Monday, 10 August 2026
Welcoming the ICO's Draft Corporate Strategy: Talan's Perspective

The Information Commissioner’s Office (ICO) has published its draft Corporate Strategy for 2026–2028, setting out how the UK regulator intends to build trust in responsible data use and innovation at a time of rapid technological and organisational change. Talan is pleased to see that the strategy recognises that data protection should not be treated as a brake on innovation, but as one of the conditions that enables it.
That matters because the UK is entering a more complex data economy. AI is reshaping services, cyber threats are increasing, public services are becoming more digital, and Smart Data initiatives are creating new ways for citizens and organisations to share and use information. The ICO’s strategy therefore has an important role in enabling adoption, investment and sustainable growth.
Trust as the Foundation for Innovation
The strongest theme in the ICO’s strategy is its rejection of the false choice between privacy and innovation. Responsible data use, public confidence and economic growth are presented as mutually reinforcing. This is the right framing: organisations are more likely to invest in new technologies when expectations are clear, and citizens are more likely to adopt them when they trust that their information is handled responsibly.
This is particularly important for Smart Data. Whether the aim is to help consumers share energy, finance or other personal data to access better services, trust will determine whether these ecosystems succeed. People need confidence that the organisations handling their data are accountable, transparent and subject to effective oversight.
A Clear Focus on Enabling Responsible Innovation
The strategy also places welcome emphasis on helping organisations understand not only what the law requires, but what it enables. Most organisations understand the importance of data protection, and clear, practical guidance helps them design, evidence and maintain good practice. For higher-risk activities, codes of conduct, certification and independent audit provide additional routes to translate legal principles into controls that can be tested and improved.
However, guidance and assurance must be visibly backed by effective enforcement. Organisations that invest seriously in compliance need confidence that they are operating on a level playing field, where the same expectations apply to all personal data users and poor practice does not create a competitive advantage. The strategy’s success will be judged by whether it gives responsible organisations the confidence to invest, individuals the confidence to share data, and whether new products and services prove worthy of that confidence.
A More Collaborative Regulatory Model
The strategy rightly recognises that trust cannot be built by the ICO alone. Modern data ecosystems are shaped by data protection law, sector regulation, industry standards, assurance schemes and operating licences. The strategy points in the right direction, but it does not yet do enough to position the ICO as convenor and anchor for that wider assurance ecosystem. It would be stronger if it set out how code managers, certification bodies, auditors, sector regulators and scheme operators should align around common outcomes for trustworthy data use.
Those organisations should review the draft strategy and consider whether their own frameworks, monitoring arrangements and assurance activities remain aligned with the ICO’s direction. If trusted data use is to be delivered consistently, the UK needs an approach to data protection that is applied coherently across the wider assurance community.
Reducing Burden Without Weakening Trust
The strategy should also be read alongside the UK Government’s commitment to reduce the administrative burden of compliance by 25%. This creates both an opportunity and a risk. Done well, simplification can remove duplication, improve scalability and help organisations focus on controls that genuinely protect people. Done badly, it could increase risk just as Smart Data expands access to personal data and raises the importance of trusted, repeatable assurance.
Administrative burden should be reduced through efficiencies, risk-based targeting and clearer expectations, not by weakening accountability. As Smart Data initiatives expand, assurance models must become more scalable, interoperable and outcomes-focused. The ICO is well placed to give direction, but the final strategy would be stronger if it explained more clearly how simplification, assurance and enforcement should work together to maintain trust, confidence and data security.
Leading Through Transformation
The strategy also lands during a significant period of change for the ICO itself. It acknowledges the planned transition from a single Commissioner model to a new Information Commission, with a non-executive Chair, Board and separate Chief Executive. That structural reform sits alongside wider leadership and cultural change, including John Edwards’ recent resignation, the associated independent review of the ICO’s culture, the recent appointments of an interim Chief Executive and seven new non-executives and ongoing recruitment for a new Chair.
The draft strategy recognises the formal governance transition, but less directly addresses this wider context. For industry, continuity is essential. Organisations need clarity and predictability while they are being asked to innovate, share data more confidently and invest in assurance. Internal reform should strengthen the regulator over time, but it must preserve confidence in regulatory direction, decision-making and independence.
Focusing on Areas Where Trust Matters Most
The ICO’s four priority areas — children’s data, AI transparency, responsible public sector data use and cyber resilience — are well chosen. Each is an area where trust has a direct impact on adoption and legitimacy. However, given the importance of Smart Data to the UK data economy, it would have been helpful for the strategy to include at least one priority explicitly linked to its demands. Accuracy, accountability and secure multi-party assurance will be central to Smart Data, yet are not brought through as clearly as they could be.
Conclusion
Overall, Talan welcomes the ICO’s draft Corporate Strategy. Its central proposition — that public trust, responsible innovation and economic growth are mutually reinforcing — is timely and important. The next stage must be about delivery: maintaining consistency through organisational transition, ensuring guidance is supported by effective enforcement, coordinating the wider assurance ecosystem and modernising compliance without weakening the controls that protect people.
As AI adoption, Smart Data and digital transformation accelerate, trusted data use will become a foundation of UK competitiveness. The ICO’s strategy provides a strong starting point, but it should go further in explaining how trust will be sustained across the wider assurance ecosystem. Ultimately, the ICO will be judged on whether responsible innovation grows, public confidence increases and data-driven services deliver benefits without putting personal data at unnecessary risk.
Let's Talk!
Related topics
