Last Wednesday, 30 September 2026, the office of the Information Commissioner was abolished. No case was dropped and no notice lapsed. From the start of that day the regulator that had spent forty-two years as a single person holding statutory powers became a body corporate called the Information Commission, run by a board, and carried on. Two days earlier, on Monday 28 September, the same organisation had moved its head office from Wycliffe House in Wilmslow, where it had sat since the Data Protection Registrar first opened for business in the 1980s, to the fourth floor of a new building on Oxford Road in Manchester.
I have spent a good part of the last decade on the other side of the table from this regulator, as a data protection officer for clients, as the person drafting the breach notification at two in the morning, and occasionally as the person explaining to a board why the letter on the table did not mean what they feared it meant. So I read last week's announcements with more than passing interest. This piece sets out what has actually changed in law, what has changed in practice, what has not changed at all, and the one detail that I think deserves more attention than it has had: the new Commission has started life without the one officer the legislation assumed it would have.
What the Act did
The reorganisation comes from Part 6 of the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025. Section 117 establishes the Information Commission as a body corporate and, through Schedule 14, inserts a new Schedule 12A into the Data Protection Act 2018 to govern it. Section 118 abolishes the office of Information Commissioner. Section 119 transfers the Commissioner's functions to the Commission, and section 120 lets the Secretary of State make a scheme moving the property, rights and liabilities across.
The establishing provision was switched on in August 2025 so that the new body could be built in the background, and the transfer-scheme power followed in February 2026. The abolition and the transfer of functions waited until the Commencement No. 9 Regulations, made on 10 September 2026, which brought sections 118 and 119 into force on 30 September. Regulation 3 of that instrument is the clause that matters to anyone with an open matter: anything done, or in the process of being done, by or in relation to the Information Commissioner is to be treated as done by or in relation to the Information Commission. A monetary penalty notice issued in Wilmslow in August under the old name is as enforceable this morning as it was then. A reprimand stands. An investigation continues. Legal proceedings carry on with the party's name changed and nothing else.
What the Act did not do is change the regulator's powers. The ICO was careful to say so in its 15 September notice: the transition "makes changes to the governance structure of our organisation, while maintaining existing regulatory functions and responsibilities." The UK GDPR, the Data Protection Act 2018, the Freedom of Information Act 2000 and the Privacy and Electronic Communications Regulations are unchanged by Wednesday's event. Every reference in every statute, contract and privacy notice to "the Information Commissioner" now reads across to the Commission by operation of law, so there is nothing you must rush to amend.
From one person to a board
The substantive change is the one that sounds administrative. Since 1984 the regulator has been a corporation sole: a single office-holder in whom all the statutory powers were vested personally. Every fine, every enforcement notice and every decision to walk away from a complaint was, legally, the act of one individual, however many hundreds of staff advised them. That was the model for the Data Protection Registrar, the Data Protection Commissioner and then the Information Commissioner, and it was increasingly out of step with the rest of the British regulatory landscape. Ofcom, the Financial Conduct Authority and the Competition and Markets Authority are all boards.
Schedule 14 to the Act sets out the new shape. The Commission is to have a chair appointed by the King by Letters Patent on the recommendation of the Secretary of State, for a single non-renewable term of up to seven years, removable only by an Address of both Houses. It is to have a chief executive appointed by the non-executive members, and other executive members appointed by the non-executives after consulting the chief executive. The Secretary of State sets the total size between three and fourteen, and the non-executives must always outnumber the executives. Appointments are to be on merit after fair and open competition, and the Secretary of State must be satisfied there is no conflict of interest before recommending a chair or appointing a non-executive.
That design has a consequence that is easy to miss. Decisions about the strategic direction of the regulator, and ultimately about how its enforcement powers are deployed, are now collective. The ICO's own description of the board says its role is to "make collective decisions about the strategic direction and performance of the Information Commission's Office (ICO)" and to ensure "effective arrangements are in place to provide assurance on governance, risk management and internal control." How much of the day-to-day casework the board delegates to the executive is governed by a Scheme of Delegations, and I would expect the practical answer to be nearly all of it. But the days when a regulated organisation's fate turned on the judgement of one named official are over, and the days when a minister could change the regulator's direction simply by changing the Commissioner are over too.
