Back to Blog

PolicifyAI

Published July 2026 · 3 min read

Small Business

The ICO Data Protection Fee: Does Your Small Business Have to Pay?

Most UK businesses that handle personal data owe the ICO an annual fee - and many small firms only find out when the penalty letter arrives. The tiers, the exemptions, and how to register.

The fee most new business owners have never heard of

Under the Data Protection (Charges and Information) Regulations 2018, every UK organisation that processes personal data as a controller must pay an annual fee to the ICO unless an exemption applies. It funds the regulator, it is separate from having a privacy policy, and ignorance is not a defence - the ICO runs regular letter campaigns cross-referencing Companies House registrations against its fee register.

For most small businesses the practical question is simple: which tier are you in, or are you exempt?

The three tiers (raised in February 2025)

  • Tier 1 - micro organisations: maximum turnover £632,000 or no more than 10 staff -£52 per year
  • Tier 2 - small and medium organisations: maximum turnover £36 million or no more than 250 staff -£78 per year
  • Tier 3 - large organisations: everyone else -£3,763 per year

Charities and small occupational pension schemes pay the Tier 1 rate regardless of size, and there is a £5 discount for paying by direct debit. The overwhelming majority of new businesses fall into Tier 1: about the price of a coffee per month.

Who is exempt?

You do not have to pay if you only process personal data for a short list of "core purposes":

  • Staff administration (payroll, recruitment)
  • Accounts and records (invoicing customers and suppliers)
  • Advertising, marketing and PR for your own business
  • Not-for-profit purposes (many small clubs and community groups)
  • Personal, family or household affairs

Sounds generous - but the exemption collapses the moment you go beyond those purposes. In practice, two things drag small businesses back into paying:

  • CCTV: using cameras for crime prevention - a shop, café, or workshop with CCTV almost always owes the fee
  • Anything beyond the basics: profiling customers, sharing data with third parties for their purposes, or processing at a scale beyond simple record-keeping

Because the line is genuinely fuzzy, the ICO provides a short online self-assessment. It takes under five minutes, and if it says you are exempt, keep a note of the date and your answers.

What happens if you don't pay

Failing to pay when required is not a GDPR fine - it is a separate fixed penalty of up to 150% of your tier's fee, on top of still owing the fee itself. The ICO publishes lists of penalised organisations, and its enforcement letters have become a rite of passage for new limited companies. For £52, it is not a risk worth taking.

How to register (it takes minutes)

  • Complete the self-assessment on the ICO website to confirm you need to pay
  • Register online with your company details and a payment method - direct debit is cheapest and auto-renews
  • Diarise the renewal if you paid by card; letting the fee lapse counts as non-payment
  • Your entry appears on the public register of fee payers - a small trust signal customers and partners occasionally check

Common scenarios

  • Freelancer with a laptop and invoices only: likely exempt (accounts and records) - but run the self-assessment to be sure
  • Online shop with a marketing list: marketing your own business is technically a core purpose, but shops using ad pixels, profiling tools, or analytics platforms typically fall outside the exemption - most pay Tier 1
  • Café with CCTV: pays - CCTV for crime prevention is the classic exemption-breaker
  • SaaS startup processing customer data: pays - processing user data to deliver a product is well beyond the core purposes

Frequently asked questions

Do sole traders have to pay the ICO fee?

Yes, if they process personal data as a controller and no exemption applies. The fee duty attaches to the business activity, not the company structure.

Is paying the fee the same as being "GDPR compliant"?

No. The fee is just registration. You still need a lawful basis, a privacy policy, security measures, and a way to handle rights requests - the fee covers none of that.

I only use my customer data for invoicing. Am I exempt?

Probably, under the accounts-and-records purpose - but confirm with the ICO self-assessment and keep a record of the result, because the exemption is lost the moment you add CCTV, profiling, or data sharing.

Need a policy for your business?

Generate a legally-formatted, AI-reviewed policy in under 60 seconds.

Generate your policy

Keep reading

All articles