UK's Data Protection Watchdog Restructures: What It Means for Businesses
The UK's data protection regulator has undergone a major governance overhaul. As of September 30, the Information Commission has replaced the Information Commissioner as the statutory authority, with the organisation continuing to operate under the familiar ICO name. Previously, all regulatory power rested with a single person; now it sits with a corporate board made up of executive and non-executive members, a structure created under the Data (Use and Access) Act 2025.
The change follows a turbulent period for the regulator. Former Information Commissioner John Edwards resigned in June after an investigation into workplace conduct found he had a case to answer, with Edwards himself admitting attempts at humour had been inappropriate. Paul Arnold is now serving as interim chief executive, and Maggie Carver has been appointed deputy chair while a permanent chair is recruited, a process not expected to finish until 2027. The regulator has also relocated its headquarters from Wilmslow to Manchester.
Despite these structural changes, the UK government says the watchdog's actual regulatory functions, guidance, and powers remain unchanged. Businesses that handle UK personal data, including Australian SMBs with UK customers or operations, should expect continuity in enforcement approach even as the organisation's leadership and governance evolve.