Skip to main content
ComplianceData Protection

UK's ICO Reconstitutes with New Board, HQ Amid Regulatory Overhaul

Stately government building with modern office complex and people walking in courtyard.
"My position had become 'untenable' and attempts at humor had been 'inappropriate and caused offense,'" John Edwards said, language that bookended a governance overhaul at Britain's data protection watchdog that took effect on September 30.

The legal reset: Information Commission replaces the Information Commissioner

On September 30 the statutory regulator's legal identity changed: the Information Commission replaced the Information Commissioner as the statutory regulator. The organization will be known operationally as the Information Commission's Office but will continue using the familiar ICO initials. The legal restructuring comes from the Data (Use and Access) Act 2025, which received Royal Assent in June 2025.

The government described the change as a modernization of governance while saying it will not alter the regulator's existing regulatory functions. For day-to-day contacts, the Information Commission retains responsibility for data protection and freedom of information regulation, together with the ICO's existing powers, guidance, and public services.

From a corporation sole to a corporate body: what changed

The old regulator had been structured as a "corporation sole": statutory powers and responsibilities were vested in a single officeholder, the Information Commissioner. Under the new legal form those functions now sit with a corporate body overseen by executive and non-executive board members. The shift replaces concentrated statutory authority in one person with a collective board governance model.

The change is administrative and constitutional rather than substantive, according to the government — it transfers statutory functions but, in official terms, does not change the regulator's powers or routine public services.

Leadership turbulence and the new board

The transition follows an awkward final few months under the old structure. Information Commissioner John Edwards resigned in June after an independent workplace investigation into his conduct. The ICO removed his remaining responsibilities after the investigation concluded there was "a case to answer," and Paul Arnold, who had assumed Edwards' statutory responsibilities before his resignation, is serving as interim chief executive of the Information Commission.

Seven non-executive members have joined the new board. They appointed Maggie Carver deputy chair, and she will perform the chair's duties while the government searches for someone to fill the permanent chair role. That recruitment process is not expected to finish until spring 2027.

Relocation to Manchester and operational direction

The Information Commission has moved its headquarters from Wilmslow to Oxford Road in Manchester. The regulator says the relocation will give it access to a "diverse talent pool" and strengthen links with businesses and communities across the UK. Officials also say that for anyone dealing with the watchdog, little should change day to day.

Alongside the governance and location changes, the regulator is preparing a new corporate strategy. Areas singled out for attention include AI, cyber resilience, children's privacy, and public services — signalling the priorities that the new board and executive team will be expected to pursue.

How technologists, policymakers, and the public are affected

  • Technologists and security teams: Expect continuity in enforcement and guidance. The Information Commission retains its regulatory remit, and the planned corporate strategy lists AI and cyber resilience as priority areas to watch for new guidance or enforcement emphasis.
  • Policymakers and regulators: The statutory shift implemented by the Data (Use and Access) Act 2025 creates a collective governance model — seven non-executives and an executive team — and leaves a visible recruitment milestone (a permanent chair to be appointed by spring 2027) that will shape the regulator's direction.
  • The public and service users: Front-line services and statutory responsibilities — data protection and freedom of information regulation, plus existing powers and guidance — remain in place. The move to Manchester is presented as operational rather than service-disrupting.

The facts are straightforward: the legal identity changed on September 30, the board model replaced a corporation sole, the watchdog relocated to Manchester, seven non-executives are in place, Maggie Carver will act as chair pending a spring 2027 appointment, and a new corporate strategy will prioritise AI, cyber resilience, children's privacy, and public services. Whether the structural reset and the board's early decisions will stabilise the regulator after the investigation and shape a different tone to enforcement and guidance is now a question with two fixed dates attached — June 2025 (Royal Assent to the Data (Use and Access) Act) and spring 2027 (target for selecting a permanent chair) — and a relocated HQ on Oxford Road in Manchester as a visible marker of change.

Source: UK privacy watchdog starts over with new board and Manchester HQ — The Register, 1 Oct 2026