The seven non-executive members were announced on 15 July 2026: Laurie Benson, Maggie Carver, Stephen Cohen, Sukhvinder Kaur-Stubbs, Gary Kildare, Hilary Newiss and Scott McPherson. PublicTechnology's report of the appointments gives initial three-year terms, and the ICO's board page gives the backgrounds: a former Ofcom deputy chair, a former director general in four Whitehall departments, a former member of IBM's global leadership team, a board member of the Regulator of Social Housing, a former law-firm partner, a media executive and an asset-management investor. It is a governance board, in other words, rather than a bench of data protection specialists, which is what the Act intended. The specialists are the staff.
The chair the Act expected
Here is the detail I think matters most. Schedule 14 contains a transitional provision that was written with a clear sequence of events in mind. When the Schedule commenced in August 2025 the sitting Information Commissioner was treated as having been appointed the first chair of the Commission, for a term expiring when his original appointment would have ended, and it fell to that first chair to appoint the first chief executive. The chief executive's own appointment was to be for no more than two years, and the statute itself gives the post-holder the label "the interim chief executive" for that term. The idea was that the new body would be born with the old officer at the top of it, and that when the functions finally transferred the chair would already be a year into the job.
Events overtook the design. John Edwards, who took office as Information Commissioner in January 2022 and duly became the Commission's first chair in August 2025, stepped back from his duties on 26 February 2026 while an independent workplace investigation was carried out, and on 19 June 2026 he resigned from both posts with immediate effect. His own statement was unusually direct: "Since February of this year I have been the subject of an investigation. While I have not agreed with how that investigation has been conducted, I accept that my position has become untenable." He acknowledged attempts at humour that were, in his words, inappropriate and caused offence. No Commissioner in the office's forty-two-year history had previously left in those circumstances.
The consequence is that the Information Commission took over its functions on 30 September with no chair. The Department for Science, Innovation and Technology opened a recruitment campaign in July, with applications closing on 19 August; after the machinery-of-government changes later that month the ICO's sponsorship, and the recruitment, passed to the Department for Digital, Culture, Media and Sport, and the ICO's launch-day release says the process is expected to conclude in spring 2027. In the meantime the board has appointed Maggie Carver as Deputy Chair to carry out the chair's responsibilities. She is well qualified for a holding role of this kind, having been interim chair of Ofcom from January 2021 to April 2022 and its deputy chair until 2024, and having chaired ITN and the British Board of Film Classification. Her comment on launch day was measured: "The new Board looks forward to supporting Paul and the executive of the ICO through this exciting time in its development."
The Paul in question is Paul Arnold, previously Deputy Commissioner and Chief Executive, who has carried the Commissioner's non-delegable duties since Mr Edwards stepped back in February, and who holds the statutory first chief executive post that the Act calls interim, with the Accounting Officer role alongside it. So the new regulator begins with a deputy standing in for a chair who has yet to be appointed, and a chief executive whose two-year term is time-limited by design. Only the first of those is a consequence of events, and I would rather see the chair appointed carefully than quickly. Mr Arnold's own framing on the day was that "Today is the beginning of an important new chapter for our organisation. As the Information Commission, we are building on more than four decades of experience while strengthening how we are governed and led." The Digital Government Minister, Stephanie Peacock, said the Commission "will continue to provide strong, independent oversight of data protection, while bringing together a range of expertise to ensure the regulator remains equipped to respond to future challenges and opportunities in a fast-changing digital world."
Still the ICO
One thing has not changed, by deliberate choice. The organisation will continue to call itself the ICO. The initials now stand for the Information Commission's Office rather than the Information Commissioner's Office, a sleight of hand that preserves four decades of brand recognition at the cost of an apostrophe moving one letter to the left. The ICO said as much in September: "As the Information Commission's Office, we will continue to be known as the ICO." The website is still ico.org.uk, the casework teams are the same people, and the letters you receive will look very much as they did.
I think this was the right call. Small organisations, which make up the overwhelming majority of the UK's data controllers, know what the ICO is. Very few of them could tell you the difference between a corporation sole and a body corporate, and nor should they need to. What they need is for the data protection fee to be paid to the same place, the breach report to go to the same form, and the guidance to stay where they bookmarked it.
Manchester
The second announcement of the week is the one that has drawn the local headlines. The ICO's head office has been at Wycliffe House on Water Lane in Wilmslow, Cheshire, for its entire existence. The move to Manchester was announced in June 2025, with the Circle Square development on Oxford Road chosen, in the ICO's words, for its proximity to the universities and to other organisations working in data and digital, and to help the regulator attract a more diverse workforce. The new postal address, effective from 28 September 2026, is ICO Head Office, 4th Floor, No.3 Circle Square, 5 Hawkshaw Street, Manchester, M1 7BL. If you have the Wilmslow address hard-coded in a privacy notice, a data processing agreement or a breach response runbook, that is the one thing from last week that does merit a correction, though the ICO said in June 2025 that it would keep a small presence in the Wilmslow area beyond 2026, and I would expect post to find its way for some time.
