The Information Commission: the end of the ICO as a one-person regulator

The Information Commission: the ICO moves from a single Commissioner to a statutory board under the Data (Use and Access) Act 2025

In short: The Information Commission is the statutory board that will replace the Information Commissioner as the UK data protection regulator. Sections 117 to 119 of the Data (Use and Access) Act 2025 abolish the Commissioner as a corporation sole and vest its functions in a body corporate led by a chair, chief executive and other members, expected during 2026/27.

By Rob Bratby, Managing Partner, Bratby Law. Lexology Global Elite Thought Leader for Data Protection. Chambers UK Band 2 (Telecommunications). Legal 500 Leading UK Telecoms Partner. 30+ years in telecoms and data protection regulation, including Oftel and senior operator roles.

For as long as there has been UK data protection law, one named person has held the regulator’s powers. Parliament has now legislated to end that. The Data (Use and Access) Act 2025 abolishes the office of Information Commissioner and transfers its functions to a new body corporate, the Information Commission, governed by a board rather than a single office-holder. The Information Commissioner’s Office records the change in its annual report for 2025/26, laid before Parliament on 14 July 2026, which it expects to be its last full year in the present form. The governance change is only one part of the DUAA, which also reshaped the substance of data protection law; but the reconstitution of the regulator is a change of its corporate governance, and it follows the same path telecoms took when Oftel became Ofcom: a single office-holder replaced by a statutory board.

Key findings (ICO Annual Report 2025/26)

  • The Data (Use and Access) Act 2025 will abolish the Information Commissioner as a corporation sole and transfer its functions to the Information Commission, a statutory board, with the change expected during 2026/27. Source: ICO, The Information Commission.
  • The regulator imposed £33.848m in monetary penalties in 2025/26, up from £4.426m the year before; £18.259m of that is under appeal. Source: ICO Annual Report 2025/26, financial performance summary.
  • The largest fine was £14,472,500 to Reddit for failing to apply robust age assurance before processing children’s data. Source: ICO Annual Report 2025/26.
  • Cookie compliance work brought 979 of the top 1,000 UK websites into line, which the ICO estimates gives around 40 million people control over online tracking. Source: ICO Annual Report 2025/26.
  • John Edwards resigned as Information Commissioner on 19 June 2026 following an independent workplace investigation that found a case to answer; Paul Arnold is Interim Chief Executive Designate of the Information Commission. Source: ICO Annual Report 2025/26, Introduction.
Enforcement in 2025/26FigureWhat the ICO did
Total monetary penalties imposed£33.848m (2024/25: £4.426m)Concentrated a higher penalty total in fewer, larger actions
Penalties under appeal£18.259mNot recognised in the financial statements pending appeal
Reddit£14,472,500Fined for failing to apply robust age assurance for under-13s
23andMe£2,310,000Fined for security failings under Articles 5(1)(f) and 32(1) UK GDPR, after a joint investigation with Canada
MediaLab (Imgur)£247,590Fined for processing children’s data without age checks or a lawful basis
Green Spark Energy and Home Improvement Marketing£250,000 and £300,000Fined for robocalls breaching regulation 19 of PECR

What the Data (Use and Access) Act 2025 changes

Sections 117 to 119 of the Data (Use and Access) Act 2025 change the regulator’s legal form and transfer its existing functions to the new body; on their own they do not alter what data protection law requires. The office has been a corporation sole since the Data Protection Act 1984 created the Data Protection Registrar (Schedule 2), a form the Data Protection Act 1998 continued when it renamed the office the Data Protection Commissioner and the Data Protection Act 2018 carried forward as the Information Commissioner. Section 117 inserts a new section 114A into the DPA 2018 to establish the Information Commission; section 118 abolishes the office of Information Commissioner; and section 119 transfers the functions. Schedule 14 sets out how the board is composed and run.

In place of one office-holder, the Commission will be a body corporate led by a chair, a chief executive and other executive and non-executive members with shared responsibility for decisions. The DUAA also gave the regulator, for the first time, a statutory principal objective: to secure an appropriate level of protection for personal data and to promote public trust and confidence in how personal data is used, while having regard to innovation and competition, the prevention of crime, public and national security, and the protection of children. The board will inherit that objective and the data protection framework as the DUAA has reshaped it, including the amended UK GDPR and DPA 2018 and the Privacy and Electronic Communications Regulations 2003. The reshaping is substantial: the DUAA added a recognised-legitimate-interests lawful basis, recast the rules on automated decision-making and strengthened the regulator’s enforcement powers, all set out in our guide to the Data (Use and Access) Act 2025. The reconstitution of the regulator is a separate strand: Parliament legislated for it, and the commencement of sections 118 and 119 waits on a separate order, which is why the regulator still described itself as the ICO throughout 2025/26.

