If you run a small business in the UK and you process personal data — which almost every business does — there’s a good chance you’re required to pay an annual fee to the Information Commissioner’s Office. And there’s also a decent chance you either don’t know about it, or know about it vaguely but haven’t got round to sorting it.

The ICO’s data protection fee isn’t optional, it’s not particularly complicated, and the consequences of ignoring it are disproportionate to the minor administrative effort required to register. So let’s go through what it actually is.

What the Fee Is For

The data protection fee replaced the old data protection notification system that used to exist under the 1998 Data Protection Act. Under UK GDPR and the Data Protection Act 2018, most organisations that determine how personal data is used — what the law calls data controllers — must pay an annual fee to the ICO.

The ICO uses this money to fund its regulatory work: investigating complaints, issuing guidance, enforcing data protection law, and generally running the UK’s data protection regime. In 2025/26, the fee raised around £56 million from registered organisations.

The amount you pay depends on the size of your organisation:

Tier 1 — organisations with a turnover below £632,000 or fewer than 10 members of staff pay £40 per year.

Tier 2 — organisations with turnover above £632,000 but below £36 million, or between 10 and 250 staff, pay £60 per year.

Tier 3 — large organisations (over £36 million turnover or more than 250 staff) pay £2,900 per year.

If you’re a sole trader, a micro-business, or a small charity, you’re almost certainly in Tier 1. Forty pounds a year. That’s it.

Who Needs to Register

The rule is: if you’re a data controller and none of the exemptions apply to you, you need to pay the fee.

A data controller is an organisation or individual that decides why personal data is collected and how it’s used. If you store customer names and email addresses in a spreadsheet, you’re a data controller. If you have a CRM with client details, you’re a data controller. If you process employee payroll information, you’re a data controller.

The exemptions are where people get confused. Some businesses genuinely don’t need to pay because they only use personal data for exempt purposes. The main exemptions include:

  • Processing data solely for personal, family, or household purposes (this doesn’t apply to businesses)
  • Certain not-for-profit organisations with limited processing
  • Organisations that only process personal data for staff administration, advertising their own goods and services, and accounts and records — but only if all three of those activities together represent the entirety of the processing

That last exemption is narrower than people think. If you also send marketing emails, run a website with cookies, have a customer database, or use CCTV, you’re outside the exemption and you need to register.

The ICO has a self-assessment tool on its website that takes about two minutes and tells you whether you need to pay. If you’re unsure, use it.

What Happens If You Don’t Register

The ICO actively enforces the registration requirement. It identifies unregistered organisations through complaints, through its own investigations, and by cross-referencing Companies House data with the registration database.

Fixed penalty notices for not being registered start at £400. For organisations that ignore the notice or have a history of non-compliance, enforcement escalates. The ICO has issued fines running into tens of thousands of pounds for persistent non-registration, which is obviously wildly disproportionate to the £40 you’d have paid in the first place.

Worth noting: not being registered doesn’t give you any protection. You still have all the obligations under UK GDPR. You still have to comply with data subject access requests, implement appropriate security measures, have a lawful basis for processing, and all the rest. You’ve just also failed to pay the registration fee on top of your other obligations.

How to Register

It takes about ten minutes and can be done entirely online at ico.org.uk. You’ll need a debit or credit card for payment.

You’ll be asked for basic details about your organisation, the nature of the personal data you process, and roughly how many individuals you hold data about. You’ll be prompted to select a fee tier based on your organisation’s size.

Once registered, the ICO sends you a certificate that you can display if needed. You’ll receive a renewal reminder by email before your annual fee expires. If your organisation changes significantly — becomes substantially larger, changes the nature of what it processes — you may need to update your registration tier.

One thing people sometimes miss: if you’re a sole trader and also a company director of a limited company, the company and the sole trader are separate legal entities with potentially separate registration obligations.

Other Compliance Points While You’re Here

Registration doesn’t mean you’re GDPR compliant — it just means you’ve met the registration requirement. The substantive UK GDPR obligations are separate and more involved.

But if you haven’t registered and you’re not exempt, that’s the first thing to fix today. The ICO’s enforcement action for non-registration is the most avoidable penalty in UK data protection law. Forty pounds a year, a few minutes to register, and one fewer compliance gap to worry about.

The ICO website has a public register of data controllers, so anyone — including your customers, prospective clients, or the ICO itself — can check whether your organisation is registered. Being absent from that register when you should be there is a straightforwardly visible compliance failure.

Get registered. Renew annually. And while you’re on the ICO website, have a look at their guidance for small businesses — it’s genuinely accessible and covers the practical obligations in plain English.