DSIT appoints 7 non-executive directors to IC Board, advertises for new Chair

Published: 15/07/2026
| Last Updated: 16/07/2026
| UK Government

The Department for Science, Innovation and Technology (DSIT) has announced the appointment of seven non-executive directors (NEDs) to the new Information Commission (IC). The new IC will replace the Information Commissioner's Office (ICO) as the UK's independent data protection authority (DPA) later in the year. 

The newly appointed NEDs are Laurie Benson, Maggie Carver, Stephen Cohen, Sukhvinder Kaur-Stubbs, Gary Kildare, Hilary Newiss, and Scott McPherson. DSIT has confirmed that the NEDs were selected in accordance with the Public Appointments Governance Code, and that they will assume their positions when the transition takes effect later this year. Each NED is appointed for an initial three-year term with an annual salary of £25,000.

In addition to these appointments, DSIT has launched a campaign to recruit the new IC Chair. The successful candidate will receive a £120,000  annual salary for 3 days of work per week. The role includes leading the board alongside the chief executive to set the strategic direction of the regulator. Applications for the role close on 19 August 2026. The consultation closes on 23 August 2026.

In a statement responding to the news, Paul Arnold MBE, Interim Chief Executive at the ICO, said he welcomed the appointments. Arnold went on to say how the regulator has been working on updating its governance arrangements for some time, noting that recent events "have brought this into even sharper focus," and that these "appointments will ensure the new Board immediately benefits from a wide range of skills and experience,  strengthening our strategic leadership and oversight."

Meanwhile, the ICO has launched a consultation about its draft corporate strategy. The strategy serves as a transitional framework from the current ICO25 strategic plan to its modernised governance structure under the IC. The consultation seeks feedback from the public, organisations, stakeholders, and parliamentarians on the regulator's draft purpose, strategic outcomes, and transformation priorities. 

In a blog post on LinkedIn, Arnold said the strategy "how we will step up to our new mandate by focusing on a clear purpose: to build trust in responsible data use and innovation, and the regulatory outcomes most likely to achieve it." Arnold was clear that the "enabling innovation and having regard for economic growth" doesn't come at the expense of protecting people or their rights. 

However, questions about how such behaviour was kept in the dark for so long remain. In a call to the prime minister-in-waiting, Andy Burnham, the Open Rights Group (ORG) highlight how the government has an opportunity to restore trust in public service delivery, as well as in a digital economy and innovation that benefits the British public. ORG argues that ICO has an important role to play, provided that the government promotes bold change and learns from past mistakes.

The meltdown of the leadership at the ICO underscores the need to restore integrity at the top. ORG recommends an overhaul of its approach, in which the monitoring and enforcement of regulatory requirements take precedence over other considerations.

In a rather unwelcome post on LinkedIn, the now disgraced former Commissioner is apparently taking credit for "these seven excellent candidates to the new board of the ICO. I insisted from the outset on a gender balance and a diversity of thought and experience." It's quite a remarkable and cynical action that one could argue reveals the bitterness and resentment underlying his true motives. 

You can't comment on the post because Edwards disabled them, but you can join the chorus of condemnation in this post by Jon Baines. 


Training announcement: Freevacy provides comprehensive training for new and existing practitioners on the changes introduced by the DUA Act to the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA18), and the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations). Our courses are always up to date and provide a forum for learning and discussing how to ensure your data protection processes remain compliant. Find out more.

Read Full Story
executive boardroom, governance report

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.