Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

ICO governance changes confirmed for 30 September 2026

30 September 2026

30 September 2026 marks the date when new governance arrangements for the ICO come into force, as mandated by the Data (Use and Access) Act 2025. This legislative change impacts the internal structure and oversight of the UK's primary data protection regulator, requiring preparatory work within the ICO itself.

The Data (Use and Access) Act 2025 introduces significant changes to the governance of the ICO, which must be fully implemented by 30 September 2026. This involves a restructuring of the Commissioner's role and the establishment of new oversight mechanisms within the organisation. The ICO's internal legal and operational teams are responsible for ensuring compliance with these statutory requirements.

Organisations should recognise that while the ICO's internal governance is changing, its regulatory functions and powers concerning data protection remain consistent. Controllers and processors will continue to engage with the ICO under the existing frameworks, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The work preceding this deadline is internal to the ICO, focusing on administrative and structural adjustments rather than new obligations for external entities.

Evidence of compliance for the ICO would include updated internal policies, revised organisational charts, and documentation detailing the new decision making processes and accountability structures. This internal transformation ensures the regulator operates effectively under its new statutory mandate.

Data (Use and Access) Act 2025 sets 30 September 2026 as the point of effect, and the preparation it requires sits with teams who are measured on other work, which is why this date slips rather than the obligation being misread.

Data (Use and Access) Act 2025

Who this binds
The ICO
What changed
Nothing changed today. What is fixed is the date the obligation begins to apply: 30 September 2026, when the ICO will transition to the Information Commission, altering its governance structure but maintaining existing regulatory functions.
What to check
No direct action required for controllers and processors, as regulatory functions remain unchanged.
What this does not mean
This is a date in the diary, not a new obligation published today. Nothing in force changed this morning.

Send this to your team

The ICO will undergo significant governance changes by 30 September 2026, as mandated by the Data (Use and Access) Act 2025, though its regulatory functions for external organisations remain unchanged.

Today's question

An organisation is reviewing the impact of recent legislative changes on data protection compliance. They note that the Data (Use and Access) Act 2025 mandates new governance arrangements for the ICO, effective 30 September 2026. What is the primary implication of these changes for external controllers and processors?

  1. Controllers and processors will continue to engage with the ICO under existing frameworks, as regulatory functions remain consistent.
  2. Controllers and processors must prepare for new data processing obligations introduced by the Data (Use and Access) Act 2025.
  3. Controllers and processors will need to update their internal policies to align with the ICO's new governance structure.
  4. Controllers and processors should anticipate a change in the ICO's enforcement powers regarding the UK GDPR and Data Protection Act 2018.

Answer this question on the site

Worth knowing

  1. Italy establishes national AI regulatory architecture to operationalise the EU AI Act

    Organisations deploying AI systems in Italy must familiarise themselves with Law No. 132 and Legislative Decree No. 160, as these national laws provide specific rules, governance models, and sanctions for AI use.

  2. NZ Privacy Commissioner issues Compliance Notices to Manage My Health and Health NZ

    Organisations handling health information in New Zealand must ensure their data processing practices, from collection to disclosure, strictly adhere to all principles of the Privacy Act 2020 to avoid compliance notices and potential enforcement.

  3. EDPB publishes Guidelines 3/2025 on the interplay between the DSA and the GDPR

    Digital service providers and online platforms operating in the EU must review the EDPB's Guidelines 3/2025 to understand their overlapping obligations under the DSA and the GDPR, ensuring a harmonised compliance approach.

  4. Vasindas’ Around the Clock Care Settles Data Breach Litigation

    The settlement by Vasindas’ Around the Clock Care demonstrates the financial liability healthcare providers face from data breaches, even without regulatory enforcement.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.