ICO registration: who pays the 2026 data protection fee?
ICO registration in 2026: check whether your UK business owes the data protection fee, which activities may be exempt, how tiers work, and when to renew.

Quick Answer: ICO registration requires a UK business acting as a controller to pay the data protection fee unless an exemption applies. Every processing purpose matters. The annual tiers are £52, £78 and £3,763; staff numbers and turnover usually determine the tier. Assess with the ICO and renew every 12 months1,2,3.
Summary in a mind map
ICO registration: who pays the 2026 data protection fee? │ ├─ Duty to pay │ ├─ A controller pays unless an exemption applies │ └─ An exemption does not remove other duties │ ├─ Exemption test │ ├─ Staff administration and accounts are listed │ ├─ The listed purposes must be the only purposes │ └─ Check the complete activity inventory │ ├─ Three annual tiers │ ├─ Tier 1: £52 · Tier 2: £78 · Tier 3: £3,763 │ ├─ Staff and turnover usually determine the tier │ └─ Special categories can change the result │ └─ Action and renewal ├─ Run the ICO's two self-assessments ├─ Record the figures and fee decision └─ Renew every 12 months
Who must pay the ICO data protection fee?
An inventory of the business's controller activities is the starting point. For each activity, record whose personal data is involved and why the business handles it. The ICO's rule is direct: a controller must pay the fee when no exemption applies1; a company name, a sector label or a filing reminder cannot answer that question on its own.
For a dental practice, the useful inventory might distinguish staff administration, accounts, appointment records and clinical records. These are examples of questions to investigate, not a declaration that a particular practice owes a particular tier. The exercise tests the purposes actually served by its processing. If the organisation is uncertain whether it acts as a controller in an activity, it should settle that role before interpreting the payment rule.
A fee decision is separate from the broader question of whether data protection law governs an activity; the ICO specifically says that an organisation exempt from paying must still comply with its other data protection obligations2. Profiling customers through automated decisions involving personal data is not one of the listed exempt purposes2, so it belongs in the inventory as a separate activity.
Controller activities that qualify for exemption
The ICO's list includes staff administration, advertising, marketing and public relations, and accounts and records. It also names not-for-profit purposes, personal or household affairs, maintaining a public register, judicial functions and processing without an automated system2. The condition is that the controller processes personal data only for one or more of the listed purposes. One exempt purpose does not erase another purpose outside the list.
| Inventory question | What to record | Why it matters |
|---|---|---|
| What is the purpose? | A plain description of each controller activity | The exemption is tied to purposes, not the organisation's trading name2. |
| Is every purpose listed? | Match each activity against the ICO's list | An unlisted purpose can change the fee conclusion1,2. |
| What changed this year? | Note new services or data uses | The last assessment may no longer describe current activity. |
An office that keeps payroll and accounting information should therefore check what else it processes. The accounts and records exemption is a reason to test the full inventory, not a shortcut for declaring an entire company exempt. A marketing team should also distinguish the fee question from whether a particular message is lawful; rules for emailing businesses answer a different decision.
Determining the ICO fee tier
Once the business has established that it must pay, it can calculate the applicable tier. The ICO says the calculation depends on staff numbers, annual turnover and, for some organisations, their type3. Its fee self-assessment asks for the information needed to locate the correct tier. An organisation should retain the figures it used, the financial year to which they relate and the resulting decision.
Staff numbers are not simply the number of full-time employees on the payment date. The ICO defines members of staff broadly to include employees, workers, office holders and partners. It uses an average across completed months of the financial year and counts each part-time staff member as one3. A business near a threshold should therefore calculate the figure instead of estimating from its current payroll screen.
The special cases also matter. Public authorities use staff numbers only. Charities and small occupational pension schemes that are not otherwise exempt pay at tier 1 regardless of size or turnover3. These cases show why a generic fee chart is an aid to the assessment, never the assessment itself. The ICO's own fee tool should resolve the actual category before payment.
