---
title: "The ICO becomes the Information Commission: what changes on 30 September, and what does not"
description: On 30 September 2026 the ICO becomes the Information Commission, a board-led regulator. The law you follow stays the same. Three privacy checks to run now.
---

<https://www.cybercontrols.io/blog>

# [The ICO becomes the Information Commission: what changes on 30 September, and what does not](https://www.cybercontrols.io/blog/the-ico-becomes-the-information-commission-what-changes-on-30-september-and-what-does-not)

 Written by [Marius van Aswegen](https://www.cybercontrols.io/blog/author/marius-van-aswegen) | Sep 28, 2026, 4:53:03 PM

On Wednesday 30 September 2026 the Information Commissioner's Office becomes the Information Commission. For most UK organisations the rules do not change at all. What changes is how the regulator governs itself, and that is worth a moment's thought.

## What is happening

The Data (Use and Access) Act 2025 replaces the single Information Commissioner with the Information Commission, a body led by a board that shares responsibility collectively. Seven non-executive members, appointed in the summer, take up their seats on the new board on 30 September.

The regulator will still be known as the ICO. Its regulatory functions and responsibilities carry across unchanged.

## What does not change

This is a change to the regulator's governance, not to your obligations. UK GDPR, the Data Protection Act 2018 and PECR continue to apply. Your lawful bases, your privacy notices, your breach reporting duties and your handling of subject access requests work exactly as they did the day before.

Other parts of the Data (Use and Access) Act are being brought into force in stages, so it is sensible to track those separately. Nothing about 30 September itself requires you to rewrite a policy.

## Why it still matters

Regulators tend to look for what they practise. A board-led regulator, with decisions owned, recorded and reviewed collectively, is likely to be less patient with privacy programmes that live in one person's head or in a mailbox nobody owns.

The law does not move. The expectation of evidence probably does. When a complaint arrives or an incident is reported, the question will increasingly be not only "what happened?" but "how is privacy governed here, and can you show us?"

## Where ISO 27701 fits

ISO 27701 is built for exactly that question. The 2025 edition is a standalone Privacy Information Management System standard, certifiable in its own right, and it pairs naturally with ISO 27001 if you already have one.

It makes you decide whether you act as a controller, a processor or both, and many SMEs are both at once: controller for staff and marketing data, processor for their clients' data. It then asks for a privacy risk assessment, a treatment plan and a Statement of Applicability of its own, and for evidence that privacy decisions are made, written down and revisited. In other words, governance that is owned, recorded and reviewed.

## Three checks worth doing this month

1. **Ownership.** Does your data protection policy name an accountable owner, a person with authority, rather than a shared mailbox?
2. **Currency.** Is your record of processing current, or was it last updated for an audit or a tender?
3. **Evidence.** Could you show how your last complaint or subject access request was handled, who handled it and how long it took?

If any answer is "not quite", that is normal, and it is fixable. It is also the kind of gap a board-led regulator is well placed to notice.

## We practise what we implement

Cybercontrols holds ISO 27001 and ISO 42001 certification ourselves, and we audit for UK certification bodies. We help organisations put privacy governance in place that stands up to scrutiny, whether that ends in ISO 27701 certification or simply in a system you can explain with confidence.

If you would like a second pair of eyes on your privacy governance, [talk to us](https://www.cybercontrols.io/contact-us) or email hello@cybercontrols.io.

[View full post](https://www.cybercontrols.io/blog/the-ico-becomes-the-information-commission-what-changes-on-30-september-and-what-does-not)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Marius van Aswegen"
  },
  "dateModified" : "2026-09-28T16:53:03.047Z",
  "datePublished" : "2026-09-28T16:53:03Z",
  "headline" : "The ICO becomes the Information Commission: what changes on 30 September, and what does not",
  "image" : {
    "@type" : "ImageObject",
    "height" : 900,
    "url" : "https://144611087.fs1.hubspotusercontent-eu1.net/hubfs/144611087/cybercontrols-ico-information-commission.png",
    "width" : 1600
  },
  "mainEntityOfPage" : "https://www.cybercontrols.io/blog/the-ico-becomes-the-information-commission-what-changes-on-30-september-and-what-does-not",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "CyberControls Blog"
  }
}
```