ICO confirms transition to Information Commission on 30 September 2026
The UK Government has confirmed that the Information Commissioner’s Office will transition to the Information Commission on 30 September 2026, marking a formal change to the regulator’s governance structure while keeping its current regulatory role in place.
The change follows the Data (Use and Access) Act 2025, which introduces a new governance model for the organisation. The ICO has confirmed that its existing functions and responsibilities will continue through the transition.
The move also follows the July announcement of seven Non-Executive Members appointed to the new Information Commission Board. Those members will take up their roles on 30 September 2026.
Although the organisation’s governance structure is changing, its public identity will remain familiar. As the Information Commission’s Office, it will continue to be known as the ICO.
What has been confirmed
The Government’s confirmation sets a clear date for the change. On 30 September 2026, the Information Commissioner’s Office will transition to the Information Commission.
The transition is not a change in the regulator’s purpose. It is a change to how the organisation is governed.
The ICO has said the new arrangements come from the Data (Use and Access) Act 2025. That Act makes changes to the organisation’s governance structure, while maintaining its current regulatory functions and responsibilities.
For organisations, public authorities, data protection professionals and members of the public who interact with the ICO, the key point is continuity. The regulator’s work will continue during and after the transition.
That means the organisation will remain responsible for the areas people already associate with it, including information rights regulation and data protection oversight. The announcement does not suggest a pause in services, a transfer of responsibilities to another regulator, or a change in how people should recognise the ICO.
The confirmed date now gives stakeholders a clear timeframe. The period between the announcement and 30 September 2026 will be used to manage the move to the new governance model.
Why the organisation is changing
The transition is a result of the Data (Use and Access) Act 2025. The Act changes the way the organisation is structured at governance level.
In simple terms, the reform moves the organisation from a model centred on the Information Commissioner to a commission model. A commission structure usually places formal governance responsibility with a board, rather than with a single office-holder alone.
The ICO’s announcement focuses on governance rather than policy. It does not frame the transition as a change to the regulator’s day-to-day duties. Instead, it confirms that the current responsibilities will remain in place while the internal governance model changes.
This distinction matters. Governance affects how an organisation is led, overseen and held accountable. Regulatory functions affect what the organisation is responsible for doing.
The update confirms that the second of those, the regulator’s functions, will continue.
For Insight readers following UK data regulation, the date is the main operational milestone. It places the governance change on a fixed footing and confirms when the new structure will formally begin.
What will stay the same
The ICO has made clear that its existing regulatory functions and responsibilities will be maintained.
That is the central reassurance in the announcement. The transition is not being presented as a reset of the regulator’s remit.
The organisation will continue to be known as the ICO. This point is likely to matter in practice because the ICO name is widely used by organisations, practitioners and members of the public.
Public-facing continuity should help reduce confusion during the transition. People are used to referring to ICO guidance, ICO decisions, ICO services and ICO contact routes. The announcement confirms that the ICO identity will remain in use after the governance change.
The regulator has also said it remains focused on a smooth transition and continuity of service for customers and stakeholders.
That focus on continuity suggests the organisation is preparing to manage the change without disrupting the work people rely on, including engagement with regulated organisations and support for people using information rights services.
The most practical takeaway is clear:
The name behind the governance model is changing, but the ICO’s recognised role and responsibilities are expected to continue.

