On 30 September 2026, the Information Commissioner’s Office becomes the Information Commission. The change comes from the Data (Use and Access) Act 2025.
For most small businesses, the day will pass quietly. UK GDPR and the Data Protection Act 2018 still apply. Open investigations carry across. The regulator will still call itself the ICO.
So why write about it? Because the change is in how the regulator is run, and how a regulator is run shapes how it behaves.
What changes
Until now, the ICO’s legal powers sat with one person, the Information Commissioner. Lawyers call this a “corporation sole”. From 30 September, those powers sit with a board.
The board can have between 3 and 14 members: a chair, non-executive members, a chief executive and possibly other executives. Where practicable, non-executives must outnumber executives. The chair keeps the title Information Commissioner, and the Government is recruiting for that role now.
A single office-holder answers for their own judgement. A board answers for results.
What you need to do on 30 September
Nothing urgent.
The commencement regulations treat anything done by or in relation to the Information Commissioner as done by or in relation to the new Commission. That includes legal proceedings. References to the Information Commissioner in legislation and documents are read as references to the Commission where appropriate.
You don’t need to reissue contracts or restart anything with the regulator.
There is some light housekeeping for your next review. Start with your privacy notice, especially the paragraph that tells people they can complain to the regulator. Then check your cookie policy, data protection policy and complaints procedure. Where a document says “Information Commissioner’s Office (ICO)”, change it to “Information Commission’s Office (ICO)”. Where it just says “ICO”, leave it alone.
That’s a 20-minute job when the documents are next open. There is no deadline attached to it.
What this means for a small business
The maximum fines haven’t changed. The Commission’s UK GDPR enforcement functions are the same on 1 October as on 29 September. The Government has also asked the regulator to weigh economic growth alongside the protection of personal information. Nothing here points to a wave of fines against small firms next month.
My read is that the effect will arrive slowly, through complaints. A small business usually meets the regulator because one customer, employee or former employee is unhappy. A board measured on how it handles 40,000-plus complaints a year has every reason to deal with them faster and follow through more often.
So the useful test is simple. If a complaint about your business arrived next week, could you show what personal data you hold, why you hold it and who can see it?
For most owner-managed businesses, that needs 3 things in order:
- a privacy notice that matches what you do with personal data
- a record of what you hold and where it sits, including Xero, your CRM and your inbox
- a written process for a subject access request or a data breach, which someone has tested
These are existing duties. Kept current, they let you answer a complaint in days, with evidence.
If you’d like some help from me please book a discovery call at https://calendly.com/noelguilford
