The data protection fee is an annual payment that most UK organisations handling personal data must make to the Information Commissioner’s Office, unless an exemption applies. People still call it “registering with the ICO”, because it replaced the old registration system, and the ICO lists every fee payer on a public register.
How the data protection fee works
The fee comes from the Data Protection (Charges and Information) Regulations 2018, made under the Data Protection Act 2018. It is payable by controllers, the organisations that decide why and how personal data is used. There are three tiers, set by the number of staff and annual turnover: one for micro organisations, one for small and medium ones, and one for large ones. Charities pay the lowest tier whatever their size. The amounts change from time to time, so check the ICO’s website for the current figures rather than relying on a number quoted anywhere else.
Some organisations do not have to pay. You are exempt if the only personal data you process is for one or more of these purposes:
- staff administration;
- advertising, marketing and public relations for your own business;
- accounts and records;
- certain not-for-profit purposes;
- personal, family or household affairs;
- maintaining a public register, or judicial functions;
- processing that does not use a computer or other automated equipment.
The exemption is lost the moment you process personal data for anything else. Using CCTV to prevent crime is the classic example that catches small shops and offices, and handling personal data on behalf of clients is another. The ICO has a short self-assessment on its website that walks through the questions.
Once registered, you renew every year. The ICO sends reminders, and paying by direct debit avoids accidental lapses.
Why it matters for a UK business
The fee is one of the cheapest compliance tasks you will have, and one of the easiest for the ICO to check, because the register is public and the ICO can issue fixed penalties to organisations that should have paid and have not. It is also a visible trust signal. Larger clients and public sector buyers often ask for an ICO registration number in tenders and supplier forms, and an agency or consultant without one can look less established.
The marketing exemption causes the most confusion. A business that only markets its own products to its own customers may well be exempt. An agency or freelancer who holds client customer lists, runs campaigns with uploaded audiences or manages a client’s CRM is processing data for other purposes and should expect to pay.
Common mistakes
- Assuming a small or new business is automatically exempt.
- Forgetting that CCTV for crime prevention removes the exemption.
- Letting the registration lapse when the card on file expires.
- Staying in the wrong tier after the business grows.
- Quoting a registration number in the privacy notice that belongs to a former company or trading name.
How to act on it
Take the ICO’s fee self-assessment and keep a note of the answer and the date. If you need to pay, register under the legal entity that acts as controller, set up a direct debit and add your registration number to your privacy notice and supplier paperwork. If you are exempt, write down which exemption applies and review it whenever you add a new activity, such as CCTV, a loyalty scheme or client work.
The fee does not replace any other duty under UK GDPR; it simply funds the regulator. When I set up a digital marketing strategy for a client, I check the registration alongside the cookie and consent set-up, because both are the kind of basic item a prospective client or tender panel may look for.