What will change
The main confirmed change is the creation of the new Information Commission governance structure.
The July announcement of seven Non-Executive Members was an important step towards that structure. Those members have been appointed to the new Information Commission Board and will assume their roles on 30 September 2026.
Non-Executive Members are generally appointed to provide independent oversight, challenge and governance experience. In this case, the announcement confirms their role as members of the new board.
The board’s arrival marks a shift in how the regulator is governed. The organisation will transition from the Information Commissioner’s Office to the Information Commission, with the Information Commission’s Office continuing to use the ICO name.
The update does not provide further detail on any changes to internal teams, processes, guidance, casework, enforcement approach or service channels. It also does not set out any change for organisations in how they should meet their data protection or information rights obligations.
For now, the confirmed facts are narrow but significant:
The transition date is 30 September 2026.
The legal basis is the Data (Use and Access) Act 2025.
The new body will be the Information Commission.
Seven Non-Executive Members will join the new Information Commission Board.
The organisation will continue to be known publicly as the ICO.
Existing regulatory functions and responsibilities will continue.
That combination points to a governance reform rather than a service or regulatory handover.
Why this matters for regulated organisations
For organisations that follow ICO guidance, respond to ICO enquiries, report data protection issues, or monitor UK data regulation, the announcement helps separate two questions.
The first is whether the regulator’s governance model is changing. The answer is yes.
The second is whether the regulator’s role is changing. Based on the announcement, its existing functions and responsibilities are being maintained.
That distinction should help keep planning proportionate. Organisations do not need to treat the announcement as a signal that their legal obligations have changed. They should, though, keep track of further ICO updates as the transition date approaches.
The most sensible steps are practical rather than dramatic.
Teams that manage data protection, freedom of information, records management or compliance can note the date in their regulatory calendar. They can also make sure internal documents use the correct terminology if they refer to the regulator after the transition.
For example, policies that name the Information Commissioner’s Office may later need wording updates once the Information Commission is in place. Public-facing references may still use ICO, since the organisation has confirmed that it will continue to be known by that name.
This is also relevant for training materials. Staff may see both terms during the transition period: Information Commissioner’s Office and Information Commission. Explaining that this is a governance change, with the ICO name retained, should help avoid confusion.
What this means for the public
For members of the public, the clearest message is continuity.
The ICO is a familiar point of contact for people seeking help with information rights and data protection concerns. The announcement confirms that, as the Information Commission’s Office, the organisation will continue to be known as the ICO.
That matters because regulatory changes can sometimes make services feel harder to navigate. Names, remit and public contact routes can become confusing if changes are not explained clearly.
Here, the regulator has stressed continuity of service. The announcement does not suggest that people will need to approach a different body or learn a new public identity.
People who already recognise the ICO should be able to keep using that name.
The change sits behind the public-facing work of the regulator. It affects the organisation’s governance framework, including the new board, rather than replacing the purpose people associate with the ICO.

The role of the new board
The appointment of seven Non-Executive Members to the new Information Commission Board is a key part of the governance change.
Their appointments were announced in July, with the roles beginning on 30 September 2026. That timing aligns the board’s start with the formal transition from the Information Commissioner’s Office to the Information Commission.
The board will sit within the new governance model created by the Data (Use and Access) Act 2025. The announcement does not set out detailed biographies or individual responsibilities, so the most reliable summary is that the members have been appointed to the new board and will take up their roles when the transition takes effect.
From a governance perspective, this is the practical moment when the future structure becomes active. The organisation is not only being renamed in legal or structural terms. It is also putting the new board in place at the same time.
That sequencing matters because it shows the transition is planned around a defined governance start date, not a gradual or unclear handover.
What happens between now and 30 September 2026
The ICO has said it remains focused on ensuring a smooth transition and continuity of service for all customers and stakeholders.
That suggests the period leading up to 30 September 2026 will be used to prepare the organisation, its governance arrangements and its communications for the change.
Readers should expect further practical updates if the regulator needs to explain any changes to documents, governance pages, public materials or references to the organisation’s legal name.
For now, the message is relatively simple. The change has been confirmed, the date has been set, and the ICO name will remain.
A sensible watchlist for the coming months includes:
Any further information about the Information Commission Board.
Updates to ICO governance pages and publications.
Any changes to wording in official guidance.
Practical notices about continuity of services.
Clarification on how the regulator will refer to itself before and after the transition date.
None of these points requires speculation. They are simply the areas where readers may see the transition reflected as 30 September 2026 approaches.
A clear governance milestone, not a change in regulatory expectations
The confirmed transition is an important marker in the development of the UK’s information rights regulator.
The Information Commissioner’s Office will become the Information Commission on 30 September 2026. The change comes from the Data (Use and Access) Act 2025 and introduces a new governance structure, including the new Information Commission Board.
At the same time, the announcement is careful to stress continuity. Existing regulatory functions and responsibilities will remain. The organisation will continue to be known as the ICO. Service continuity remains a stated focus throughout the transition period.
For Insight readers, the update is best understood as a governance milestone with practical communication implications. The date is now confirmed, the new board will begin its role on the same day, and the familiar ICO name will continue beyond the transition.

The practical takeaway is straightforward: mark 30 September 2026 in the regulatory calendar, keep an eye on further ICO updates, and treat the change as a formal governance transition rather than a change to the regulator’s core responsibilities.




Comments