A New UK Regulator - Data Protection
On 30 September 2026 the Information Commissioner's Office ceased to exist. Its functions passed to the Information Commission under the Data (Use and Access) Act 2025.
In the same fortnight, Europe's data protection regulators adopted guidance that makes a fine the expected outcome for any infringement that is not minor. And the Irish regulator fined Google €403m over location data.
One is a change of structure. The other two are a change of mood. Businesses should pay attention to both.
What changed on 30 September
The old ICO was a "corporation sole": its powers sat with one person, the Information Commissioner. The new Information Commission is a board. It has seven non-executive members, appointed in July, and Paul Arnold as interim Chief Executive.
What it does not have is a Chair. That role was meant for the Information Commissioner, and since John Edwards resigned in June there has not been one. Recruitment continues. So the UK's data regulator began its new life fully governed, save for the person meant to govern it.
The powers themselves are unchanged. So is the familiar name: it will still be known as the ICO, which now stands for the Information Commission's Office.
Do you need to update your documents?
Not urgently. The Act provides that references to the Information Commissioner in legislation and documents are to be read as references to the Information Commission. Nothing in your privacy notice, DPA or breach playbook became wrong overnight.
But "not urgently" is not "never". At your next scheduled review:
• Update privacy notices and DPAs to name the Information Commission.
• Check your breach playbook points to current reporting routes and contact details.
• Brief whoever makes the 72-hour call. The name on the form should not be the thing that slows them down.
Why a board matters more than a name
A regulator run by one person moves at the pace and priorities of that person. A regulator run by a board with collective responsibility tends to move more predictably, and to document why it acted.
For businesses, that should mean clearer reasoning behind enforcement decisions. Whether it means more enforcement will depend on the Chair who has not yet been appointed.
Meanwhile in Europe: a presumption in favour of fines
On 21 September the European Data Protection Board adopted guidelines on when supervisory authorities should impose a fine at all. They set out five steps. One sentence matters most: if the infringement is not minor, there is a strong presumption that a fine will follow. The consultation closes on 13 November 2026.
For years the reprimand was the regulator's raised eyebrow. A stern letter, an undertaking, a promise to do better. The eyebrow is being retired.
The same day, the Data Protection Commission in Ireland fined Google Ireland €403m over location data collected through Web & App Activity, Location History and Location Accuracy, from the start of GDPR until February 2020. The findings covered lawfulness, fairness, transparency, accountability and retention: very nearly the full set. Google has six months to put it right.
What this means if you trade into the EU
The UK regime is not bound by EDPB guidelines. But any business processing EU personal data, or with an EU establishment, now faces regulators encouraged to start from a fine rather than end at one.
Three practical steps:
Know which of your processing would not look "minor". Location data, children's data, special category data and anything used to train AI are the obvious candidates.
Fix the paperwork gaps that turn a mistake into a finding. Records of processing, lawful basis assessments and retention schedules are what regulators ask for first.
Read the EDPB draft before 13 November. If you have a view, the consultation is the cheapest moment to share it.
Frequently Asked Questions
-
Yes, in name. The Information Commissioner's Office became the Information Commission on 30 September 2026, but it continues to use the ICO name, now standing for the Information Commission's Office. Its powers are unchanged.
-
No. The Data (Use and Access) Act 2025 treats references to the Information Commissioner as references to the Information Commission. Update your documents at the next routine review.
-
No. It applies to EU supervisory authorities. UK businesses that process EU personal data or have an EU establishment should still take it seriously.
If you want a quick, fixed-fee check that your privacy documents and breach process are ready for both regimes, book a discovery call.
RMOK Legal. We Look After It.

