
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

The UK’s data regulator has rebranded and restructured, but critics question the lack of data protection expertise at the top of the organisation, while lingering concerns about a “toxic workplace culture” stemming from the organisation’s leadership persist among staff.
Summary
On 30 September 2026, the UK Information Commission took over the functions of the Information Commissioner’s Office (ICO), transferring the statutory powers and responsibilities previously vested in the Information Commissioner role to a board that will instead take collective responsibility for regulatory decisions. The transition follows the resignation of the previous head, John Edwards, in June 2026, who left after an independent workplace investigation upheld multiple allegations of harassment and bullying against him. Multiple ICO sources previously told Computer Weekly in July 2026 that the regulator’s internal problems were not limited to Edwards alone, and extended to the wider leadership team, who were aware of his conduct but failed to take action to protect staff.
They specifically accused the regulator’s senior leadership – many of whom are being carried over to the new Information Commission – of upholding a toxic workplace culture that ultimately made it a “less effective” regulator. Staff response Disaffected staff, organising with the Public and Commercial Services Union (PCS), have responded to the regulator’s rebrand and restructure by holding a “day of activity” to demand accountability for the leadership’s failures. “The opening of a new headquarters and a rebrand cannot be allowed to distract from the serious concerns staff have raised about the culture within the organisation,” said PCS general secretary Fran Heathcote.
“Our members want to see real accountability, a fully independent investigation and meaningful action to ensure that everyone can work in an environment free from bullying, harassment and discrimination.” The action – which includes calling for a genuinely independent investigation into the leadership and workplace culture, and leafleting visitors and staff at the new headquarters – coincides with the opening of the regulator’s new Manchester headquarters, and the appointment of a new board. The PCS said there is growing dissatisfaction and a declining sense of pride in working at the ICO among staff, who are unhappy with the continued lack of accountability for senior leadership and conduct that has “contributed to a climate of fear” at the organisation. It added that a new name and headquarters will not, on their own, address the serious issues impacting staff well-being and safety.
According to a recent internal staff survey conducted by the ICO in the wake of Edwards’ departure, almost one in four employees had experienced or witnessed bullying, harassment or discrimination in the previous 12 months, with more than a third of those incidents allegedly involving senior staff. As a result, just 34% of employees said they felt safe speaking up or challenging the way things are done at the organisation. This marks an increase from a previous internal survey conducted in October 2025, which found that 10% of ICO staff experienced or witnessed bullying and harassment, with women twice as likely to experience that as men.
Privacy and data protection professionals outside of the ICO have also expressed concern about the internal culture and leadership of the rebranded regulator. A source close to the Information Commission told Computer Weekly that the regulator had an opportunity to reset, but that it would require new leadership. “John Edwards’ issues have really damaged the standing and the reputation of the office,” he said.
“They have got the new non-execs. They are going to have a new chair and a new permanent chief executive, so there is an opportunity for them.” But the source said the Information Commission needed to bring in a new chief executive to work alongside Edwards’ replacement if the reset was to be seen as credible. “If you just have a coronation and just say, ‘well, you have been there forever so you can just have the permanent role’, it’s not going to be seen as a step to change the culture,” he added.
The Information Commissioner’s Office has entered into 16 non-disclosure agreements with current or former employees at a cost of £354,000 since January 2022. Nine of the agreements included clauses to prevent former employees making disparaging comments about their former employer, according to a Freedom of Information disclosure published today. Another privacy professional who asked not to be named said allegations of a toxic workforce were a “monumental shambles” and a distraction for the organisation.
“It’s a big blow to the ICO at a time when it should and cold be doing some meaningful things on privacy, safety and the impact of emerging tech,” they said. An ‘independent’ review? While technology secretary Liz Kendall announced on 8 July that the government will be launching an “independent review into the culture, accountability and governance of the ICO”, this is yet to begin.
The ICO also confirmed at the time that it will be involved in the “independent review” of its workplace culture and practices. While the union sent a letter to digital secretary Lisa Nandy – who has responsibility for oversight of the commission since the government’s abolition of the Department for Science, Innovation and Technology (DSIT) – raising concerns about the safety of ICO workers and asking to set a meeting, it says it is yet to receive a response after nearly two months. The PCS has expressed concern about the lack of clear assurances over whether any investigation will have the scope and authority needed to hold those responsible accountable.
Lawrence Dunne, PCS industrial officer for the ICO, told Computer Weekly that any independent review will need to avoid the perception that the previous leadership has influence over the process, and must be “practically separate from the leadership”, as a significant part of the workforce have no confidence in their ability to deal with the issues themselves. “It’s a matter of accountability,” he said. “Ultimately before ICO can move on its workforce, and the public, frankly, they deserve answers about how it got to that stage – it was not, and it was never the case, of one bad apple.
