The UK’s data protection regulator has a new structure. On 30 September, the Information Commission took over the functions of the Information Commissioner’s Office (ICO), the UK government said.
What has changed
The ICO was a “corporation sole”, meaning all its legal powers and duties belonged to one person, the Information Commissioner. Those functions now pass to the Information Commission, a body led by executive and non-executive members who share responsibility for decisions.
The new model was set up under the Data (Use and Access) Act 2025, which received Royal Assent in June 2025. The government says it will help the regulator respond to fast technological change, more complex uses of data and public expectations of transparency.
What stays the same
The regulator’s role, responsibilities and powers do not change. It will keep independently regulating data protection and freedom of information law, issuing guidance and holding organisations to account. People can still complain about how their personal data is handled.
Who leads it
The Commission is led by interim Chief Executive Paul Arnold and seven newly appointed non-executive members: Laurie Benson, Maggie Carver, Stephen Cohen, Sukhvinder Kaur-Stubbs, Gary Kildare, Hilary Newiss and Scott McPherson. Recruitment for a permanent Chair is still under way.
Digital Government Minister Stephanie Peacock said people should be confident their information is used responsibly, whether they are using public services, shopping online or trying new digital technologies.
In Scotland
The Commission regulates data protection across the whole UK. Freedom of information requests to Scottish public bodies are still overseen separately by the Scottish Information Commissioner.




