Analyzing critical legal trends and developments across data, cyber, AI and digital regulations from around the world and beyond borders

The transition from the office of the Information Commissioner to the new Information Commission under the Data (Use and Access) Act 2025 (“DUAA”) is due to take effect from 30 September 2026. In addition, the ICO outlined its priorities for the next two years through its draft corporate strategy which was published in July 2026.

The draft corporate strategy is intended to bridge the gap between the ICO’s existing strategy (ICO25) and the first strategy to be adopted by the new Information Commission governance model.

What is the ICO’s new governance model?

On 10 September 2026, the Government published The Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026, which brings Sections 118 and 119 of DUAA into force from 30 September 2026. These sections abolish the office of the Information Commissioner and transfer its functions to the new Information Commission. Under this new governance model, the Information Commission is made up of a Board, Chair and CEO.

In July 2026, seven Non-Executive members were appointed to the future Information Commission Board, ahead of the regulator’s move from a single-commissioner model to a new structure on 30 September 2026. The Chair of the Information Commission, who will lead the Board and oversee its strategic direction (alongside the Chief Executive), is yet to be announced.

Although the office of the Information Commissioner will no longer exist, the ICO has confirmed it will continue to operate under the familiar “ICO” acronym as the Information Commission’s Office.

What are the ICO’s priorities going forward?

In the draft corporate strategy, the ICO has identified four principal regulatory priorities:

  • Children’s data:ensuring children’s personal data is used responsibly, and that digital and education technology services build privacy protections into their design.
  • AI:promoting trust and transparency in AI by setting clear expectations for the responsible use of personal data.
  • Public services:improving how public services use and protect personal data to build trust and support digital transformation.
  • Cyber resilience: strengthening organisations’ protection of personal data against cyber threats and reducing the impact of data breaches.

The strategy also sets out plans to modernise the ICO’s own operations, including by streamlining customer services and making greater use of AI and automation. The transition to the new Information Commission board is also intended to strengthen decision-making, accountability and organisational capability.

What does this mean for organisations?

Although the corporate strategy is currently in draft form following a period of public consultation, it provides a clear indication of the ICO’s intended areas of regulatory focus, which are broadly in line with areas the ICO has been focused on in recent times.

Therefore, organisations should expect continued attention on children’s privacy, AI governance, cyber resilience and responsible data use, particularly in the context of public-sector transformation and complex data-sharing arrangements.

The move to the Information Commission also represents a significant change to the regulator’s governance structure. While the reforms do not themselves create new compliance obligations for organisations, they form part of a broader shift towards a more targeted, risk-based and technologically enabled approach to regulation.

Author

Ben advises clients in a wide range of industry sectors, focusing in particular on data protection compliance, including healthcare, financial services, adtech, video games, consumer and business-to-business organisations. Ben regularly assists clients with global data protection compliance projects and assessments as well as specific data protection challenges such as international transfers and data security breaches. Ben is also regularly involved in drafting and negotiating data protection clauses in agreements for various clients in a wide range of industry sectors. Ben also regularly advises clients on electronic direct marketing and cookies.

Author

Vin leads our London Data Privacy practice and is also a member of our Global Privacy & Security Leadership team bringing his vast experience in this specialist area for over 22 years, advising clients from various data-rich sectors including retail, financial services/fin-tech, life sciences, healthcare, proptech and technology platforms.

Author

Author

Adele is a partner in Baker McKenzie's London office.