BLS Stay Compliant
News and Information

What next for the ICO?

The UK’s Information Commissioner’s Office is quietly evolving to become an Information Commission.

It is a meaningful change in approach, moving from a single, controlling Commissioner as the regulator to a corporate board structure with shared decision-making responsibilities across a Chair, Chief Executive and Executive and Non-Executive Directors.

Whilst we are told that this organisational change will not alter the role and responsibilities of the regulator, and all existing ICO functions will simply move to the Commission, there are other factors at play which are likely to influence the character and approach of the UK’s independent regulator.

When in June 2026 the information commissioner John Edwards resigned following a workplace investigation, there was already a degree of disquiet over the direction and decision making of the organisation.

Concerns were aired about the organisation’s perceived weak enforcement, low rates of formal fines, and tardy response in issuing guidance following the passing of the Data (Use and Access) Act 2025 (DUAA).

All of us here at BLS Stay Compliant have experience of various information commissioners and I think it’s fair to say that the transition from the previous Commissioner, Elizabeth Denham, to the reign of John Edwards was stark.

Under his watch frustration and anxieties grew regarding a number of tangible changes in the approach of the ICO. Critics note that the majority of complaints that were found as proven by the ICO now result in no formal action or just light reprimands instead of financial penalties.

The Open Rights Group highlighted that the ICO took regulatory action in only a tiny fraction of the tens of thousands of complaints lodged in recent years.

Public Sector authorities have been perceived as having been treated advantageously, any malpractice or breaches almost always resulting in merely informal warnings rather than more significant and ultimately deterring consequences. Whilst there is some merit in the thought process that a financial penalty against a public authority will simply recirculate public funds and potentially harm tax payers, the lack of any strong, punitive sanctions sends negative messages to senior leaders.

The ICO has formidable powers, when these are only used against non-public organisations, in our experience resentment and perplexity breeds amongst private companies who perceive a two-tier regulatory attitude.

In fairness the regulator has a difficult role; to police the law and act as guide and advisor at the same time.

They have recently complained of a growing backlog in FOI complaints against “unprecedented” demand. They say they now have insufficient resources to tackle the number of FOI complaints after its bid for more funding was rejected at the 2025 Spending Review.

However, as FOI legislation only applies to public authorities, perhaps a more proportionate sanction process would have avoided such an increase, as public bodies would have realised they needed to properly address this important access right. A few well publicised fines and necessary enforcement notices against public authorities might have kept this rise in complaints in check.

There are also reports of disquiet about how close the ICO is to the Westminster political scene. Indeed, one of the most head-scratching decisions of late by the ICO followed the Ministry of Defence (MoD) who in 2022 accidentally disclosed highly sensitive personal data of 18,700 Afghan nationals who had assisted UK forces, and their associated family members. Sadly, dozens of deaths in Afghanistan have since been attributed to this data breach and many of those on the disclosed document report having received direct threats as a result.

And yet the ICO, faithfully pursuing their new “public sector approach” issued a reducing monetary penalty against the MoD and, when criticised over this perceived timid response, refused to take any further action.

So, the new Information Commission is likely to have many challenges to deal with and no doubt various policy decisions to review.

The Data (Use & Access) Act 2025, which legislated for the revised re-structure into a Commisision, places clearer demands on the regulator, and the days of them simply investigating data breaches and non-compliance with privacy rights are long gone.

The new body will need to get up to speed quickly, scrutiny and frustrations are growing and whilst they have been handed even more powers, their appetite for sanctions for data breaches will need a detailed examination and serious self-reflection.

A public accusation of “.. brushing aside thousands of public data complaints” (1) is not a comfortable starting point for any new public body.

© BLS Stay Compliant Limited

Share this post

More News