Most people know they must file accounts and tax returns, but many company owners overlook a separate legal duty: if your business processes personal data, you usually must pay a data protection fee to the ICO (Information Commissioner's Office) and comply with UK GDPR. Failing to pay the fee is itself an offence with fines up to £4,350. This guide explains who must register, the cost, and your core obligations.
ICO & Data Protection Key Facts 2026
- Who: most organisations processing personal data must pay the fee
- Tier 1: £40 (small business/charity, low turnover and staff)
- Tier 2: £60 (medium organisations)
- Tier 3: £2,900 (large organisations)
- £5 discount: if you pay by direct debit
- Non-payment penalty: up to £4,350
Who must pay the ICO fee?
If your company is a “data controller” — deciding how and why personal data is processed — you generally must pay the data protection fee. Personal data is broad: customer names and emails, employee records, supplier contacts, CCTV, marketing lists. Almost every trading company processes some, so most must register and pay, even sole-director companies working from home.
The three fee tiers
The fee has three tiers based on size and turnover. Tier 1 (£40) covers small organisations — broadly turnover under £632,000 or fewer than 11 staff, and most start-ups and micro-businesses fall here. Tier 2 (£60) covers medium organisations. Tier 3 (£2,900) covers large ones. You get a £5 discount for paying by direct debit. The fee is paid annually.
When you might be exempt
A limited set of organisations are exempt — for example, those processing personal data only for core business purposes like staff administration, advertising their own goods, or keeping accounts, and not for anything else. In practice, the moment you use data for marketing, run CCTV, or hold customer databases beyond basic accounting, the exemption usually falls away. Check the ICO's self-assessment tool rather than assuming you're exempt.
Your UK GDPR duties
Paying the fee is separate from — and additional to — complying with UK GDPR. Core duties include: only collecting data you need, having a lawful basis to process it, keeping it secure, being transparent through a privacy notice, and honouring individuals' rights (access, deletion, correction). You must also report certain personal data breaches to the ICO within 72 hours.
Setting it up
Register and pay online at the ICO website — it takes a few minutes and you'll need basic company details and your turnover/staff numbers. Put a privacy notice on your website, keep a simple record of what data you hold and why, and diarise the annual renewal. For an e-commerce company handling lots of customer data, treat data protection as a standing part of your compliance, alongside your confirmation statement and accounts.
Start your compliant UK company
1st Formations helps you incorporate and start on the right compliance footing — fast online formation from £12.99.
View company packagesFAQ
Do I need to register with the ICO?
If your company is a data controller processing personal data — customer emails, employee records, marketing lists, CCTV and similar — you generally must pay the ICO data protection fee. Most trading companies process some personal data, so most must register, including small home-based companies.
How much is the ICO data protection fee?
There are three tiers: £40 for most small businesses (Tier 1), £60 for medium organisations (Tier 2), and £2,900 for large ones (Tier 3). You get a £5 discount for paying by direct debit. The fee is paid annually.
Is my company exempt from the ICO fee?
Some organisations are exempt if they process personal data only for limited core purposes like staff administration or basic accounting and nothing else. In practice, using data for marketing, running CCTV or holding customer databases usually removes the exemption. Use the ICO self-assessment tool to check.
What happens if I don't pay the ICO fee?
Not paying the data protection fee when required is an offence, and the ICO can impose a penalty of up to £4,350. The ICO actively contacts companies it believes should be registered, so it is not worth ignoring.
What are my UK GDPR duties beyond the fee?
UK GDPR requires you to collect only necessary data, have a lawful basis to process it, keep it secure, publish a privacy notice, and honour individuals' rights such as access and deletion. You must also report certain personal data breaches to the ICO within 72 hours.