I understand the attraction of Oxford Road. The corridor between the University of Manchester, Manchester Metropolitan and the hospitals is one of the densest concentrations of data science, health informatics and computer security research in the country, and a regulator that needs to recruit people who understand machine learning and modern engineering is better placed there than in a Cheshire commuter town. The ICO has struggled for years, as every public body has, to hire and retain technical staff against private-sector salaries. Being a short walk from several thousand graduates every summer will not solve that, but it will help.
What this means on a Monday morning
For most of the organisations I work with, the honest answer is that nothing changes this week. Your obligations under the UK GDPR are the same. The seventy-two-hour clock on a reportable breach is the same. The fees are the same. Your DPO still reports to the same regulator through the same portal. If you were in the middle of a complaint, an audit or an enforcement matter, regulation 3 of the commencement order means it continues as if nothing had happened.
There are three small pieces of housekeeping. First, where documents name "the Information Commissioner" as a recipient of notifications or as the supervisory authority, they remain legally effective as they stand, but the next time they come up for review you should change the wording to "the Information Commission" and the address to Manchester. Second, if your records of processing or your supplier contracts include the Wilmslow postal address, update it at the same time. Third, if your incident response plan has a named contact or a specific phone line at the ICO, test it; organisations in the middle of a relocation do not always carry every extension across.
The more interesting question is the medium-term one, and I will put it plainly. The transition to the Commission did not change the regulator's powers, but the same Act did, and those changes have been arriving quietly over the past eight months. Since 5 February 2026 the regulator has had the power to issue interview notices requiring the people who run a controller or processor to attend and answer questions, with safeguards for privilege and self-incrimination. From the same date the enforcement regime for PECR, which governs marketing calls, texts, emails and cookies, was aligned with the Data Protection Act 2018, bringing nuisance marketing within reach of the same penalty ceilings as data protection breaches rather than the old £500,000 cap. Since August 2025 the regulator has had a statutory principal objective: to secure an appropriate level of protection for personal data and to promote public trust and confidence in its processing, alongside duties to have regard to innovation, competition, crime prevention, national security and the particular protection of children.
A board-led regulator with those powers and that mandate behaves differently from a single Commissioner, and I would expect the difference to show first in strategy rather than in casework. The ICO's launch-day release says the Commission's forthcoming corporate strategy will concentrate on artificial intelligence, cyber resilience, children's privacy and public services, and The Register picked out the same four. None of those will surprise anyone who has read the ICO's output over the past two years, but a board that has collectively signed off on them is a board that will ask the executive, in six months, what has been done about them. Expect the regulator to be more consistent, more predictable, and somewhat harder to argue out of a position once it has taken one.
For boards
Three questions for the next meeting: Do our privacy notices, processing agreements and breach runbook still name the Information Commissioner and a Wilmslow address, and who owns bringing them up to date at the next review? If the regulator served an interview notice tomorrow on the director responsible for data, would that person know what it was, what their rights were, and who to call before answering? Given that the regulator's stated priorities are AI, cyber resilience and children's data, which of those three touches our processing, and when did we last look at it with the same seriousness the regulator now says it will?
The closing observation
I have watched the Information Commissioner's Office from the outside for most of its life, and from across the table for a good part of mine. It has been, at its best, a regulator that preferred to educate before it punished and that reserved its heaviest penalties for organisations that had been warned and had not listened. The move to a board, and the move to Manchester, were both conceived as ways of making that organisation stronger: better governed, better located, better able to hire the people it needs. The irony of the first week is that the design assumed a continuity of leadership that events took away, and the new body has begun with the chair's seat empty and a deputy keeping it warm.
I do not think that undermines the reform. If anything it makes the case for it. A regulator that could be destabilised by the departure of one individual was precisely the problem a board was meant to solve, and the fact that the ICO's casework carried on through February, June and September without interruption suggests the institution is already stronger than the office it replaced. The chair will be appointed. The strategy will be published. And in the meantime the regulator you deal with is the same one you dealt with last month, with a new name on the door and a better view.
This article is commentary, not legal advice. The statutory references are to the Data (Use and Access) Act 2025 and the Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026, SI 2026/1015, as published on legislation.gov.uk on 5 October 2026.