All you need to know about the changes at the ICO

If your responsibilities include data protection, you’re probably no doubt aware that the UK regulator is moving to a new structure and new name.

It’s been a long time coming, with data infractions and breaches now occurring on a regular basis. Indeed, data protection has fast become one of the most important business operational challenges, and its societal impact is now squarely on the political agenda.

So what’s happening on the September 30?
The office of the Information Commissioner will be abolished and its functions will transfer to the Information Commission, following changes introduced by the Data (Use & Access) Act 2025. It is far more than just a change of name because the regulator itself is moving to a new statutory, ie, legal, body.

Here’s what you need to know:

– The bigger change is the Commission’s structure. Regulation is moving from a model centred on a single Information Commissioner to a board-led Information Commission, giving the regulator a broader leadership structure.

– AI, children’s privacy, cyber resilience and public trust in the use of personal data will be firm priorities.

AI is particularly relevant because adoption is now accelerating rapidly across most business sectors. It isn’t about putting the brakes on AI either, but knowing which AI systems are being used, what personal data is going into them, what happens to that information and whether a business can explain the decisions being made.

For British businesses, there is no sudden change to your data protection obligations. UK GDPR continues to apply and the Information Commission takes over the regulatory work currently carried out by the Information Commissioner. Moreover, existing complaints and investigations already underway will continue through the transition.

Furthermore, there was an important clarification from the ICO on September 15 that despite the change, it will continue to be known as the ICO.

Finally, make sure your company board knows about the change, particularly if data protection only reaches them when there is a complaint, breach or major project requiring a decision. They probably won’t need an in-depth briefing on the legislation, but they should know about it.

It is a relatively simple transition for most companies, provided somebody notices it is happening.

Andy Chesterman is managing director of Privacy Helper

Be the first to comment on "All you need to know about the changes at the ICO"

Leave a comment