Quentin CasaresData and AI leadership for regulated growth
Insights

2026-09-26 / 8 min

The data regulator becomes a board on 30 September

On 30 September 2026 the office of the Information Commissioner is abolished and its functions pass to the Information Commission, a board of seven non-executives and an interim chief executive holding the enforcement powers the Data (Use and Access) Act enlarged in February.

In brief: on 30 September 2026 the office of the Information Commissioner is abolished and its functions transfer to the Information Commission, a body corporate with collective responsibility for decisions. The powers that board inherits were enlarged on 5 February, when the maximum penalty under the direct marketing and cookies rules rose from £500,000 to £17.5 million or 4 per cent of global turnover and the regulator gained the power to compel named individuals to attend interviews. Boards should establish where the firm is exposed under those rules and who would answer such a notice.

Enforcement changes when the people making the decision change, and on 30 September the body making data protection decisions in the UK stops being one person.

The Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026, made on 10 September, bring sections 118 and 119 of the Act into force on 30 September 2026. Section 118 abolishes the office of Information Commissioner. Section 119 transfers its functions to the Information Commission. Regulation 3 carries over every act, omission and other thing done by the old regulator, including legal proceedings, so open investigations continue without restarting, and regulation 4 leaves the accounts for the financial year ending 31 March 2027 with the new body. References to the Information Commissioner in existing legislation are read as references to the Commission.

Nothing in the rulebook changes that day. The UK GDPR and the Data Protection Act 2018 are untouched, and no privacy notice needs rewriting before Wednesday. What changes is who decides, how that decision is made, and how visible the record of it becomes.

A corporation sole becomes a board

In a written ministerial statement on 14 September 2026, the government told Parliament that the ICO has operated as a corporation sole, with powers and responsibilities vested in one individual, and that from 30 September those functions pass to a body corporate with non-executive and executive members and collective responsibility for decision making. The Commission is constituted as a board of between three and fourteen members, comprising a chair, non-executive members and a chief executive.

Seven non-executive members announced in July take up their roles on 30 September: Laurie Benson, Maggie Carver, Stephen Cohen, Sukhvinder Kaur-Stubbs, Gary Kildare, Hilary Newiss and Scott McPherson. They will sit alongside the interim chief executive, Paul Arnold, while a public appointments campaign runs to recruit a permanent chair. The statement described the intent as an organisation that is open, accountable and resilient, and capable of regulating with rigour and independence.

Two structural duties matter more to firms than the personnel. The regulator now carries secondary objectives alongside data protection, including promoting innovation and supporting competition, and must consult other regulators on growth, competition and innovation. It must also publish an annual analysis of its performance against key performance indicators and report on its investigations, their timelines and the powers it used. A regulator that reports on the powers it used has a reason to use them.

The powers the new board inherits

The enlargement happened on 5 February 2026, seven months before the board arrived to hold it.

PowerWhat it allowsWhere the firm is exposed
Penalties under the Privacy and Electronic Communications RegulationsUp to £17.5 million or 4 per cent of global annual turnover, matching UK GDPR levels, against a previous cap of £500,000Direct marketing, electronic mail consent and cookie banners, usually owned by marketing rather than by risk
Interview noticesCompels an individual to attend and answer questions, with a false statement an offenceNamed individuals, whose account will be read against their statement of responsibilities under SM&CR in regulated firms
Report noticesRequires the organisation to arrange and pay for a report by an approved person on a specified matterCost, timetable and the disclosure of a third party's findings mid-investigation
Information notices for documentsCompels specified documents from controllers and processors, including data protection impact assessmentsWhether the assessments exist, are current, and match what the system now does

The regulator has said it will use the interview and report powers where necessary in the most serious cases, and has not publicly reported using either yet. Its final enforcement procedural guidance, consulted on in a process that closed in January 2026, is still awaited alongside updated fining guidance. That is a narrow window, not a reprieve: the statutory powers are live whether or not the guidance explaining how they will be exercised has been published.

The calendar a board should be working to

DateWhat changed or changesWhat it asks of the firm
5 February 2026PECR penalties raised to UK GDPR levels; interview, report and document powers commenceKnow the turnover-linked exposure of the marketing estate and who would be interviewed
5 February 2026The restriction on solely automated significant decisions narrows to decisions based wholly or partly on special category data, with safeguards retainedIdentify which automated decisions moved into the wider lawful basis route, and record the safeguards relied on
5 February 2026Consent no longer required for statistical, appearance and emergency assistance cookies, with a free and simple opt-out for the first twoRe-test the banner against the exemptions rather than assuming the old configuration still fits
19 June 2026Statutory complaints route: controllers must help people complain, including an electronic form, acknowledge within 30 days and respond without undue delayReport complaint volumes and response times to the board as a monitored control, not an inbox
30 September 2026The Information Commission takes over all functions; investigations and enforcement continue unbrokenUpdate references to the Information Commissioner at the next policy review
Expected 2027Statutory code of practice on AI and automated decision-makingBuild the evidence the code will ask for while it is still being drafted

The code of practice is the real test

The new board's first substantial piece of rule writing is already mandated. Section 124A of the Data Protection Act 2018, inserted by the Data (Use and Access) Act, was activated by regulations made on 16 April 2026 and in force from 12 May, which require the Commissioner to prepare a code of practice giving guidance on good practice in processing personal data in relation to developing and using artificial intelligence and to automated decision-making. The code must include guidance on processing children's personal data. The advisory panel that reviews it is barred from considering the national security aspects.

The sequence runs through guidance first. The ICO consulted on draft guidance covering automated decision-making and profiling from 31 March to 29 May 2026, final guidance is expected in the winter, and the statutory code is anticipated in 2027. The distinction matters commercially. A statutory code is not ordinary guidance: courts must take it into account in relevant proceedings, and the regulator must have regard to it when it enforces. The board that takes office on 30 September owns the drafting of the document a court will later read.

What the code will ask for is what a working data governance function already produces. Which decisions are made by a model rather than a person, which data elements feed them, where those elements came from, what quality threshold they have to meet, and what a customer can do about the outcome. That is Critical Data Elements and data lineage applied to a decision rather than to a report, and in regulated firms it is the same evidence Consumer Duty outcome monitoring and SM&CR accountability already require in another language. Firms that treat the code as an AI project will build it twice.

Five questions before the next board meeting

  1. Which of our activities sit under PECR, and what is the maximum penalty now available against 4 per cent of our global turnover rather than the old £500,000 cap?
  2. If an interview notice named an individual here tomorrow, who would it be, and does their statement of responsibilities match what they would be asked to explain?
  3. Do we hold current data protection impact assessments for our automated decisions, knowing an information notice can demand them by name?
  4. Since 19 June we have had to acknowledge data protection complaints within 30 days. How many have we received, what is our median response time, and why has that number never reached this board?
  5. Which of our automated decisions moved to the narrower February test, and would we defend those safeguards against a statutory code that courts must take into account?

A regulator that has to publish its own performance will look for cases worth publishing, and the firms that can evidence their answers now are the ones that will be explaining rather than reconstructing.

Sources

Related service: Advisory

Executive Data Briefing

A low-volume note for data and AI decisions with consequence.

Consent-based and double opt-in. Governance patterns, board-level data trust, and decision infrastructure - not generic AI commentary.