ICO morphs into Information Commission
As of the 30th September the Information Commissioner’s Office officially becomes the Information Commission, although it will continue to be known at the ICO (Information Commission’s Office). A subtle tweak of name bringing with it a significant change to how the regulator is governed, but no change to its core functions or responsibilities.
The ICO has faced considerable criticism in recent years. Its failure to fully investigate the Ministry of Defence’s devastating disclosure of the personal details of thousands of Afghans who’d worked with British forces. Its policy of routinely only issuing reprimands and not fines to public sector bodies. Its failure to tackle a growing backlog of complaints. Criticism which reached a fever pitch earlier this year when Information Commissioner, John Edwards, was the subject of a workplace investigation which culminated in his resignation. This has led to accusations senior management allowed certain behaviour to continue unchecked.
Against this backdrop, can the new Information Commission steer a brighter path, and will we actually see any material change?
Governance
Until now, the ICO operated as a corporation sole, with powers and responsibility vested in the Information Commissioner. Those functions have transferred to the Information Commission; a corporate body whose executive and non-executive members now share responsibility for decision-making.
This brings the ICO in line with other UK regulatory bodies such as Ofcom, and the Government hopes this will usher in a broader range of skills, experience and perspectives.
Key people
Paul Arnold is the interim Chief Executive Officer managing day-to-day operations, overseeing casework and enforcement. He’ll act as a key link between the Board and the organisation.
The board comprises a chair, seven non-executive board members, along with the CEO (an executive member), and there’s provision for other executive members to be appointed.
Unfortunately, the Commission had to launch chair-less. While applications for the role closed in mid-August an appointment has yet to be made. Paul Arnold is expected to act as interim chair.
Earlier this Summer the following seven non-executives were appointed and have now officially taken up their roles:
■ Laurie Benson is a former international media executive and experienced board director, with senior roles in broadcasting, publishing, technology and digital media. She was an early member of the CNN team, and former Managing Director of Bloomberg Media EMEA. She describes herself as a London-based American.
■ Maggie Carver was deputy chair of Ofcom until 2024 where she is described as leading preparations and working closely with the government on online safety regulation. This is relevant to the Commission’s focus on children’s privacy and online harms.
■ Stephen Cohen has spent 35 years in executive roles in global asset management, investment strategy and corporate governance. He set up two businesses in Japan and lived there for seven years.
■ Sukhvinder Kaur-Stubbs sits on the Board of the Regulatory of Social Housing, chairs the Independent Customer Challenge Group at Thames Water and is a member of the RICS Standards and Regulation Board.
■ Gary Kildare spent more than three decades at IBM, where he was a member of the Senior Leadership Group, he also holds a number of public sector and regulatory board roles.
■ Hilary Newiss is Chair of the British Science Association and a former partner in a law firm specialising in intellectual property, and is said to maintain a keen interest in data law and privacy.
■ Scott McPherson is a career civil servant with more than 25 years in government, including Director General roles across four departments.
The Government says the NEDs will play a key role in providing strategic leadership, oversight and accountability to the Commission.
I know NEDs are often chosen for their broad, complimentary and cross-sector experience, but I’m surprised there are no NEDs with specific data protection expertise. To my mind this risks the board not having the skills to effectively scrutinise nuanced subject matter related decisions or perhaps they could fail spot when something doesn’t quite add up. It means the board may not have a level of specialist knowledge to challenge executive decisions which are founded in the data protection space.
Regulatory functions
As said, the ICO’s functions remain unchanged and continue to include overseeing how organisation’s comply with UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). On this front, it will be business-as-usual; handling complaints, investigating personal data breaches and taking enforcement action.
Regulatory focus
During the Summer the ICO published its draft strategy. This doesn’t mark a seismic shift in focus, with children’s privacy, responsible AI use, building trust in public services’ use of personal data and enhancing cyber security, at its heart. Although it does seem a little strange this was published before approval by the new board. A key role of any board should be to set the strategic direction, so this isn’t filling me with confidence. You can read more about this here: ICO priorities
What action do organisations need to take?
This is the simple bit; you don’t need to do anything. Existing references to the Information Commissioner’s Office in legislation are to be read moving forward as references to the Information Commission, so contracts and policies do not need updating. You may however want to update the name in public facing documents, such as privacy notices.
What next?
I believe many have lost faith in the ICO and would like to see a more robust stance. It’s not easy; whether led by a sole Commissioner or a Commission board, the regulator has a difficult tightrope to walk. Balancing enforcement with its remit to promote growth and innovation. I personally don’t think we’ll see much change, certainly not in the short term. It remains to be seen how much influence the non-executives and the new Chair, whoever that might be, will actually manage to exert in practice.