If your business holds customer details, staff records, or even security camera footage, the Information Commissioner’s Office probably expects a fee from you. Most UK organisations must pay it every year, and getting the tier wrong is one of the costliest mistakes owners make.
What is the ICO Data Protection Fee?
The ICO data protection fee is an annual charge that funds the Information Commissioner’s Office, the UK’s independent data protection regulator. Under the Data Protection (Charges and Information) Regulations 2018, any organisation — including sole traders — that uses personal information has to pay it unless a specific exemption applies.
It isn’t a tax and it isn’t optional. If you process personal data as a controller, meaning you decide why and how that data is used, you’re expected to register and pay.
Why Does the ICO Charge a Fee?
Parliament sets the fee to reflect the level of risk that personal data processing presents. The money funds the ICO’s guidance work, enforcement activity, and public registers rather than general government revenue.

Who Must Pay the ICO Data Protection Fee in 2026?
Quick answer: You must pay if you’re a data controller processing personal data electronically — customer records, marketing lists, employee data, or CCTV — unless a narrow exemption applies. Holding customer contacts, running payroll, sending marketing emails, or using a CRM all typically trigger it.
Data Controllers vs. Data Processors: Who is Liable?
The fee applies to controllers, not processors. A controller decides why and how personal data is processed. A processor acts on someone else’s instructions — an outsourced payroll provider processes data on your behalf, but you usually remain the controller and the one liable. This trips people up when businesses outsource HR, IT, or marketing and assume responsibility has shifted. It usually hasn’t.
Does This Apply to Sole Traders and Partnerships?
Yes. Sole traders and partnerships are treated the same as limited companies here. If you’re weighing up sole trader vs limited company structures, note that the fee obligation follows the business activity, not the legal structure — switching from sole trader to limited company doesn’t remove it.
The 2026 ICO Fee Tiers and Costs
Fees rose across all three tiers in February 2025, and the current 2026 rates remain in place. Here’s the full breakdown:
| Tier | Who It Applies To | Standard Fee | Direct Debit Fee |
|---|---|---|---|
| Tier 1 | Micro organisations: turnover up to £632,000, or no more than 10 staff | £52 | £47 |
| Tier 2 | Small and medium organisations: turnover up to £36 million, or no more than 250 staff | £78 | £73 |
| Tier 3 | Large organisations that exceed both Tier 1 and Tier 2 limits | £3,763 | £3,758 |
You only need to meet one of the two criteria — turnover or staff numbers — to qualify for a tier, not both.
Tier 1: Micro Organisations (£52)
Most sole traders, freelancers, and very small companies land here — 10 or fewer staff, or turnover under £632,000, regardless of the other figure.
Tier 2: Small and Medium Organisations (£78)
Up to 250 staff or turnover up to £36 million — the bulk of established SMEs.
Tier 3: Large Organisations (£3,763)
Anything above the Tier 1 and Tier 2 limits defaults here. Public authorities are placed by staff numbers alone rather than turnover, which matters for public bodies with low income but larger headcounts.
How to Correctly Calculate Your Staff Headcount
This is where competitor guides tend to go vague, and it’s exactly where businesses miscalculate their tier. The ICO’s definition of “members of staff” is broader than most people expect.
- Staff includes every employee, worker, office holder, and partner — not just people on payroll.
- Each part-time staff member counts as one full member of staff. A person working two days a week counts the same as someone working five.
- Your figure is an average across the financial year, not a headcount taken on a single date.
- To calculate it properly, work out the total number of staff for each completed month of your financial year, then average those monthly totals across the year.
A professional services firm with several partners and a mix of contractors and part-timers should run this calculation properly rather than relying on a payroll headcount, since partners and office holders are often left off standard payroll reports entirely.

Who is Exempt from the ICO Data Protection Fee?
Quick answer: You’re exempt only if your processing falls entirely within specific categories such as staff administration, accounts and records, or not-for-profit membership admin. Mixing in any other type of processing, like marketing or CCTV, usually cancels the exemption.