Tier 1, 2 and 3 amounts in 2026
The ICO publishes three base amounts. A direct debit discount may reduce the payment by £5, but it does not change the tier3. These amounts are statutory fees and the ICO says it charges no VAT on them1.
| Tier | Published amount | ICO's stated threshold |
|---|---|---|
| 1, micro organisations | £52 | Maximum turnover of £632,000 or no more than 10 staff3. |
| 2, small and medium organisations | £78 | Maximum turnover of £36 million or no more than 250 staff3. |
| 3, large organisations | £3,763 | The organisation meets neither tier 1 nor tier 2 criteria3. |
The word or matters: a business can qualify for a tier through the relevant staff condition or turnover condition described by the ICO3. A dental practice averaging 14 staff with £900,000 turnover meets neither tier 1 limit, so its fee is £78, or £73 by direct debit3. A 300-person firm with £20 million turnover still meets tier 2 through turnover3. The figures also explain why the headcount calculation deserves attention: assigning the wrong number of staff can change the apparent tier. When financial circumstances or staffing change, reassess rather than copying the amount from an old receipt.
Renewal every 12 months
The ICO says the data protection fee is paid every 12 months; coverage runs from the renewal date, not the payment date, and the ICO does not regard an organisation as covered until it receives an attributable payment1. The renewal date belongs beside the payment reference in an internal record; when responsibility moves between colleagues, this small detail helps prevent a missed anniversary.
The ICO says it contacts organisations before the previous payment expires1. That reminder is useful, but it should not be the sole record of the obligation. An organisation that changes address, payment method or internal owner can still keep a simple annual review. At that review it should ask whether its activities remain the same, whether an exemption now applies and whether the staff and turnover figures still point to the same tier. A new system for AI for order processing, for instance, adds a processing purpose to test against the list2.
Assessing the position and paying
The practical route has two assessments. First, complete the ICO registration self-assessment to check whether the organisation must pay at all1,2. Second, if payment is due, complete the fee self-assessment to identify the tier1,3. The answers, date and controller activity inventory belong together; the business can then follow the ICO's payment route and record the renewal date.
In words, the tree branches like this: if all controller processing serves only listed exempt purposes, record the exemption2. Otherwise use the ICO's fee assessment to identify tier 1, 2 or 3, pay the assessed amount and record when the next 12-month period renews1,3.
| Decision | Evidence to retain | Next action |
|---|---|---|
| Exempt | Purposes checked against the ICO list | Review when processing purposes change2. |
| Not exempt | Completed registration self-assessment | Calculate the fee tier1. |
| Tier selected | Staff average, turnover and any special category | Pay the assessed fee and record renewal1,3. |
This sequence prevents an avoidable mistake: selecting the cheapest tier before testing whether the fee is due. It also gives the next person a clear explanation of the decision. The published direct debit discount is £5 3. It is a payment option after the tier has been established, rather than a way to decide the tier.
What happens if you do not pay the fee?
Failure to pay has a separate consequence. The ICO may issue a notice of intent 28 days after expiry; the controller then has 28 days to pay or make representations. Continued failure to pay or explain why payment is no longer required may lead to a fine of up to £4,350 1. Until a controller tells the ICO otherwise, the ICO treats it as eligible for the tier 3 fee of £3,763 3. The fee assessment should therefore have a named owner and an escalation route before expiry.
What to do next
Assign one person to record the controller activities, complete the ICO's registration self-assessment and, if needed, its fee self-assessment. One record should hold the answers, relevant financial-year figures, payment reference and renewal date. The check should recur when processing changes and at the next annual renewal1,2,3.
Frequently Asked Questions
Does every UK business have to pay the ICO data protection fee?
Is a business exempt if it keeps only staff and accounting records?
How much is ICO registration in 2026?
Is the ICO data protection fee paid every year?
Does choosing direct debit change the ICO fee?
Sources
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.