Skip to main content
Category: Supervisory Authorities & Enforcement

Information Commissioner

Also known as: ICO, Information Commissioner's Office, ICO
Simply put

The Information Commissioner's Office (ICO) is the UK's independent authority responsible for upholding information rights. It works to protect people's personal data and to promote openness by public bodies, and provides support to the public on matters such as accessing their own data and dealing with data breaches. Note that the individual Information Commissioner heads this office, though the two terms are often used interchangeably.

Formal definition

The Information Commissioner is the UK's independent supervisory authority for information rights, operating through the Information Commissioner's Office (ICO). According to the evidence, the ICO is a non-departmental public body that reports directly to the UK Parliament, and is set up to uphold information rights in the public interest, promoting openness by public bodies and protecting personal data. Its remit spans data protection and freedom of information, and it provides functions including public support after breaches and access-to-information matters. Practitioners should distinguish the office (ICO) from the officeholder (the Information Commissioner) where legal precision is required. The evidence provided does not enumerate the specific statutory powers, governing legislation, or enforcement mechanisms of the ICO; readers should verify these against current official sources.

Why it matters

The Information Commissioner's Office is the UK's independent authority for upholding information rights, which means it sits at the centre of how personal data protection and freedom of information are administered in the UK. For organisations processing personal data, the ICO is the reference point for guidance and for the public-facing consequences of how data is handled, since it protects personal data while also promoting openness by public bodies. Understanding its role is therefore foundational for anyone building or assessing a compliance programme in the UK context.

For individuals, the ICO matters because it provides direct support on information rights. According to the evidence, this includes helping people get copies of their data, exercise the right to access information from a public body, obtain support after a breach, and address matters such as nuisance calls. This dual function of serving both the public and holding organisations to account shapes the practical environment in which controllers and processors operate.

Its constitutional position also matters: the evidence indicates the ICO is a non-departmental public body that reports directly to the UK Parliament, which underlines its independence. The evidence provided does not enumerate the ICO's specific statutory powers, governing legislation, or enforcement mechanisms, so readers should verify those details against current official sources rather than assume a particular scope of authority.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance teams treat the ICO as the primary UK authority for information rights and typically look to it for guidance and for the public-facing dimension of how personal data is handled. Because the evidence here does not enumerate the ICO's specific powers or governing legislation, these practitioners should verify the current statutory framework and any applicable procedures against official sources.
Individuals exercising information rights
Members of the public are directly served by the ICO, which the evidence describes as offering support in getting copies of their data, accessing information from a public body, obtaining help after a breach, and dealing with nuisance calls. This makes the ICO a practical point of contact for people seeking to understand or enforce their information rights.
Public bodies subject to openness obligations
Because the ICO promotes openness by public bodies alongside protecting personal data, public sector organisations are a key audience for its work. The evidence indicates a remit covering both data protection and freedom of information, though the specific obligations and mechanisms should be confirmed against current official guidance.
Lawyers and advisers requiring role precision
For legal work, it is important to distinguish the office (the ICO) from the officeholder (the Information Commissioner), particularly where precise attribution matters. Advisers should also note that the evidence provided does not detail the ICO's statutory powers or enforcement mechanisms, which must be checked against current official texts.

Inside ICO

Supervisory authority role
The Information Commissioner is the person who heads the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection. The role sits within the framework of the UK GDPR and the Data Protection Act 2018 rather than the EU GDPR, which since the end of the Brexit transition period applies as retained and amended UK law. Practitioners should verify the current structure against official ICO materials, as governance arrangements can change.
Regulatory and supervisory functions
The office typically carries functions such as promoting good practice, providing guidance, handling complaints from data subjects, and monitoring and enforcing compliance with UK data protection law. The precise catalogue of tasks and powers is set out in the applicable UK legislation and should be confirmed against the current statutory text.
Enforcement powers
The Commissioner's office may exercise corrective and enforcement powers, which can generally include investigation, issuing notices, and imposing penalties in appropriate cases. The availability and scope of any particular power, and any monetary thresholds, are determined by law and guidance; specific figures should be checked against current official sources rather than assumed.
Distinct jurisdiction from EU authorities
The Information Commissioner is a UK authority and is distinct from the supervisory authorities of EU member states and from the European Data Protection Board. Where processing spans the UK and the EU, more than one authority and legal regime may be relevant, and the position can vary depending on establishment and the affected individuals.

Common questions

Answers to the questions practitioners most commonly ask about ICO.

