ICO Enforcement Reform: What UK Boards Must Prove in 2026
UK boards must now evidence data protection accountability more rigorously: the Data (Use and Access) Act 2025 (DUAA) commenced most of its remaining provisions on 5 February 2026, handing the ICO sharper enforcement tools.
The DUAA amends UK GDPR and the Data Protection Act 2018 rather than replacing them, but the practical effect for boards is significant: new lawful grounds for processing, a formal complaints-handling obligation, and a regulator entering 2026 with a track record of record fines and reach it did not previously have. For NEDs whose exposure to data protection has historically been limited to an annual compliance update, this is the year the ICO’s posture changes from guidance to enforcement.
What Does the Data (Use and Access) Act Actually Change?
The DUAA introduces new “recognised legitimate interests” that simplify some processing decisions, but it also tightens accountability elsewhere — including automated decision-making safeguards and international transfer mechanisms. Most substantive provisions commenced on 5 February 2026, but the board-relevant deadline is 19 June 2026: the date by which every organisation processing personal data must have a formal, documented complaints-handling procedure in place. That deadline has already passed for this run’s audience, which makes it a live compliance gap, not a future one.
Executive Action:
- Confirm the mandatory complaints-handling procedure, due 19 June 2026, is documented, live and being tracked — not just drafted.
- Ask the DPO or general counsel for a DUAA gap analysis against current data processing practices.
- Require quarterly reporting on complaint volumes and resolution times to the audit or risk committee.
Why Is ICO Governance Itself Changing?
The ICO is moving from a single-commissioner model to a board-run structure, intended to bring broader expertise and match its expanding statutory workload. Commissioner John Edwards is expected to chair the new board while additional non-executive members are appointed by government. For regulated organisations, a better-resourced, board-governed ICO with a wider remit typically means more consistent — and more assertive — enforcement, not less.
Executive Action:
- Treat any current ICO correspondence or informal enquiry with the seriousness it would receive from a fully-resourced regulator.
- Review whether the company’s last data protection impact assessment predates the DUAA changes.
What Should Boards Ask About Enforcement Risk?
The ICO also consulted through to January 2026 on new procedural guidance covering how it conducts investigations and applies its enforcement powers under UK GDPR and the Data Protection Act 2018. Boards should ask management not just “are we compliant” but “how would we respond if the ICO opened a formal investigation tomorrow” — including who owns the response, what the escalation path is, and whether legal privilege is protected from the outset.
Executive Action:
- Request a documented ICO investigation response plan, including named owners and an escalation path to the board.
- Confirm legal privilege protocols are in place before any incident, not drafted reactively during one.
- Benchmark the response plan using INFORMD’s governance self-assessment tools.
How Should Directors Evidence Personal Accountability?
Director accountability for data protection failures sits within existing Companies Act 2006 duties — particularly the duty to promote the success of the company and to exercise reasonable care, skill and diligence. Boards should not wait for an ICO enforcement notice to demonstrate that data protection was a standing governance item, with minuted discussion, rather than a once-a-year briefing slot.
Executive Action:
- Add data protection accountability as a standing quarterly board or audit committee agenda item, minuted accordingly.
- Require the DPO to report directly to the audit or risk committee, not solely through the executive team.
What Should the Board Approve Before Year-End?
This is a genuine NED-level responsibility: approving the organisation’s data protection risk appetite and confirming that management’s DUAA remediation plan is adequately resourced. Boards that treat this as a pure compliance exercise, delegated entirely downward, will struggle to demonstrate the “reasonable steps” defence that regulators and courts increasingly expect.
Executive Action:
- Formally approve the DUAA remediation plan and its resourcing at board level before year-end.
- Document the board’s data protection risk appetite explicitly, rather than inferring it from past practice.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
The DUAA amends UK GDPR and the Data Protection Act 2018. Most provisions commenced on 5 February 2026, introducing new lawful processing grounds alongside tighter accountability requirements, including a mandatory complaints-handling procedure that took effect on 19 June 2026.
By 19 June 2026, every organisation processing personal data was required to have a formal, documented complaints-handling procedure in place under the DUAA. Boards should confirm this is operating, not merely drafted.
The ICO is moving from a single-commissioner model to a board-run structure to bring broader expertise and match its expanding statutory workload, signalling more consistent and assertive enforcement ahead.
Make data protection a standing, minuted board or audit committee agenda item, require the DPO to report directly to that committee, and formally approve the organisation’s data protection risk appetite and remediation plans.
