The government has confirmed the Information Commissioner's Office will become the Information Commission on 30 September 2026. The change is the result of the Data (Use and Access) Act 2025 modifying its governance structure and regulations.
It also reminds companies of the minor changes that come with the Act. While many of the changes don’t really affect how an organisation can use personal information, there are things to know.
Changes to complaints procedures
Should an individual make a complaint to an organisation about how it uses personal information, companies need to provide an electronic complaints form. It also must acknowledge a complaint within 30 days and respond to it in a timely fashion.
Changes to the use of personal information
An organisation can use personal information to make significant automated decisions if it can show it has a valid reason or ‘legitimate interest’.
This legitimate interest needs to outweigh the impact on an individual's rights and freedoms. If the data falls into the ‘special category information’, it may not be used: information about racial or ethnic origin or sexual orientation, for example.
Charities that have collected personal information because individuals have supported, or expressed an interest in, their work can send direct marketing emails, unless the person asks the charity not to.
An organisation can give out a person’s personal information when it is needed for the purposes of ‘archiving in the public interest’. Even if the information was originally provided for a different reason, the data can still be used. (Archiving in the public interest means preserving records of public value.)
A law enforcement agency (such as the police) does not have to follow some of the usual rules about how it can use your personal information, if this is necessary to protect national security.
Law enforcement agencies and the intelligence services (such as MI5) that are working together on joint operations can work to the same intelligence services’ rules when using information, if the Secretary of State authorises this.
Cookies no longer need consent if their function is limited primarily to improve the functionality of its website.
Changes to what an organisation must do when it uses your personal information
An organisation must think about children when it uses personal information to provide online services and make sure it properly protects them.
There is no longer a need to inform people that an organisation intends to re-use their personal information for research, archiving in the public interest or generating statistics, if it would involve a disproportionate effort for it to do so. So long as it protects the individual’s rights in other ways and still explains what it’s doing by publishing details on its website.
Changes to how the law is regulated
The Act also gives the ICO stronger powers, allowing it to compel witnesses to attend interviews and request reports from approved persons.
Maximum fines for breaking Privacy and Electronic Communications Regulations (PECR) rules increase to match major data protection breaches (up to £17.5 million or 4% of global annual turnover).
For more info, please click here