Glossary · Who is regulated

Information Commission

Definition

The Information Commission is the UK regulator that replaced the Information Commissioner under the Data (Use and Access) Act 2025. Under the Cyber Security and Resilience Bill it is the competent authority for relevant digital service providers and relevant managed service providers across the UK, and it can designate their critical suppliers.

What does the Information Commission do under the Bill?

It is the single UK-wide regulator for relevant digital service providers and relevant managed service providers. It maintains the registers, publishes guidance that RDSPs and RMSPs must have regard to, receives incident notifications, can direct providers to inform customers or the public, and enforces through information notices, inspections, enforcement notices and penalties.

It can also designate critical suppliers to RDSPs and RMSPs, although that power cannot commence until the first Part 3 activity-critical supply regulations are in force.

Why does the name matter?

The Data (Use and Access) Act 2025 replaced the Information Commissioner, a single office holder, with a body corporate called the Information Commission. The Bill reflects that change, so references to the "ICO" or "Information Commissioner" in older guidance about the NIS Regulations now mean the Information Commission. The same body also regulates data protection, which matters where a cyber incident is also a personal data breach.

In practice, an RDSP or RMSP may deal with the same regulator twice over for one incident: once under the NIS Regulations, with the 24-hour and 72-hour clocks, and once under UK GDPR if personal data is involved. Those are separate legal duties with separate deadlines, so incident plans should treat them as two workstreams.

Where it appears in the Bill

  • cl.9(7), reg 3(2)Competent authority for RDSPs and RMSPs.
  • cl.14, regs 14 and 14CRegisters of RDSPs and RMSPs.
  • cl.15, new regs 12A and 14EReceives incident notifications.
  • cl.12, new reg 14H(2)Critical supplier designation for RDSP and RMSP supply chains.
  • cl.19, new reg 3(4A)Minimum content of its guidance.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Is the Information Commission the same as the ICO?

It is the successor body. The Data (Use and Access) Act 2025 replaced the Information Commissioner with the Information Commission, a body corporate. It carries on the same data protection and NIS functions, and the Cyber Security and Resilience Bill adds new responsibilities for managed service providers and critical suppliers on top.

Do RMSPs register with the Information Commission?

Yes. New reg 14C requires an RMSP to submit its name, address, directors or partners and contact details before the registration date: 3 months after section 14 commences, or 3 months after it first meets the RMSP test. Changes must be notified within 7 days. The Commission shares the register with GCHQ.

Does the Information Commission regulate operators of essential services?

No. Operators of essential services are regulated by the competent authority for their subsector in Schedule 1 of the NIS Regulations, such as Ofcom for data centres. The Information Commission may be consulted, for example on critical supplier designations or where an incident involves personal data.

Related guidance

Official sources

More in Who is regulated

Full glossary