Posted on September 29, 2026  
by Noel Guilford

On 30 September 2026, the Information Commissioner’s Office becomes the Information Commission. The change comes from the Data (Use and Access) Act 2025.

For most small businesses, the day will pass quietly. UK GDPR and the Data Protection Act 2018 still apply. Open investigations carry across. The regulator will still call itself the ICO.

So why write about it? Because the change is in how the regulator is run, and how a regulator is run shapes how it behaves.

What changes

Until now, the ICO’s legal powers sat with one person, the Information Commissioner. Lawyers call this a “corporation sole”. From 30 September, those powers sit with a board.

The board can have between 3 and 14 members: a chair, non-executive members, a chief executive and possibly other executives. Where practicable, non-executives must outnumber executives. The chair keeps the title Information Commissioner, and the Government is recruiting for that role now.

A single office-holder answers for their own judgement. A board answers for results.

What you need to do on 30 September

Nothing urgent.

The commencement regulations treat anything done by or in relation to the Information Commissioner as done by or in relation to the new Commission. That includes legal proceedings. References to the Information Commissioner in legislation and documents are read as references to the Commission where appropriate.

You don’t need to reissue contracts or restart anything with the regulator.

There is some light housekeeping for your next review. Start with your privacy notice, especially the paragraph that tells people they can complain to the regulator. Then check your cookie policy, data protection policy and complaints procedure. Where a document says “Information Commissioner’s Office (ICO)”, change it to “Information Commission’s Office (ICO)”. Where it just says “ICO”, leave it alone.

That’s a 20-minute job when the documents are next open. There is no deadline attached to it.

What this means for a small business 

The maximum fines haven’t changed. The Commission’s UK GDPR enforcement functions are the same on 1 October as on 29 September. The Government has also asked the regulator to weigh economic growth alongside the protection of personal information. Nothing here points to a wave of fines against small firms next month.

My read is that the effect will arrive slowly, through complaints. A small business usually meets the regulator because one customer, employee or former employee is unhappy. A board measured on how it handles 40,000-plus complaints a year has every reason to deal with them faster and follow through more often.

So the useful test is simple. If a complaint about your business arrived next week, could you show what personal data you hold, why you hold it and who can see it?

For most owner-managed businesses, that needs 3 things in order:

  • a privacy notice that matches what you do with personal data
  • a record of what you hold and where it sits, including Xero, your CRM and your inbox
  • a written process for a subject access request or a data breach, which someone has tested

These are existing duties. Kept current, they let you answer a complaint in days, with evidence.

If you’d like some help from me please book a discovery call at https://calendly.com/noelguilford

Related Posts

Plan for the new normal

Plan for the new normal

Should You Actually Grow?

Should You Actually Grow?

What a virtual board meeting actually looks like

What a virtual board meeting actually looks like

Autumn Budget 2025 – What It Means for You

Autumn Budget 2025 – What It Means for You

Noel Guilford


Your Signature

Leave a Reply


Your email address will not be published. Required fields are marked

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}