Legal and Compliance

Data Protection Fee

Also called ICO fee, ICO registration

An annual fee most UK organisations that process personal data pay to the ICO unless exempt, with tiers set by staff numbers and turnover.

Quick facts: Data Protection Fee

Category
Legal and Compliance
Also called
ICO fee, ICO registration
Level
Beginner
Affects
ICO compliance, tenders and supplier checks, privacy notices, agency and freelancer set-up
Where to see it
ICO fee self-assessment, ICO register of fee payers, privacy notice
In this article4
  1. How the data protection fee works
  2. Why it matters for a UK business
  3. Common mistakes
  4. How to act on it

The data protection fee is an annual payment that most UK organisations handling personal data must make to the Information Commissioner’s Office, unless an exemption applies. People still call it “registering with the ICO”, because it replaced the old registration system, and the ICO lists every fee payer on a public register.

How the data protection fee works

The fee comes from the Data Protection (Charges and Information) Regulations 2018, made under the Data Protection Act 2018. It is payable by controllers, the organisations that decide why and how personal data is used. There are three tiers, set by the number of staff and annual turnover: one for micro organisations, one for small and medium ones, and one for large ones. Charities pay the lowest tier whatever their size. The amounts change from time to time, so check the ICO’s website for the current figures rather than relying on a number quoted anywhere else.

Some organisations do not have to pay. You are exempt if the only personal data you process is for one or more of these purposes:

  • staff administration;
  • advertising, marketing and public relations for your own business;
  • accounts and records;
  • certain not-for-profit purposes;
  • personal, family or household affairs;
  • maintaining a public register, or judicial functions;
  • processing that does not use a computer or other automated equipment.

The exemption is lost the moment you process personal data for anything else. Using CCTV to prevent crime is the classic example that catches small shops and offices, and handling personal data on behalf of clients is another. The ICO has a short self-assessment on its website that walks through the questions.

Once registered, you renew every year. The ICO sends reminders, and paying by direct debit avoids accidental lapses.

Why it matters for a UK business

The fee is one of the cheapest compliance tasks you will have, and one of the easiest for the ICO to check, because the register is public and the ICO can issue fixed penalties to organisations that should have paid and have not. It is also a visible trust signal. Larger clients and public sector buyers often ask for an ICO registration number in tenders and supplier forms, and an agency or consultant without one can look less established.

The marketing exemption causes the most confusion. A business that only markets its own products to its own customers may well be exempt. An agency or freelancer who holds client customer lists, runs campaigns with uploaded audiences or manages a client’s CRM is processing data for other purposes and should expect to pay.

Common mistakes

  • Assuming a small or new business is automatically exempt.
  • Forgetting that CCTV for crime prevention removes the exemption.
  • Letting the registration lapse when the card on file expires.
  • Staying in the wrong tier after the business grows.
  • Quoting a registration number in the privacy notice that belongs to a former company or trading name.

How to act on it

Take the ICO’s fee self-assessment and keep a note of the answer and the date. If you need to pay, register under the legal entity that acts as controller, set up a direct debit and add your registration number to your privacy notice and supplier paperwork. If you are exempt, write down which exemption applies and review it whenever you add a new activity, such as CCTV, a loyalty scheme or client work.

The fee does not replace any other duty under UK GDPR; it simply funds the regulator. When I set up a digital marketing strategy for a client, I check the registration alongside the cookie and consent set-up, because both are the kind of basic item a prospective client or tender panel may look for.

Do and do not

Do

  • Take the ICO's self-assessment and record the answer
  • Pay by direct debit so the registration never lapses
  • Show your registration number in your privacy notice

Do not

  • Assume a small business is automatically exempt
  • Forget that CCTV for crime prevention changes the answer
  • Quote fee amounts from memory instead of the ICO's site

Questions people ask about this

Do sole traders need to pay the ICO data protection fee?

Many do. Being a sole trader does not exempt you; what matters is why you process personal data. If your only processing is staff administration, your own marketing and your accounts, you may be exempt, but CCTV for crime prevention or handling client data would bring you into the fee. Take the ICO's self-assessment to be sure.

How much is the ICO data protection fee?

It depends on your tier, which is based on staff numbers and turnover, and the ICO revises the amounts from time to time. Check the ICO's fee page for the current amounts and for any discount offered for paying by direct debit.

How can I check whether a company has paid the ICO fee?

Search the ICO's public register of fee payers on its website by company name or registration number. The entry shows the organisation's name, address and registration dates. If a supplier says it is registered and you cannot find it, ask which legal entity the registration is under.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.