them will be wrong. They are pricing different things: a different scop ...
on 03 Oct, 2026 Read More
 
Most people have been stuck with a bad support bot: it misreads the question, repeats the same help article, and hides the route to a person. The bots people dislike usually fail for design reasons, n ...
on 03 Oct, 2026 Read More
 
Most software projects now include an API, whether or not anyone asked for one by name. Your mobile app needs it to talk to your servers. Your accounting system needs it to receive orders. A partner w ...
on 03 Oct, 2026 Read More