The UK Information Commissioner's Office (ICO) is the United Kingdom's independent data protection and information-rights regulator. It is being reconstituted as the "Information Commission" by the Data (Use and Access) Act 2025. Because AI systems increasingly process personal data at scale, the ICO functions as a principal UK AI-adjacent regulator, particularly for automated decision-making, biometric systems, and AI-era transparency.
| Field | Value | |
|---|---|---|
| Type | UK independent regulator | |
| Founded | 1984 (as Data Protection Registrar); reformed multiple times; being reconstituted as the "Information Commission" by the [[uk-data-use-access-act-2025 | Data (Use and Access) Act 2025]] |
| Headquarters | Wilmslow, Cheshire | |
| Information Commissioner (current) | John Edwards | |
| Known for | UK data protection enforcement; the UK GDPR; AI and automated-decision guidance; biometric policy |
Mandate
The ICO regulates the UK GDPR (the retained post-Brexit data protection regime), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations, and adjacent information-rights frameworks including the Freedom of Information Act. Its remit covers the deployed systems that process personal data, which brings much AI use within its scope.
Relevance to AI policy
The ICO is the UK's lead regulator on several AI-policy-relevant issues.
Automated decision-making (ADM) has historically been governed by Article 22 of the GDPR. The DUAA 2025 substantially narrows the default prohibition on solely automated decisions, creating a more permissive regime for many AI uses.
On AI and data protection more broadly, the ICO has published guidance covering AI generally, data protection impact assessments (DPIAs) for AI, and generative AI. It oversees biometric systems, including live facial recognition, retail surveillance, and biometric categorization, and has issued guidance on large-scale machine-learning training addressing lawful basis, data minimization, and special-category data in training datasets. The ICO's Children's Code (Age Appropriate Design Code), a pre-2023 framework, has had global influence on how platforms, including AI platforms, handle minors.
The DUAA reforms
Before the DUAA, the ICO operated under the UK GDPR as inherited from the EU, with Article 22's default prohibition on solely automated decisions that produce legal or similarly significant effects. From June 2025, the DUAA narrows Article 22, permits solely automated decisions more broadly subject to safeguards, and reconstitutes the ICO as the "Information Commission" with a revised governance structure. UK civil-society groups have criticized the change as a liberalization of UK data protection, while UK industry has welcomed it. The DUAA reforms are the principal UK divergence from the EU GDPR regime to date.
Relationship to AI governance
The ICO's remit is broadly non-overlapping with that of the UK AI Safety Institute: AISI conducts frontier-model evaluation, while the ICO covers deployed systems processing personal data. Under the UK's principles-based AI regulation approach (see CDEI/DSIT), the ICO is one of the principal sectoral regulators expected to apply AI principles within its remit. If the delayed UK AI Bill is enacted, the ICO's AI remit may be narrowed or clarified (UK AI Bill — Status and Delay (Source Summary)).
Key publications
The ICO maintains an evolving body of AI guidance, including the Guidance on AI and Data Protection and an accountability framework for AI. In 2024 it ran a set of five consultation chapters on generative AI and UK data protection. It also conducts advisory and enforcement work on biometric systems and live facial recognition.
Key people
John Edwards has served as Information Commissioner since 2022, having previously been New Zealand's Privacy Commissioner.
Relationships
- related: Data (Use and Access) Act 2025 — Source Summary — reconstitutes ICO; narrows ADM regime
- related: UK AI Bill — Status and Delay (Source Summary) — pending legislation may further reshape ICO AI remit
- related: CDEI and DSIT (UK) — parent ministerial environment
- related: UK AI Safety Institute (AI Security Institute) — complementary UK regulator
- related: CNIL (Commission nationale de l'informatique et des libertés), Irish Data Protection Commission (DPC) — parallel EU DPAs (now in separate regimes post-Brexit)
- related: General Data Protection Regulation (GDPR) — retained regulatory framework