ICO gets new board and a Manchester home
The UK data protection watchdog becomes a corporate body after a leadership scandal and a move from Wilmslow to Manchester.
Britain's data protection watchdog has a new legal identity, a new board, and a new address. As of September 30, the Information Commission replaced the Information Commissioner as the statutory regulator — though the familiar ICO initials are staying put.
The overhaul is more than a rebrand. It shifts statutory powers away from a single officeholder and into a corporate body with executive and non-executive board members, following a leadership scandal and a relocation from Wilmslow to Oxford Road in Manchester.
From one person to a board
The former regulator was a "corporation sole," a legal structure in which statutory powers and responsibilities were vested in one person: the Information Commissioner. Under the new arrangement, those functions have transferred to a corporate body overseen by executive and non-executive board members.
The organization itself is now known as the Information Commission's Office, but it will continue to use the ICO name. The change was created by the Data (Use and Access) Act 2025, which received Royal Assent in June 2025. The government says the new structure will modernize the watchdog's governance without changing its existing regulatory functions.
A resignation and an interim chief
The transition follows an awkward final few months under the old structure. Information Commissioner John Edwards resigned in June after an independent workplace investigation into his conduct. Edwards admitted that his position had become "untenable" and that attempts at humor had been "inappropriate and caused offense."
Edwards had stepped back from his duties in April, and the ICO removed his remaining responsibilities after the investigation concluded there was "a case to answer." Paul Arnold, who assumed Edwards' statutory responsibilities before his resignation, is serving as interim chief executive of the Information Commission.
Seven non-executive members join the board
Seven non-executive members have joined the new board. They appointed Maggie Carver as deputy chair, and she will perform the chair's duties while the government searches for somebody to fill the job permanently. That recruitment process is not expected to wrap up until spring 2027.
For anyone dealing with the watchdog, little should change day to day. The Information Commission retains responsibility for data protection and freedom of information regulation, along with the ICO's existing powers, guidance, and public services.
Manchester move and talent pool
The regulator has also packed its boxes and moved its headquarters from Wilmslow to Oxford Road in Manchester. It says the move will give it access to a "diverse talent pool" and strengthen links with businesses and communities across the UK.
The ICO's new corporate strategy is also on the way, with AI, cyber resilience, children's privacy, and public services among the areas singled out for attention.
Why the governance change matters
Putting statutory powers under collective control is a structural change, not just an administrative one. Under the old corporation sole model, the Information Commissioner personally held the regulator's legal powers. Now those powers sit with a corporate body, which could change how decisions are made and how accountability is distributed across the board.
The move to Manchester and the recruitment of a permanent chair are still in progress, with the chair search expected to continue until spring 2027. For the organizations and individuals the ICO regulates, the practical effect may be limited in the short term, but the governance model they are dealing with has fundamentally changed.
Sources
- The Register Original source
Continue Reading
England's schools recover faster from cyberattacks
Ofqual survey finds secondary schools reporting fewer incidents and quicker recovery, but training and responsibility gaps persist.
Zimbra Flaw Exploited Before Disclosure
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
Cloudflare Vows Quantum-Proof TLS Shift
Cloudflare says it will issue post-quantum TLS certificates using Merkle Tree Certificates, targeting Q1 2027 after acquiring a GlobalSign root.