ICO governance changes confirmed for 30 September 2026
30 September 2026
30 September 2026 marks the date when new governance arrangements for the ICO come into force, as mandated by the Data (Use and Access) Act 2025. This legislative change impacts the internal structure and oversight of the UK's primary data protection regulator, requiring preparatory work within the ICO itself.
The Data (Use and Access) Act 2025 introduces significant changes to the governance of the ICO, which must be fully implemented by 30 September 2026. This involves a restructuring of the Commissioner's role and the establishment of new oversight mechanisms within the organisation. The ICO's internal legal and operational teams are responsible for ensuring compliance with these statutory requirements.
Organisations should recognise that while the ICO's internal governance is changing, its regulatory functions and powers concerning data protection remain consistent. Controllers and processors will continue to engage with the ICO under the existing frameworks, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The work preceding this deadline is internal to the ICO, focusing on administrative and structural adjustments rather than new obligations for external entities.
Evidence of compliance for the ICO would include updated internal policies, revised organisational charts, and documentation detailing the new decision making processes and accountability structures. This internal transformation ensures the regulator operates effectively under its new statutory mandate.
Data (Use and Access) Act 2025 sets 30 September 2026 as the point of effect, and the preparation it requires sits with teams who are measured on other work, which is why this date slips rather than the obligation being misread.
Data (Use and Access) Act 2025
- Who this binds
- The ICO
- What changed
- Nothing changed today. What is fixed is the date the obligation begins to apply: 30 September 2026, when the ICO will transition to the Information Commission, altering its governance structure but maintaining existing regulatory functions.
- What to check
- No direct action required for controllers and processors, as regulatory functions remain unchanged.
- What this does not mean
- This is a date in the diary, not a new obligation published today. Nothing in force changed this morning.
Send this to your team
The ICO will undergo significant governance changes by 30 September 2026, as mandated by the Data (Use and Access) Act 2025, though its regulatory functions for external organisations remain unchanged.