The timetable is not open-ended, and the groundwork is largely done. The Act commences in stages: section 117 establishes the Commission as a body ahead of the transfer, and a later order brings sections 118 and 119 into force to abolish the office and move the functions across. Paul Arnold already serves as Interim Chief Executive Designate of the Information Commission, and the consequential and transitional Regulations were made on 26 March 2026, drafted to take effect the moment the transfer of functions is commenced. What remains is that commencement order, which the ICO expects during 2026/27.

The Oftel-to-Ofcom precedent

There is a close precedent for replacing a single regulatory office-holder with a board, and it comes from telecoms. When British Telecommunications was privatised, the Telecommunications Act 1984 created the office of Director General of Telecommunications, supported by the Office of Telecommunications, or Oftel. As with the Information Commissioner, the powers to license and to enforce were vested in one named person. That model held for almost twenty years. The Office of Communications Act 2002 then created Ofcom as a body corporate, and the Communications Act 2003 gave it its functions; Ofcom took full powers on 29 December 2003, when the Director General of Telecommunications and Oftel were abolished.

The parallel holds on the constitutional point but there was one big difference. Oftel becoming Ofcom was mainly a merger: five regulators, including Oftel, the Independent Television Commission, the Radio Authority, the Radiocommunications Agency and the Broadcasting Standards Commission, were folded into one converged body to deal with the convergence of telecoms and broadcasting. The move from a Director General of Telecommunications to a board came with that reorganisation rather than as its purpose. The ICO change carries no merger. The new Commission takes exactly the same functions the Commissioner holds today. What the two share is the core constitutional move, from powers held by one office-holder to powers exercised by a collective board, and the reasons a board is thought better: resilience against the loss of a single office-holder, and clearer independent accountability of the kind most other UK regulators, including Ofcom, the Financial Conduct Authority and the Competition and Markets Authority, already have.

FeatureOftel to OfcomCommissioner to Information Commission
Old formDirector General of Telecommunications (single office-holder)Information Commissioner (corporation sole)
New formOfcom, a body corporate with a boardInformation Commission, a statutory board
Governing statuteOffice of Communications Act 2002; Communications Act 2003Data (Use and Access) Act 2025, ss.117 to 119
Merger of regulatorsYes: five bodies combinedNo: same functions, same organisation
Main driverConvergence of telecoms and broadcastingGovernance resilience and independent accountability
Effective29 December 2003Expected during 2026/27

The corporate governance case for a board

The change is best understood as corporate governance. Today the Information Commissioner holds the regulator’s statutory powers personally, and the board of non-executive directors that sits alongside the office is, on the regulator’s own account, advisory only: the non-executives give counsel but do not exercise the functions. The Information Commission replaces that with a conventional statutory board, on which executive and non-executive members share responsibility for the regulator’s decisions. The non-executives move from advising an office-holder to governing the body. That is the standard corporate governance model for a UK regulator, and it is the model Parliament has chosen to bring data protection into line with Ofcom, the Financial Conduct Authority and the Competition and Markets Authority.

A board changes how the regulator works even where the law it enforces does not move. Accountability shifts from one person to several: under a corporation sole, responsibility for every reserved decision rests with the office-holder, whereas a board shares and minutes those decisions, with the chair and chief executive holding distinct roles. Resilience improves. The report is candid that the corporation sole model concentrates risk, because when the office-holder is unavailable the reserved functions pass to deputies under the scheme of delegation but the organisation still turns on a single appointment. The exercise of discretion changes too: data protection enforcement depends on judgement about which cases to take and how hard to press them, and a board spreads that judgement rather than leaving it with one person.

The report ties the change to John Edwards’s departure. He stepped back from his duties on 26 February 2026 to allow an independent workplace investigation relating to him; on 10 June 2026 that investigation concluded there was a case to answer, and he was found temporarily unable to act; he resigned on 19 June 2026. During that period the reserved functions passed to the Deputy Commissioners under Schedule 12 of the DPA 2018, and Paul Arnold, already Interim Chief Executive Designate of the Information Commission, took on the non-delegable responsibilities. In the Senior Independent Director’s report, the regulator states that the board model will make it easier to act in circumstances of that kind. Those are the facts as the report records them. A governance structure that carries a live continuity risk in a single appointment is one worth changing, and this is the year the regulator has said so in terms.