“The allegations around Edwards and the incidents that were allowed to happen took place because of an environment that fostered this sort of behaviour unfortunately.” He also expressed “disappointment” that, despite writing to Nandy two months ago, DCMS is still yet to respond, or set a meeting with the workers or their union. Dunne concluded that an independent review is ultimately needed to establish exactly who in the senior leadership is responsible for what: “It’s not credible for them to launch a new era for the regulator – with a new building, board, name and revised powers – with the same leaders who have presided over an increasingly toxic workplace, without answers and accountability for how it got so bad.” ‘Zero-tolerance approach’ Computer Weekly contacted the Information Commission about every aspect of the story. “Our recent internal survey results come at a time of significant change for the organisation as we transition to our new governance structure and when recent events have had an impact on our people and how they feel,” said a spokesperson.
“While the majority of colleagues continue to recommend the ICO as a great place to work, any reports of bullying and harassment are treated with the utmost seriousness and a zero-tolerance approach. We already have a number of actions in place to support our colleagues and we are working with them and our trade unions to listen, learn and take action.” They added that, for the independent review, it is closely working with the Department for Digital, Culture, Media and Sport (DCMS) to finalise the terms of reference and support it to progress, but the process is taking longer than expected due to the abolition of DSIT. “Our leadership share our colleagues’ desire for this to proceed at pace and we will continue to keep staff updated,” they said.
“We take seriously our responsibility to balance both privacy and transparency in every aspect of our work. As is standard in many workplaces, we have previously agreed a small number of confidential settlements as an appropriate way to resolve employment disputes. While we do not comment on individual settlements, each is considered on its own circumstances.” Responding to Computer Weekly’s questions, a DCMS spokesperson said: “The government is committed to ensuring the Information Commission has strong governance, accountability and leadership, and that the concerns raised about its workplace culture are properly examined through an independent process.
We are progressing plans for the review and will provide further details in due course.” Neither the commission nor DCMS commented on whether Paul Arnold will need to be replaced if the regulator’s reset is to be seen as credible. A change of structure The structure of the ICO will bring it in line with other regulators, with responsibility for making decisions now being vested in a board, rather than an individual commissioner. The Information Commission appointed seven non-executive members in July 2026, who will play a role in the organisation’s governance strategy from today.
However, the structure leaves a lack of data protection expertise at the top of the organisation, with none of the non-executives having data protection expertise. “Decision-making is going to fall quite a few layers from the top,” said the source close to the ICO. “And there is a degree of uncertainty because at least with a commissioner, you know where the commissioner stands.” DCMS is recruiting for a permanent chair of the Information Commission, with a decision expected by Spring 2027.
Maggie Carver, former deputy chair of Ofcom and a company director, has been appointed deputy chair of the Information Commission. Read more about the Information Commission UK data regulator slammed over lack of action on complaints : The UK data regulator is being threatened with legal action after it was accused of ‘ignoring’ thousands of data protection complaints, with critics describing its new approach to complaint triage and investigation as akin to a ‘digital bin’ for the public’s concerns. UK data watchdog accused of dragging feet on eVisa investigation : Despite longstanding data protection issues with the Home Office’s electronic visa system being flagged five months ago, the UK’s data regulator is yet to take any action.
ICO fines Cl0p victim South Staffs Water over data breach : The ICO has levied a reduced fine on South Staffordshire Water following cyber improvements in the wake of a Cl0p ransomware attack. The new governance model for the Information Commission was established in the Data (Use and Access) Act 2025 , which received royal assent in June 2025 . The act gave the ICO powers to compel witnesses, who may be current or former employees of an organisation under investigation to attend an interview and answer questions, and to require organisations to disclose documents relevant to an investigation.
It also gained powers to introduce higher fines to organisations involved in nuisance emails, text messages and calls, raising the cap from a maximum of £500,0000 to £17.5m, or 4% of annual turnover. James Moss, director of Cyber Investigations at law firm Addleshaw Goddard, told Computer Weekly that the change in structure was an opportunity, but it was the people, rather than the structure that would make a difference. “The commission will need a strong and able chair and a strong and able permanent chief exec working alongside a senior leadership team who can effectively prioritise the work the Information Commission has in front of it, decide what they want to achieve and set about working to achieve it,” he said.
“Without those things, the change of structure risks being a missed opportunity.” Lee Ramsay, managing knowledge lawyer at law firm Lewis Silkin, told Computer Weekly that having an executive board with multidisciplinary experience would bring the Information Commission in line with other regulators. “You don’t need to have data protection specialists to be effective,” she said. “A board is really there to set strategy, provide the oversight and challenge, and then your deep technical expertise is sitting within the organisation.” Joe Jones, director of research and insights at the IAPP, a professional association for privacy professionals, said the restructuring was an overdue move.
“With a new board and recruitment underway to identify a chair, we don’t yet know whether the governance model, designed to distribute power and responsibility to a board, will form a clear identity and approach from the ICO, in the way that many past commissioners have defined and steered the ICO’s approach,” he said. Jones said the changes might result in greater consistency when leadership at the Information Commission changes, with longer-term priorities, instantiations and enforcement that “aren’t at the mercy of changes in commissioners”.
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.