Data protection
Do I need to register with the ICO, and what does it cost?
Most pages answering this publish the fee that applied before February 2025. If the number you have seen is £40 or £2,900, you are reading a page that has not been touched in two years.
The current fee
| Tier | Fee | By direct debit | You are in it if |
|---|---|---|---|
| 1 — micro | £52 | £47 | Turnover £632,000 or less, or 10 staff or fewer, or you are a charity, or a small occupational pension scheme |
| 2 — small and medium | £78 | £73 | Not tier 1, and turnover £36m or less or 250 staff or fewer |
| 3 — large | £3,763 | £3,758 | Everything else |
The amounts changed on 17 February 2025, a rise of just under 30% across all three tiers. The thresholds did not change — the turnover and headcount figures are the same ones set in 2018. Turnover and staff numbers are fixed as at the first day of the charge period, and payment is due within the first 21 days of it.
The direct debit discount is a flat —£5, which is worth almost nothing on tier 3 and about a tenth of the bill on tier 1.
The exemption is all-or-nothing
This is the single most common reason a business wrongly believes it does not have to pay. Regulation 2(1) says a controller must comply unless all of the processing it undertakes is exempt processing. Not most. All.
The exempt purposes are a short, specific list: paper-only records, personal or household affairs, maintaining a public register, staff administration, advertising and marketing for your own business, accounts and records, not-for-profit purposes, judicial functions, and elected representatives.
So a company can run entirely exempt payroll and bookkeeping, add one product with user accounts, and owe the full fee — because that one activity is outside the list and the exemption fails as a whole.
Charities are not exempt
They are routinely described as exempt and they are not. The Regulations place a charity in tier 1, regardless of its size. The same is true of small occupational pension schemes. Being in tier 1 means paying £52, not paying nothing.
If you do not pay
| Tier | Fixed penalty |
|---|---|
| 1 | £400 |
| 2 | £600 |
| 3 | £4,000 |
| Maximum | £4,350 |
The maximum applies where a business will not supply information or will not engage with the ICO. Penalty notices are issued under section 155 of the Data Protection Act 2018, and the ICO publishes the amounts under section 158.
One oddity worth flagging, since nobody else does. The ICO explains the £4,350 ceiling as “150% of the top tier fee”. That was exactly true of the old £2,900 fee. Against the current £3,763 it is no longer the arithmetic the ICO describes — but £4,350 is still the figure the ICO publishes on pages dated after the increase, so that is the number to work from. Do not let anyone quote you a higher one.
The bit that actually answers it for a software company
There are two separate questions here and almost every page collapses them into one.
| Whose data | What you are | Fee? |
|---|---|---|
| Your client’s users, in software you built and run on their instructions | Processor | No — the fee falls on controllers |
| Your own prospects, clients, marketing list, site analytics | Controller | Yes |
Which is why the practical answer for a UK studio is almost always: you pay tier 1, £52, for your own business processing — and separately you need a written processor agreement with each client under Article 28. They are unrelated obligations and satisfying one says nothing about the other.
The line that decides controller from processor is who determines the purposes and means of the processing. The ICO's own worked examples are professional ones: a solicitor is a controller for the data it processes in connection with a client's instructions, an accountant for the data in the accounts, a commissioned market research firm for the processing it determines. There is no published software-vendor example, so the application above is reasoning from those, not an ICO ruling. The ICO also notes that it is ultimately the controller's decision whether a registration is needed.
Registering is not the same as complying
A whole industry sells “get ICO registered” as though it were GDPR compliance. Read the ICO’s own wording carefully: being on the register shows that you are aware of your data protection obligations. Aware of. And on its exemptions page the ICO says that even where you are exempt from the fee, you still have to comply with your other data protection obligations.
So the fee is one annual statutory payment. Lawful basis, records of processing, DPIAs, breach reporting, subject access and security are a different set of duties, and paying £52 does not touch any of them.
Sources. Fees, tiers and the direct debit discount: ICO, guide to the data protection fee, and the Data Protection (Charges and Information) Regulations 2018. The increase: SI 2025/63, made 22 January 2025, in force 17 February 2025. Exemptions and the all-or-nothing rule: regulation 2(1) of the 2018 Regulations and the ICO’s exemptions guidance. Penalties: ICO, fixed penalties for failure to pay the data protection charge, under sections 155 and 158 of the Data Protection Act 2018. Controller and processor definitions: ICO, what are controllers and processors. All retrieved 9 October 2026. ICO guidance on fees, exemptions and the controller/processor distinction is currently marked as under review following the Data (Use and Access) Act 2025. This is a description of published material, not legal advice.
Building something that handles personal data?
The registration is the easy part. If you want the harder parts looked at — what you store, where it lives, what the processor agreement says — that is a conversation worth having early.
Start here →