The transition from the office of the Information Commissioner to the new Information Commission under the Data (Use and Access) Act 2025 (“DUAA”) is due to take effect from 30 September 2026. In addition, the ICO outlined its priorities for the next two years through its draft corporate strategy which was published in July 2026.
The draft corporate strategy is intended to bridge the gap between the ICO’s existing strategy (ICO25) and the first strategy to be adopted by the new Information Commission governance model.
What is the ICO’s new governance model?
On 10 September 2026, the Government published The Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026, which brings Sections 118 and 119 of DUAA into force from 30 September 2026. These sections abolish the office of the Information Commissioner and transfer its functions to the new Information Commission. Under this new governance model, the Information Commission is made up of a Board, Chair and CEO.
In July 2026, seven Non-Executive members were appointed to the future Information Commission Board, ahead of the regulator’s move from a single-commissioner model to a new structure on 30 September 2026. The Chair of the Information Commission, who will lead the Board and oversee its strategic direction (alongside the Chief Executive), is yet to be announced.
Although the office of the Information Commissioner will no longer exist, the ICO has confirmed it will continue to operate under the familiar “ICO” acronym as the Information Commission’s Office.
What are the ICO’s priorities going forward?
In the draft corporate strategy, the ICO has identified four principal regulatory priorities:
- Children’s data:ensuring children’s personal data is used responsibly, and that digital and education technology services build privacy protections into their design.
- AI:promoting trust and transparency in AI by setting clear expectations for the responsible use of personal data.
- Public services:improving how public services use and protect personal data to build trust and support digital transformation.
- Cyber resilience: strengthening organisations’ protection of personal data against cyber threats and reducing the impact of data breaches.
The strategy also sets out plans to modernise the ICO’s own operations, including by streamlining customer services and making greater use of AI and automation. The transition to the new Information Commission board is also intended to strengthen decision-making, accountability and organisational capability.
What does this mean for organisations?
Although the corporate strategy is currently in draft form following a period of public consultation, it provides a clear indication of the ICO’s intended areas of regulatory focus, which are broadly in line with areas the ICO has been focused on in recent times.
Therefore, organisations should expect continued attention on children’s privacy, AI governance, cyber resilience and responsible data use, particularly in the context of public-sector transformation and complex data-sharing arrangements.
The move to the Information Commission also represents a significant change to the regulator’s governance structure. While the reforms do not themselves create new compliance obligations for organisations, they form part of a broader shift towards a more targeted, risk-based and technologically enabled approach to regulation.