Is the Information Commissioner the regulator responsible for enforcing the EU GDPR?
Not as such. The Information Commissioner heads the Information Commissioner's Office (ICO), which is the UK's supervisory authority and primarily enforces the UK GDPR and the Data Protection Act, together with other UK information-rights legislation. Following the UK's departure from the EU, the ICO is generally no longer an EU supervisory authority for EU GDPR purposes, and enforcement of the EU GDPR in an EU member state falls to that state's own supervisory authority. Organisations operating across both regimes should assess which authority or authorities apply to their processing.
Does the Information Commissioner only deal with data protection matters?
No. While data protection is a central part of the role, the Information Commissioner's remit under UK law is broader and typically covers a range of information-rights functions, which can include areas such as freedom of information and certain electronic marketing and communications rules. The precise scope of the office's responsibilities is set by the relevant UK legislation, so readers should verify the current statutory functions against the official text and the ICO's published guidance.
When should an organisation contact or engage with the Information Commissioner?
Engagement typically arises in defined situations, such as reporting a personal data breach where the applicable notification threshold is met, or where prior consultation is required following a data protection impact assessment that indicates high residual risk. Organisations may also engage the office when seeking guidance or responding to a complaint or investigation. The specific triggers, thresholds, and timeframes are set out in the UK GDPR and associated guidance, which should be checked for the current position, as some duties are time-sensitive.
How does an organisation report a personal data breach to the Information Commissioner?
In most cases a controller assesses whether a breach is likely to result in a risk to individuals and, where the applicable threshold is met, notifies the supervisory authority within the timeframe set by law, generally using the reporting channels the ICO publishes. Processors typically must inform the relevant controller of a breach without undue delay so the controller can meet its own obligations. Because notification thresholds, content requirements, and deadlines are prescribed and can be interpreted in light of guidance, organisations should confirm the current requirements before relying on a fixed procedure.
What powers can the Information Commissioner exercise against an organisation?
The office generally has a range of supervisory and corrective powers, which can include investigating, issuing information or enforcement notices, and imposing monetary penalties, subject to the limits and procedures set in the applicable UK legislation. The availability and level of any penalty depend on the nature of the infringement and the statutory framework, and outcomes are assessed case by case. Readers should not assume a particular sanction will or will not apply and should verify the current powers and thresholds against the official text.
Should a data protection officer treat ICO guidance as binding law?
Guidance published by the office is influential and widely relied upon in practice, but it is generally not the same as the legislation itself, and its status can differ from binding legal requirements. In most cases it should be read alongside the UK GDPR, the Data Protection Act, and relevant case law, recognising that guidance may be updated and that interpretations can evolve. Where a point is uncertain or the guidance is silent, organisations typically document their reasoning and, where appropriate, take specific legal advice.

Common misconceptions

The Information Commissioner enforces the EU GDPR.
The Commissioner is the UK supervisory authority and operates under the UK GDPR and the Data Protection Act 2018. Since the end of the Brexit transition period the UK applies its own retained and amended version of the Regulation; the EU GDPR is enforced by EU member state authorities. Organisations operating across both regimes may be subject to more than one authority.
The Information Commissioner and the ICO are two different things.
The Information Commissioner is the office-holder who leads the Information Commissioner's Office (ICO). In practice references to ICO decisions and guidance reflect functions exercised under the Commissioner's authority; the exact allocation of statutory functions is set out in law.
The Commissioner can impose any level of penalty at will.
Enforcement and any penalties are exercised within the limits and procedures set by the applicable UK legislation, and outcomes are context and risk dependent. Specific maximum amounts and processes should be verified against the current official text rather than assumed.

Best practices

Confirm which regime applies to your processing, distinguishing the UK GDPR and Data Protection Act 2018 (supervised by the Information Commissioner) from the EU GDPR (supervised by EU member state authorities), especially for cross-border operations.
Consult current ICO guidance and the applicable statutory text directly when relying on the Commissioner's powers, functions, or any penalty thresholds, rather than relying on undated summaries.
Where processing affects individuals in both the UK and the EU, map which supervisory authorities may have jurisdiction and document the basis for that assessment.
Treat enforcement outcomes as context and risk dependent; do not assume a particular power or penalty level applies without checking the relevant legal provisions.
Keep a record of the source and date of any ICO guidance you rely on, since regulatory positions and structures can evolve over time.
Verify any specific figures, dates, or procedural details against official UK sources before citing them in a compliance program.