#
Framework is comprehensive and stable, but amber reflects the live institutional transition (ICO to Information Commission) with an unconfirmed final transition date, plus DUAA phased commencement concluding only in June 2026.
Sub-modules (5)
Regulator And AuthorityAmber
The ICO is the UK's independent regulator for data protection and information rights, with responsibilities under DPA 2018, UK GDPR, FOIA, EIR and PECR, among other statutes. The DUAA abolishes the office of Information Commissioner and transfers its functions to a new corporate body, the Information Commission, moving from a corporation-sole model to a chair/CEO/board structure.
Claims (3):
- The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection and information rights law, with statutory responsibilities under the DPA 2018, UK GDPR, FOIA, EIR and PECR, among other acts.
- The DUAA 2025 abolishes the office of Information Commissioner and transfers its functions to a new body, the Information Commission, replacing the corporation-sole structure with a board-governed model.
- As of mid-2026, the ICO's transition to the board-governed Information Commission structure has not been assigned a confirmed final transition date; the current Commissioner is expected to become Chair, with a CEO and non-executive board being appointed.
Act And InstrumentsGreen
The operative instruments are UK GDPR, DPA 2018 and PECR 2003, amended but not replaced by the DUAA 2025.
Claims (1):
- The DUAA 2025 amends, but does not replace, UK GDPR, the DPA 2018 and PECR 2003.
Material ScopeGreen
UK GDPR/DPA 2018 apply to processing of personal data by controllers and processors; the DUAA makes targeted amendments to purpose limitation, research processing and lawful bases without expanding core material scope.
Claims (1):
- The DUAA restructures rather than materially changes the scope of what personal information organisations may use, clarifying legitimate interests, research processing and purpose limitation while preserving core UK GDPR/DPA 2018 material scope.
Territorial ScopeGreen
UK GDPR has extraterritorial reach equivalent to EU GDPR Article 3(2): non-UK controllers/processors offering goods/services to, or monitoring the behaviour of, UK data subjects fall within scope and generally must appoint a UK representative.
Claims (1):
- A UK company with active business ties to EU member states (and no EU establishment) may need to appoint an EU GDPR representative where its processing meets the Article 3(2)-equivalent destination-principle criteria, and the same logic applies to non-UK controllers targeting or monitoring UK data subjects under UK GDPR.
Regulator Registration And FilingGreen
Controllers processing personal data must generally pay an annual data protection fee to the ICO under the Data Protection (Charges and Information) Regulations 2018, across three tiers (£52/£78/£3,763), with over one million controllers on the public register.
Claims (2):
- Under the Data Protection (Charges and Information) Regulations 2018, organisations processing personal information must pay an annual data protection fee to the ICO across three tiers ranging from £52 to £3,763, unless exempt.
- The ICO maintains a public register of more than one million fee-paying data controllers, and failure to pay the required fee can result in a fixed penalty of up to £4,000.
Key findings (1)
- DUAA 2025 reached full commencement 19 June 2026. — One month to go: what businesses need to know to meet new data law
Regulator & Framework
The Data (Use and Access) Act 2025 continues its phased implementation in the United Kingdom, and the Information Commissioner's Office is understood to be reorganised into a new Information Commission carrying expanded powers and responsibilities, part of a four-stage implementation programme running through 2026.
Outlook
The precise timing of the Information Commission's formal establishment under DUAA Part 6 has not been independently confirmed this cycle, and further secondary legislation is expected before the transition completes.
Sources and claims (8)
- ConfirmedInformation Commissioner's Office — The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection and information rights law, with statutory responsibilities under the DPA 2018, UK GDPR, FOIA, EIR and PECR, among other acts.observed
- ConfirmedInformation Commissioner's Office — The DUAA 2025 abolishes the office of Information Commissioner and transfers its functions to a new body, the Information Commission, replacing the corporation-sole structure with a board-governed model.observed
- ProbableIAPP — As of mid-2026, the ICO's transition to the board-governed Information Commission structure has not been assigned a confirmed final transition date; the current Commissioner is expected to become Chair, with a CEO and non-executive board being appointed.observed
- ConfirmedInformation Commissioner's Office — The DUAA 2025 amends, but does not replace, UK GDPR, the DPA 2018 and PECR 2003.observed
- ConfirmedInformation Commissioner's Office — The DUAA restructures rather than materially changes the scope of what personal information organisations may use, clarifying legitimate interests, research processing and purpose limitation while preserving core UK GDPR/DPA 2018 material scope.observed
- ConfirmedIAPP — A UK company with active business ties to EU member states (and no EU establishment) may need to appoint an EU GDPR representative where its processing meets the Article 3(2)-equivalent destination-principle criteria, and the same logic applies to non-UK controllers targeting or monitoring UK data subjects under UK GDPR.observed
- ConfirmedInformation Commissioner's Office — Under the Data Protection (Charges and Information) Regulations 2018, organisations processing personal information must pay an annual data protection fee to the ICO across three tiers ranging from £52 to £3,763, unless exempt.observed
- ConfirmedInformation Commissioner's Office — The ICO maintains a public register of more than one million fee-paying data controllers, and failure to pay the required fee can result in a fixed penalty of up to £4,000.observed