Common Legal Exemptions Explained
You don’t need to pay if your processing is limited only to one or more of these purposes: staff administration, advertising and marketing, keeping accounts and records, not-for-profit membership activities, personal or household affairs, maintaining a public register, judicial functions, or processing that involves no automated system such as a computer. Members of the House of Lords and elected or prospective representatives have also been exempt since April 2019.
The word “only” carries real weight. A dormant company holding nothing but statutory accounting records may genuinely qualify. A trading business that also keeps customer contacts, sends marketing emails, or runs a CRM almost certainly doesn’t, even if accounts make up most of what it does.
The CCTV Trap: Why Security Cameras Trigger the Fee
This is one of the most overlooked triggers, and it catches out shops, cafés, salons, and offices that otherwise think they’re too small to register. Having CCTV on your premises for crime prevention brings you into the fee requirement, regardless of any other exemption.
It doesn’t stop at fixed cameras. A dashcam fitted to a work vehicle counts too, since business use isn’t treated as domestic use the way a personal dashcam would be.
Examples that trigger the fee even for otherwise-exempt small operations:
- A retail shop with a security camera over the till
- A tradesperson with a dashcam fitted to a work van
- A small office with a doorbell camera covering the entrance for security
If any of these apply to you, it’s worth reviewing your wider GDPR compliance setup alongside your cybersecurity arrangements, since CCTV and data security decisions often get made by whoever installs the equipment, not whoever handles compliance.
Risks and Penalties of Non-Payment
Quick answer: Failing to pay when required can result in a fine and a public listing, on top of the fee itself becoming due.
Financial Fines (Up to £4,350)
If you don’t pay, or fail to tell the ICO you no longer need to, you’ll typically get 28 days to pay or respond before a penalty notice follows. The statutory maximum is £4,350 — 150% of the top-tier fee. In practice, the ICO’s own guidance points to fines of up to £4,000 for most non-payment cases, with £4,350 as the outer limit.
Reputational Impact: The Public Register of Non-Payers
Fines aren’t the only consequence. The ICO publishes a public list of organisations issued with a penalty notice for not paying. For a business that relies on client trust, such as an accountant or healthcare provider, appearing on that list can do more damage than the fine itself.
The ICO doesn’t chase silently either. It regularly monitors the Companies House register and sends reminder letters to a business’s registered office address when it suspects trading without registration.
How to Register, Pay, and Renew in 2026
Quick answer: Register and pay online through the ICO’s website as soon as you start processing personal data. There’s no fixed annual deadline, but the fee is due from the point your business qualifies, and it renews every 12 months from registration.
Have the following ready before you start:
- Your Companies House registration number, if applicable
- An estimate of your turnover for the current financial year
- Your staff headcount, calculated using the method above
- Details of a data protection contact within the business
- Payment details, or bank details if paying by Direct Debit
Securing the £5 Direct Debit Discount
Paying by Direct Debit knocks £5 off every tier: £47 instead of £52 for Tier 1, £73 instead of £78 for Tier 2, and £3,758 instead of £3,763 for Tier 3. The saving is modest, but it also removes the risk of a missed renewal, since payment repeats automatically each year.
Using the ICO Self-Assessment Tool
If you’re unsure whether you need to pay at all, the ICO provides a free online self-assessment tool that asks a short series of questions and tells you which tier, if any, applies. It’s worth running through even if you think you’re exempt, since the CCTV and part-time staff rules above catch out businesses that assumed otherwise.
Frequently Asked Questions
Do I need to pay if I’m a sole trader with no employees?
Yes. If you process personal data as a controller — holding client records or using CCTV, for example — you still fall into Tier 1 based on turnover.
Is the fee the same as UK GDPR compliance?
No. Paying it is separate from complying with UK GDPR and the Data Protection Act 2018, and doesn’t make you automatically compliant more broadly.
What if I registered in the wrong tier?
Contact the ICO to correct it. It won’t refund fees already paid, so use the self-assessment tool before you register.
Do charities pay the same tiers as businesses?
Charities and small occupational pension schemes are automatically placed in Tier 1, unless fully exempt.

