Organisations using personal information may need to pay the ICO data protection fee unless an exemption applies. Assess the actual processing and current criteria, including where the organisation is a sole trader. Small size alone should not be treated as a universal exemption.
Use the ICO's assessment route and record the answers and outcome. If payment is required, confirm the correct tier and current amount directly with the ICO. Paying the fee is a separate obligation from complying with data protection requirements; it is not a certification of all business practices.
Identify the organisation and actual processing
Start with the legal entity responsible for the activities. A trading name, branch or shared office does not necessarily identify a separate organisation for fee purposes. List the personal information uses actually carried out, including client work, staff administration, CCTV and online enquiries where relevant. Do not answer the assessment using only the activity that occupies the largest part of the business if other processing changes the position.
The ICO provides a current fee assessment and payment route. [1] Use it directly and keep a dated record of the answers and outcome. Small size, low turnover or working from home should not be treated as a universal exemption without applying the relevant criteria. If the answers depend on a fact that nobody has checked, resolve that fact instead of choosing the answer most likely to avoid payment.
Distinguish an exemption from general compliance
A fee exemption concerns that particular obligation. It does not certify that the organisation's notices, security, marketing or retention practices comply with data protection law. Similarly, payment is not approval of a new processing activity. Keep the fee record alongside, but separate from, the wider privacy work so management does not assume one annual payment replaces ongoing responsibility for information handling.
Where several group companies or professional entities share systems, assess who acts as controller for the relevant activities. Do not assume a payment by one familiar group name covers every legal person. Record uncertain entity or role questions for advice. The guide to Keeping a record of processing activities helps build the activity inventory needed to answer the assessment accurately rather than relying on a vague description of the business.
Check tier information and avoid payment mistakes
If a fee is payable, use the current ICO criteria and amount rather than a figure copied from an old article. Confirm the relevant staff and turnover information with the person responsible for accounts, including how the assessment defines those measures. Avoid assuming that a recent change in trading volume automatically moves the organisation into or out of a tier without checking the applicable rules.
Use the official payment route and verify any unexpected invoice or reminder independently. Keep the organisation's reference and receipt in a controlled administrative record. A supplier offering a paid registration service is not the same as the regulator requiring that additional service. Staff should know where to find the genuine renewal information so an urgent-looking message does not lead to duplicate or misdirected payment.
Assign renewal and change responsibilities
Give renewal to a named role with a deputy and a monitored contact address. Record the renewal date in the business calendar and check that confirmation reaches the correct entity. When an administrator leaves, transfer responsibility for the reminder and payment record rather than leaving it in a personal mailbox. A direct debit arrangement still needs oversight if company details or the relevant assessment changes.
Set a reassessment trigger when the organisation introduces a materially different use of personal information. A business relying on an administrative exemption may need to revisit its position after expanding client services or installing a new monitoring activity. Keep the previous assessment so the reason for the change is understandable. Use Privacy notices for UK small businesses to review whether the same operational change also affects information given to individuals.
For Business privacy notice review, provide the actual processing list, entity structure and any uncertain assessment answers. Ask for clarification of the relevant role or exemption question rather than a general promise that the business is GDPR registered. The practical outcome should identify whether payment is needed, who completes it and what evidence is retained. Broader privacy improvements should remain visible as separate actions with their own owners and completion dates.
Investigate an unexpected payment reminder
Compare a reminder with the organisation's own registration details and the official route before paying. Check the legal entity, reference, payment history and renewal owner. A trading-name change, duplicated supplier record or forwarded letter can make an ordinary administrative issue look like a new obligation.
If the business believes an exemption applies, retain the assessment and the facts supporting it, then revisit those facts when activities change. Do not regard the absence of a reminder as proof that no fee is due. Equally, do not let a payment request from an intermediary replace the organisation's own check. Keep correspondence accessible to a deputy so an absent finance contact does not interrupt the annual review.
Illustrative scenario
A business initially uses personal information only for limited administrative purposes but later introduces a new customer activity. It revisits the fee assessment rather than relying indefinitely on the original conclusion. The review is recorded alongside the new processing activity and any necessary registration update.
Preparation checklist
- List the personal information activities actually performed.
- Complete the current ICO fee assessment.
- Keep the reasoning for payment or exemption.
- Assign renewal and change-review responsibility.
Frequently asked questions
Are sole traders always exempt from the fee?
No blanket exemption follows from being a sole trader. Use the ICO's current assessment with the actual processing activities and record the applicable conclusion.
Does paying mean the ICO has approved our business?
No. Payment addresses a fee obligation. The organisation remains responsible for lawful processing, transparency, security and the other requirements relevant to its activities.
Can one group registration cover every company?
Check the legal entities and their roles rather than assuming coverage from a shared brand or system. Separate controllers may need separate assessment of their obligations.
Where should we check the current amount?
Use the official ICO assessment and payment information. Avoid relying on historic articles or an unsolicited invoice, and keep the outcome and renewal responsibility on record.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction