On 30 September, the Information Commissioner’s Office stops being run by a single Information Commissioner and becomes the Information Commission, a board-led regulator with seven non-executive members taking up their roles that day. It’s a governance change made under the Data (Use and Access) Act 2025, and the regulator has confirmed it will still be known day-to-day as the ICO. But if your business has “Information Commissioner’s Office” written into privacy notices, contracts, or supplier agreements, this is the week to notice it, even if nothing needs fixing urgently.
The reason this matters for UK SMEs isn’t the governance structure, which is genuinely just internal housekeeping for the regulator. It’s that every business handling personal data has ICO references scattered through its compliance documents, and a regulator changing its legal name is exactly the sort of detail that gets missed for years until it surfaces in a due diligence check or a client’s supplier audit.
What doesn’t change
Nothing about your actual obligations shifts on 30 September. Data breach reporting timelines, UK GDPR duties, subject access request deadlines, and the regulator’s enforcement powers all carry over unchanged. If you were compliant on 29 September, you’re still compliant on the 30th. This is not a new compliance deadline in the way a genuine regulatory reform would be, and nobody needs to panic or rush anything through this week.
What’s worth a look
Where it does matter is anywhere your business has formally named the regulator in writing:
- Privacy notices and cookie policies that reference “the Information Commissioner’s Office” by its full legal name, particularly if they were drafted by a solicitor and use precise regulatory language.
- Data processing agreements and supplier contracts that name the ICO as the relevant supervisory authority.
- Internal data protection policies and staff training materials that reference reporting a breach “to the ICO.”
None of this needs fixing today. But the next time you’re updating your privacy notice for any other reason, whether that’s a new tool you’ve adopted or a routine annual review, this is the moment to swap the wording over rather than doing it as a standalone task later. Keeping documents accurate isn’t about ticking a box; it’s the kind of small consistency that a diligent client, insurer, or investor notices when they’re checking how seriously you take your paperwork.
It’s also worth remembering the ICO isn’t a small, rarely-used regulator. It handles hundreds of thousands of data protection queries and complaints a year, and it’s the body you’d be dealing with directly if your business ever had a breach serious enough to report. A regulator confident enough to restructure its own governance while keeping every enforcement power intact isn’t one that’s about to go quiet, so this is a reasonable moment to check your business is actually ready to deal with it if it ever needed to.
Getting the wording right without a solicitor’s bill
If your privacy notice, data processing agreement, or breach response policy hasn’t been properly reviewed in a while, a regulator rename is as good a prompt as any to fix that properly rather than patching one word. Smallprint’s UK-specific legal document templates cover exactly this kind of data protection paperwork, built to stay current with actual regulatory names and requirements, so you’re not relying on a document that was accurate three years ago and has quietly drifted out of date since.
The takeaway
The regulator changing its name doesn’t create a new deadline, but it’s a useful nudge to check when your data protection documents were last properly reviewed. If the honest answer is “a while ago,” treat this as the reminder rather than waiting for the next reason to come along.