On 30th September 2026, the Information Commissioner's Office formally became the Information Commission under the Data (Use and Access) Act 2025. The Commission is now run by a Board rather than a single Commissioner, but it will still be known as the ICO.
Here's what schools, Data Protection Officers (DPOs), and trust governance boards need to know for operations, documentation, and compliance.
Should Schools Immediately Press "CTRL+F" and Update Every Document?
- No panic updates are required.
- Under the new legislation, existing legal references to the Information Commissioner are read as references to the Information Commissioner in legislation and documents are read as references to the new Information Commission. This means legacy privacy notices, policies, and contracts remain valid, and you do not need to reissue documentation or update policies overnight.
However, keeping references up to date as part of a rolling review plan matters for three practical reasons:
- Privacy notices set out individual rights, including the right to lodge a complaint with the supervisory authority. Updating these references during your scheduled annual review cycle demonstrates good governance.
- Data protection policies, breach response plans, and Subject Access Request (SAR) procedure documents outline how and when the school escalates serious incidents or unresolved complaints. Internal escalation templates should reflect the Information Commission (operating as the ICO) as the supervisory body.
- When local authorities, external auditors, or the regulator inspect a trust's compliance framework, ensuring your documentation is periodically refreshed shows that your governance framework is actively maintained.
Action Checklist for Schools and DPOs
- Reassure your teams: Existing privacy notices and contracts remain valid. Ensure key staff are aware of the governance change so there is no confusion if formal correspondence arrives referencing the "Information Commission".
- Review contact details during annual updates: Check the postal address on your templates against the ICO's official 'Contact Us' page.
- Update documents during your standard annual review cycle: Update both public facing and internal documentation:
External
-
- Parent, Pupil, Staff, and Governor Privacy Notices
-
- Subject Access Request (SAR) letters and complaint templates
-
- School Website Data Protection / Privacy Pages
- Data Protection Policy and Freedom of Information (FOI) Publication Scheme
- School Website Data Protection / Privacy Pages
Internal
-
- Data Protection Impact Assessment (DPIA) templates
-
- Personal Data Breach Response and Notification Procedures
-
- Data Processing Agreements (DPAs) and Vendor Due Diligence Questionnaires
-
- Staff Data Protection Training Modules & Induction Slides
- Data Protection Policy
- Staff Data Protection Training Modules & Induction Slides
Note: DPE templates will be updated to reflect these recommended wording changes.
The Bottom Line
The regulator's legal structure may have evolved to a Commission, but everyday operations and "ICO" branding remain the same. For schools, the change requires no immediate emergency action but it provides a clean milestone to audit your documentation, refresh your privacy notices, and ensure your schools data governance framework remains up to date.
Further Reading: ICO welcomes transition to new Information Commission
