Skip to main content
ICO to Information Commission: Your Readiness ChecklistSupervisory Authorities & Enforcement
4 min readFor Legal & Compliance Teams

ICO to Information Commission: Your Readiness Checklist

On September 30, 2026, the UK's Information Commissioner's Office will be replaced by the Information Commission, a body with shared governance. While the supervisory authority's functions remain the same, the shift from a single-person authority to collective decision-making could impact enforcement timelines, appeal processes, and your organization's engagement with the supervisory authority.

This checklist will help you prepare for the transition and understand changes in your compliance operations.

What This Checklist Covers

The Data (Use and Access) Act 2025 establishes the Information Commission, led by a chair (who retains the "Information Commissioner" title), a chief executive, and other executive and non-executive members. All current ICO functions transfer to this new body, but the governance structure differs fundamentally from the single-decision-maker model you've worked with until now.

This checklist focuses on operational readiness: updating documentation, reviewing engagement protocols, and identifying where shared governance might affect your compliance workflows.

Prerequisites

Before you start:

  • Confirm your current ICO registration details. Ensure these transfer correctly to the new body.
  • Inventory all active ICO interactions. Include open investigations, pending DSAR appeals, ongoing consultation processes, and any enforcement actions.
  • Review your data protection policy documentation. Note every reference to "Information Commissioner's Office" or "ICO" that will need updating.
  • Identify internal stakeholders. Determine who in your organization interacts with the supervisory authority. Legal, compliance, IT, HR, and business units handling DSARs all need briefing.

Readiness Checklist

1. Update all external-facing documentation by September 15, 2026

Replace "Information Commissioner's Office" or "ICO" with "Information Commission" in your privacy notices, data protection policies, DSAR response templates, and complaint procedures. Review context carefully to ensure accuracy.

2. Revise internal escalation procedures to account for collective decision-making

Your current escalation matrix likely assumes a single decision-maker can reverse or expedite determinations. With shared governance, decision timelines may lengthen, particularly for novel or contentious matters. Update your internal SLAs accordingly.

3. Review and update supervisory authority contact protocols

Verify that your organization's designated contacts for regulatory communication are current. The Information Commission may restructure internal departments or communication channels. Confirm your regulatory liaison contacts by mid-September 2026.

4. Assess impact on pending regulatory matters

If you have open investigations, enforcement actions, or appeals in progress as of September 30, 2026, review the Commencement Regulations carefully. Determine whether pending matters will be decided under the old or new governance structure, and whether timelines will be affected.

5. Update data protection impact assessments referencing supervisory authority consultation

Article 36 UK GDPR requires prior consultation with the supervisory authority for high-risk processing. If your DPIAs reference the Information Commissioner's Office by name or describe the consultation process based on the corporation sole structure, revise them.

6. Revise training materials and compliance awareness content

Update slides, e-learning modules, and compliance handbooks to reflect the shared governance model. Explain what this means for employees who handle DSARs or data protection queries.

7. Review contracts with processors and third parties

Many data processing agreements reference the "Information Commissioner's Office" in clauses about regulatory cooperation, audit rights, or breach notification. While the functions remain the same, contractual accuracy matters. Schedule a review cycle to update these references.

8. Monitor Information Commission guidance on procedural changes

The governance shift may bring procedural updates: revised complaint handling, new consultation processes, or different enforcement prioritization. Subscribe to Information Commission updates and assign someone to track procedural guidance in the months following the transition.

Common Mistakes

Assuming nothing changes operationally. Shared governance can affect decision speed, appeal outcomes, and enforcement consistency. Don't treat this as a name-change exercise.

Overlooking transitional provisions. The Commencement Regulations (SI 2026/1015) include specific provisions for matters in progress. Ignoring these could mean missed deadlines or procedural missteps.

Updating documentation without updating processes. Changing "ICO" to "Information Commission" in your privacy notice doesn't help if your complaint procedure still assumes single-decision-maker timelines.

Failing to brief business stakeholders. Marketing, HR, and product teams often interact with data protection requirements without understanding regulatory structures. They need to know what's changing and why it might affect their timelines.

Next Steps

By September 15, 2026, complete items 1-3. These are your immediate operational updates.

By October 15, 2026, complete items 4-7. These require more coordination but should be addressed within the first two weeks of the new structure.

Assign ongoing responsibility for item 8. This isn't a one-time task; it's a monitoring function that should sit with your compliance or legal team.

Finally, consider how other supervisory authorities structure their governance. Ireland's Data Protection Commission uses a multi-member commission model. France's CNIL has a collegiate structure. The UK's shift toward shared governance aligns with international norms, but implementation details will emerge over time. Stay alert to how the Information Commission interprets its own decision-making protocols in those first months.

You Might Also Like