UK Information Commission Appoints Board; DSIT Launches Data Consultations

The U.K. government has begun a structural overhaul of its data protection oversight, transitioning the Information Commissioner’s Office (ICO) from a single-commissioner format to a corporate Information Commission. On 15 July, the Department for Science, Innovation and Technology (DSIT) announced the appointment of seven non-executive directors to the commission, a change brought by modernization provisions under the Data (Use and Access) Act.

New Board Appointments and Strategic Direction

The inaugural Information Commission Board features a mix of expertise spanning media, technology, and governance. According to the DSIT, the appointees include former international media executive Laurie Benson, former Deputy Chair of the Office of Communications Maggie Carver, and global investor Stephen Cohen. Joining them are Board of the Regulator of Social Housing member Sukhvinder Kaur-Stubbs, former IBM executive Gary Kildare, British Science Association Chair Hilary Newiss, and longtime government official Scott McPherson.

DSIT Secretary of State Liz Kendall emphasized that the board’s primary mandate is to foster public trust through cultural change. “The Information Commission must be an organisation that people trust — and trust starts with culture,” Kendall stated. The government is currently seeking a chair for the commission, with applications closing 19 August, to lead the board and work alongside Information Commission CEO Paul Arnold.

Did you know?

The new corporate structure is designed to replace the ICO’s current single-commissioner format, including a commission chair, CEO and executive directors to go with the non-executive board.

Regulatory Priorities for Data and AI

Information Commission CEO Paul Arnold outlined the agency’s new corporate strategy on 10 July, identifying a “moment of genuine tension” between the benefits of data-driven innovation and the risks posed by bad actors. The agency plans to focus its regulatory efforts on four core areas: children’s data, artificial intelligence, public sector data usage, and cyber resilience.

Regulatory Priorities for Data and AI

Arnold explicitly rejected the idea that the agency must choose between economic growth and data protection. “I do not accept that our remit means choosing between protecting people, enabling innovation and having regard for economic growth,” Arnold wrote. “If harnessed effectively, they should be inseparable.”

Consultations on Future Data Policy

To support these goals, the DSIT has launched several calls for evidence regarding the practical application of data laws. These consultations seek to bridge the gap between theoretical regulation and real-world implementation:

We can't stop AI. So we must shape it | Secretary of State Liz Kendall #ai
  • International Data Flows: Seeking input from parties with experience with international data flows in “real-world settings” to help shape future transfer policy and better understand how the U.K. General Data Protection Regulation and wider data protection frameworks operate.
  • AI and Data Interaction: Requesting practical examples of how personal and nonpersonal data regulation interacts with AI and other data-intensive technologies, as well as examples of initiatives that fail to be undertaken out of concern for potential violations of data protection law.
  • Public Sector Data Reuse: Exploring whether public bodies should be able to collect fees beyond the current legal limit in order to support increased data availability, data quality and better public services.

Standardizing the Response to Data Breaches

Alongside the board appointments, the government has released a Model Action Plan for managing “significant data breaches.” This plan defines a significant breach as an attack that affects a large number of data subjects, poses national security risks, affects multiple entities, including those that originate from third-party contractors, and likely causing significant harms.

The plan mandates a strict timeline for government agencies:

Phase Requirement
24 Hours Confirm and escalate the breach.
48 Hours Conduct risk and severity assessment.
72 Hours Report the incident to the ICO.
Pro Tip:

Frequently Asked Questions

What is the primary role of the new Information Commission Board?

The chair will be responsible for working with the board to set the strategic direction of the Information Commission, with the non-executive members working with the leadership team to help shape an organisation that is open and accountable.

Frequently Asked Questions

How does the new breach reporting process differ from previous standards?

The Model Action Plan introduces a structured approach for “significant data breaches,” requiring government agencies to report the incident to the ICO within 72 hours, preceded by confirmation and escalation within 24 hours and a risk assessment within 48 hours.

Why is the government reconsidering public sector data reuse fees?

The consultation examines if eliminating a marginal cost restriction contained in the Re-Use of Public Sector Information Regulations 2015 could support increased data availability, data quality and better public services.


Stay informed on the latest regulatory changes by subscribing to our newsletter or exploring our archives for more updates on U.K. data law.

Leave a Comment