Summary
- The Data (Use and Access) Act has replaced the Information Commissioner corporation sole with the Information Commission, governed through a collective board.
- Seven non-executive members have taken office, with Maggie Carver serving as Deputy Chair while government recruits a permanent Chair.
- The regulator says its legal restructuring does not alter its core duties, while its next strategy will concentrate on areas including AI, cyber resilience, children’s privacy, and public services.
Britain’s data regulator has changed the legal structure through which some of the country’s most consequential technology decisions are overseen, moving from a single Information Commissioner to a collective board without changing the ICO name used by organisations and the public.
The Information Commissioner’s Office formally transitioned on Wednesday into the Information Commission under governance reforms contained in the Data (Use and Access) Act 2025. The legal entity is now the Information Commission, while the operating organisation will continue to call itself the Information Commission’s Office, or ICO.
The structural change replaces a corporation sole, in which legal authority sat with the Information Commissioner, with collective board governance. Seven non-executive members have assumed their positions alongside the executive leadership, with the board intended to provide additional scrutiny, challenge, expertise, and accountability.
Maggie Carver has been appointed Deputy Chair and will carry out the responsibilities of Chair while the Department for Digital, Culture, Media and Sport recruits a permanent appointee. That recruitment process is expected to conclude in spring 2027, while Paul Arnold continues as chief executive of the Information Commission.
The regulator’s functions continue through the change
The new structure does not by itself rewrite the regulator’s core responsibilities. The Information Commission remains responsible for data-protection regulation, freedom-of-information oversight, guidance, complaints, enforcement, advice, and other public services, while organisations will continue dealing with an authority that presents itself externally as the ICO.
That continuity is important because the transition follows a broader period of change in UK data law. Provisions of the Data (Use and Access) Act came into force in stages between June 2025 and June 2026, amending parts of the legal framework around data protection and digital information before the regulator’s governance structure changed this month.
For businesses, the practical effect of Wednesday’s transition is therefore more institutional than procedural. Existing obligations do not disappear because the regulator now has a board, enforcement cases do not reset, and organisations should not expect established data-protection responsibilities to be suspended while the Commission settles into its new governance model.
Recent enforcement illustrates that continuity. The regulator has continued pursuing privacy, direct-marketing, and information-rights cases during the transition, while TikTok’s withdrawal of appeals over children’s privacy this week left a £12.7 million UK data-protection fine standing.
Collective governance broadens scrutiny
Moving to a board changes where strategic challenge is expected to come from inside the regulator. Under the former model, the Information Commissioner was the statutory corporation sole; the Commission now distributes governance across an executive organisation and a board containing non-executive members with different professional backgrounds.
That does not make regulatory decisions automatically stronger or more independent, but it creates a more conventional institutional model for scrutinising priorities, management, performance, and strategy. The board can challenge executives and bring perspectives that would previously have had to be assembled around a single statutory officeholder through other advisory and governance mechanisms.
The arrangement may become particularly relevant as data regulation extends into areas where legal interpretation, technology, competition, security, and public policy overlap. Artificial intelligence systems can involve data-protection questions at training, deployment, monitoring, and decision-making stages, while cyber incidents can quickly become regulatory matters when personal information is exposed.
The ICO says its forthcoming corporate strategy will concentrate attention on AI, cyber resilience, children’s privacy, and public services among other areas. Those priorities put the regulator directly into technology debates in which government simultaneously wants stronger public protections, greater digital adoption, and economic growth.
Manchester becomes the regulator’s headquarters
The governance transition coincides with the opening of the Information Commission’s new headquarters on Oxford Road in Manchester. The regulator says the move will provide access to a broader talent pool and strengthen relationships with organisations and communities outside London.
The location also gives the change a practical workforce dimension. Regulators dealing with AI, cybersecurity, digital identity, and data-intensive public services increasingly compete with technology businesses, professional-services companies, and other public bodies for staff who understand both technical systems and regulatory obligations.
Placing headquarters in Manchester will not solve that recruitment problem on its own, although it puts the ICO inside one of the UK’s larger technology and digital clusters rather than treating national regulation as an exclusively London-centred operation.
The more substantial test will come from how collective governance changes regulatory behaviour. A larger board can introduce more expertise and challenge, but governance reform only produces value when responsibilities remain clear enough for decisions to be made without replacing one concentrated authority with slower internal process.
Organisations regulated by the ICO should therefore see little immediate change in the forms, guidance, investigations, and enforcement machinery they encounter. Over time, however, the board will influence which problems receive attention, how the regulator balances innovation against rights, and how consistently it handles technologies that cross several regulatory categories at once.
The Information Commission begins with the same public-facing initials and most of the same regulatory work, but the institution behind those initials is now different. As data regulation becomes more intertwined with AI deployment, cyber resilience, and digital public services, the success of the new structure will rest on whether broader governance makes difficult decisions more robust without making the regulator harder to move.












