Brian Sims
Editor
Brian Sims
Editor
THE INFORMATION Commissioner’s Office reached a significant milestone in its evolution on 30 September as the organisation formally transitioned to become the Information Commission. Under new governance arrangements introduced by the Data (Use and Access) Act 2025, the organisation is now overseen by a new Information Commission Board that brings together a range of skills, expertise and perspectives collated to support effective decision-making.
The transition comes as the data protection regulator and information rights champion opens its new headquarters on Oxford Road in Manchester and continues to develop a new corporate strategy. Taken together, these major changes will enable the regulator to build on more than 40 years’ worth of experience and expertise and set a clear direction for its work, all the while responding to the opportunities and challenges created by data and technology and remaining focused on protecting people’s rights at the same time as supporting innovation and economic growth.
The Board’s non-executive members formally assumed their roles on 30 September and will play a key role in scrutinising, challenging and supporting the delivery of the Information Commission’s priorities as it enters this new phase of operations.
One of the Board’s first actions was to appoint Maggie Carver in the role of deputy chair of the Information Commission. Carver brings extensive experience in governance, regulation and digital policy to the role.
While the role of permanent chair is being recruited by the Department for Digital, Culture, Media and Sport, Carver will undertake these responsibilities in the interim period.
Carver said: “The new Board looks forward to supporting the executive of the Information Commission through this exciting time in its development.”
Modernisation and transformation
Paul Arnold, CEO of the Information Commission, said: “I’m delighted to be able to formally welcome our non-executive Board members and deputy chair. Their appointments mark a further key milestone in our modernisation and transformation as a regulator.”
Arnold continued: “This is the beginning of an important new chapter for our organisation. As the Information Commission, we are building on more than four decades’ worth of experience, while at the same time strengthening how we are governed and led.”
Further, Arnold observed: “Our new Manchester office and our new governance arrangements are both part of the same ambition: to become more connected to the people and organisations we serve, more capable of meeting the challenges of what is now a rapidly changing digital world and also more confident in the contribution we can make.”
According to Arnold: “The day-to-day work that people rely on from us goes on. We will continue to provide organisations with the guidance and certainty they need, support responsible innovation and hold organisations to account when people’s information rights are not respected.”
Independent oversight
Digital Government Minister Stephanie Peacock explained: “People should have confidence that their personal information is being used responsibly, whether they are accessing public services, shopping online or using new digital technologies.”
Peacock added: “The new Information Commission will continue to provide strong and independent oversight of data protection, while bringing together a range of expertise to ensure the regulator remains equipped to respond to future challenges and opportunities in a fast-changing digital world.”
The Information Commission's new headquarters realises access to a diverse talent pool and will support the organisation on strengthening its links with partners, businesses and communities right across the UK.
Importantly, the governance transition doesn’t change the Commission’s core responsibilities. The Information Commission will continue its regulatory work, guidance, advice and public services, while preparing to deliver its forthcoming corporate strategy. The latter will focus attention on those areas where the Information Commission can make the greatest difference, including Artificial Intelligence, cyber resilience and public services.
National cyber initiative
The Information Commission’s Office has joined the National Cyber Resilience Centre Group’s National Ambassador Programme, thereby reinforcing its commitment to improving cyber resilience across the UK and helping organisations to protect the personal information they hold.
The new partnership will enable the Information Commission to work alongside fellow National Ambassadors and the network of police-led Cyber Resilience Centres to raise awareness of cyber security risks and connect SMEs with free and affordable support available across the UK.
Strong cyber security is fundamental when it comes to protecting personal information, maintaining public trust and enabling organisations to use data with confidence. Through its work with organisations across the public and private sectors, the Information Commission provides practical guidance, support and regulatory certainty to help organisations manage cyber risks, respond to emerging threats and use personal data responsibly.
The announcement comes as cyber threats continue to evolve and organisations face increasing challenges in keeping their personal information secure.
Key priority
Ian Hulme, Group director for regulatory assurance and cyber at the Information Commission, said: “As cyber threats continue to grow, helping organisations to strengthen their cyber resilience remains a key priority for the ICO. We see every day that many cyber incidents stem from organisations not making sure the basics are right. Helping organisations take practical steps towards improving their cyber resilience is one of the most effective ways in which to reduce harm and protect people’s information.”
Hulme continued: “We are committed to supporting organisations to protect the personal information they hold, while taking action where poor security practices put people at risk.”
Further, Hulme noted: “Joining the National Ambassador Programme allows us to extend the reach of that work. By collaborating with partners across the cyber security community, we can amplify important messages, connect organisations with practical support and guidance and demonstrate our commitment to helping businesses build stronger cyber resilience before problems occur.”
Joanna Goddard, CEO at the National Cyber Resilience Centre Group, observed: “Welcoming the ICO into our National Ambassador cohort is testament to the seriousness with which we and our existing National Ambassadors are taking our mission. Our aim remains to reach as many SMEs as possible to raise awareness of cyber resilience. In order to do so, we are bringing on board the most well-established and well-respected UK companies and organisations. Having the backing of the ICO is a significant success for us and we very much look forward to working with the organisation in a bid to shore up our nation’s cyber defences.”
Proactive steps
Through the National Ambassador Programme, the ICO will help to promote the support available through regional Cyber Resilience Centres and encourage organisations to take proactive steps towards improving their cyber security and meet regulatory obligations. Organisations looking to strengthen their cyber resilience can access the SME cyber guidance and practical resources.
The ICO will also highlight cyber resilience and available business support at its Data Protection Practitioners’ Conference on 13 October. Professionals working in data protection, information governance and cyber security are strongly encouraged to register for the event.
Above all, the ICO is now urging organisations not to wait for an incident, but instead to take proactive steps now that will strengthen cyber security, protect people’s information and build lasting resilience.
Western Business Media Limited
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM