The UK's data protection regulator is being remodelled. The Information Commissioner's Office, the ICO, is becoming the Information Commission, and its powers, staff and ongoing work transfer across to the new body.[1] [25] The change is expected to take shape during spring and summer 2026.
If you have ever found regulators confusing, here is the reassuring part: this is mostly about how the regulator runs itself, not about what it asks of you.
What is actually changing
The biggest change is at the top. For years the ICO was led by a single Information Commissioner. The Information Commission will instead be run by a board, with a chair, a chief executive and several independent directors.[25] That is the same shape as other big UK regulators, such as the financial and competition watchdogs.
The aim is clearer governance and more accountability, with decisions made by a board rather than resting on one office-holder.[25]
What is staying the same
Your obligations do not change because the regulator changed its structure. The same data protection law applies. The same complaints duty starts on 19 June 2026. The same rules on cookies, marketing and people's rights stay in force.
If you receive letters, guidance or enforcement notices, expect the name and branding to shift over time from "ICO" to "Information Commission". The substance behind them carries on.
What this means for you
Practically, almost nothing for you to do.
It is worth a small awareness check. Make sure your privacy notice and any complaints information point people to the right regulator over time, and do not be thrown when the name on official guidance changes. If you have bookmarks or templates that name the "Information Commissioner's Office", note that they may need a light update later in the year.
Beyond that, the best response to a stronger, better-governed regulator is the same as before: keep your own data protection basics in good order.