Security News

UK's Data Protection Watchdog Restructures: What It Means for Businesses

The Register · 1 Oct 2026
Key Takeaway If your business handles data covered by UK privacy law, don't expect enforcement priorities to change, but keep an eye on new guidance as the ICO's new board settles in.

The UK's data protection regulator has undergone a major governance overhaul. As of September 30, the Information Commission has replaced the Information Commissioner as the statutory authority, with the organisation continuing to operate under the familiar ICO name. Previously, all regulatory power rested with a single person; now it sits with a corporate board made up of executive and non-executive members, a structure created under the Data (Use and Access) Act 2025.

The change follows a turbulent period for the regulator. Former Information Commissioner John Edwards resigned in June after an investigation into workplace conduct found he had a case to answer, with Edwards himself admitting attempts at humour had been inappropriate. Paul Arnold is now serving as interim chief executive, and Maggie Carver has been appointed deputy chair while a permanent chair is recruited, a process not expected to finish until 2027. The regulator has also relocated its headquarters from Wilmslow to Manchester.

Despite these structural changes, the UK government says the watchdog's actual regulatory functions, guidance, and powers remain unchanged. Businesses that handle UK personal data, including Australian SMBs with UK customers or operations, should expect continuity in enforcement approach even as the organisation's leadership and governance evolve.

UK ICO data protection privacy regulation governance GDPR
Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.