Enforcement in a transition year

While the constitution changed on paper, the enforcement record moved in a clear direction. The ICO imposed £33.848m in monetary penalties in 2025/26, against £4.426m the year before, and £18.259m of that is under appeal. The report attributes the shift to a transformation programme that has, in its words, modernised how it identifies and selects regulatory interventions, producing a more focused enforcement pipeline. Read alongside the figures, the pattern is fewer but larger actions, concentrated in the causes the regulator has named as priorities: children’s privacy, artificial intelligence and biometrics, and online tracking.

The two children’s-data fines are the largest single category, led by the Reddit penalty. The ICO fined Reddit £14,472,500 for failing to apply robust age assurance before processing the data of children under 13, and MediaLab £247,590 over its Imgur platform for the same class of failure. It fined 23andMe £2,310,000 for security failings under Articles 5(1)(f) and 32(1) of the UK GDPR, after a joint investigation with the Office of the Privacy Commissioner of Canada, following a cyber-attack that reached the data of more than 155,000 UK users. On nuisance marketing, it fined Green Spark Energy £250,000 and Home Improvement Marketing £300,000 for robocalls that breached regulation 19 of PECR. The same year carried the ICO’s enabling side: cookie-compliance action the ICO says brought 979 of the top 1,000 UK websites into line, a new AI and biometrics strategy, and a planned statutory code of practice on AI and automated decision-making, which the ICO says will give businesses a single set of rules. The regulator puts the economic value of its work at around £233m for UK businesses over five years.

What the change means for organisations

For most organisations the change of the regulator’s form does not move the day-to-day position when the Commission takes over. It alters no compliance obligation in itself: the guidance carries over, and existing decisions, notices and correspondence remain valid. A data controller with an open ICO matter does not need to restart it, and a UK data protection compliance programme runs against the DPA 2018, the UK GDPR and the DUAA amendments, not against the change of the regulator’s name. The one operational point to note is that references in older documents and contracts to the “Information Commissioner” will, in time, need to be read as references to the Information Commission; new templates can adopt the new name once the transfer of functions is commenced.

The enforcement signal matters more to most organisations than the change of name. A board-run regulator running a more focused pipeline is likely to keep concentrating its heaviest interventions where public and political salience is highest, which on this year’s evidence means children’s data, data security and online tracking. Organisations in those areas face selective but severe scrutiny. A quiet enforcement in-tray outside those priorities is not evidence of a soft posture: the same programme that produced the larger fines also decides which cases never get opened. Where an organisation is already dealing with the regulator, the shift from a single office-holder to a board makes little practical difference to how a case is run, though decisions on the largest matters will in future be board decisions. If you are responding to an information notice or an enquiry, our investigations and enforcement support page sets out the scope of that work.

Viewpoint

I worked in telecoms regulation through the Oftel era, and the move to Ofcom changed the regulator’s behaviour more than the legislation made it look. The form of a regulator shapes how it acts over time: a board argues before it decides and records why, which makes it steadier and harder to knock off course than a single office-holder. The Information Commission should, on the same logic, become a more predictable regulator, which is what the businesses I advise want most from it. The date to watch is the commencement of sections 118 and 119, which fixes when the transfer takes effect and when contracts and privacy notices need updating. The open question is whether the more focused enforcement approach continues once a board, not one Commissioner, is choosing the cases. The governance change is the headline, but for data controllers the enforcement posture is the part that will be felt first.

Frequently asked questions

What is the Information Commission?

The Information Commission is the new statutory board that will replace the Information Commissioner as the UK regulator for data protection and information rights. It is established by section 117 of the Data (Use and Access) Act 2025, which inserts section 114A into the Data Protection Act 2018. It will be a body corporate led by a chair, a chief executive and other members, and will hold the functions currently exercised by the Information Commissioner.

When does the Information Commission take over from the ICO?

The ICO expects the change during 2026/27. The abolition of the office of Information Commissioner and the transfer of functions in sections 118 and 119 of the Data (Use and Access) Act 2025 depend on a separate commencement instrument, which sets the effective date. Until then the regulator continues as the Information Commissioner’s Office.

How is the Information Commission like the Oftel-to-Ofcom change?

Both replace a single regulatory office-holder with a board. The Director General of Telecommunications, who ran Oftel under the Telecommunications Act 1984, was replaced by Ofcom, a body corporate, in December 2003. The difference is that Ofcom was a merger of five regulators driven by convergence, whereas the Information Commission takes the same functions and organisation as the ICO with no merger.

Does the change affect my data protection compliance?

Not directly. The move to a board does not itself change the law you must comply with, and existing guidance, decisions and notices carry over. The DUAA’s substantive reforms to data protection law are a separate matter. Over time, references to the “Information Commissioner” in contracts and privacy notices will need to be read as references to the Information Commission.

For advice on responding to an ICO enquiry, or on how the move to the Information Commission affects your data protection documentation, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts