ComplyChat Start free

Guide · Data protection

The data protection fee

Every organisation or sole trader that controls personal data must pay the regulator an annual data protection fee of £52, £78 or £3,763 under the Data Protection (Charges and Information) Regulations 2018 unless all of its processing is exempt, and every charity that is not exempt pays only the £52 tier 1 fee.

By ComplyChatPublished 14 minute read

In a small rural primary school, the school business manager works at a laptop in an office converted from an old cloakroom, its iron coat pegs on the tiled wall above her still holding a couple of coats, as the headteacher stands in the doorway with a mug

Paying the fee is what people mean by registering with the ICO: there is no separate registration and no separate cost. Since 30 September 2026 the fee has been paid to the Information Commission, which replaced the Information Commissioner and is still known as the ICO. This guide sets out the rule, how to work out your tier, why the exemptions are narrower than they look, and how the fee applies to schools, nurseries, childminders, charities and care providers.

01

The rule: the 2018 Regulations and who the fee is paid to

The data protection fee is a statutory charge set by the government in regulations, not by the regulator. Section 137 of the Data Protection Act 2018 says: “The Secretary of State may by regulations require controllers to pay charges of an amount specified in the regulations to the Commission.” The ICO's own data protection fee FAQs put it as “The fee is set by Parliament”.

The regulations are the Data Protection (Charges and Information) Regulations 2018, which apply across the UK. Regulation 2 is the duty:

  • “(1) A data controller must comply with the requirements of this regulation unless all of the processing of personal data they undertake is exempt processing.”
  • “(2) Within the first 21 days of each charge period a data controller must pay a charge to the Information Commission, determined in accordance with regulation 3.”
  • (3) Within the same 21 days the controller must give the regulator its name and address, its staff band (10 or fewer, up to 250, or more), its turnover band (up to £632,000, up to £36 million, or more) and whether it is a public authority.

The fee is annual: the ICO says “Your fee covers a 12 month period from the renewal date (not the payment date)”. The responsibility falls on the data controller, the organisation that decides why and how personal data is used, or a sole trader such as a childminder.

The regulator changed on 30 September 2026. Section 118 of the Data (Use and Access) Act 2025 says “The office of Information Commissioner is abolished”, and the commencement regulations (SI 2026/1015) brought that and the transfer of functions to the Information Commission into force that day. Regulation 3 of those regulations carries everything done by or in relation to the Commissioner over to the Commission, so an existing registration continues and nobody needs to register again because of the change. It is still known as the ICO, and on 8 October 2026 its fee pages still used the old name.

02

Working out your tier: the amounts, staff and turnover

Regulation 3 sets three tiers. Since 17 February 2025, under the Data Protection (Charges and Information) (Amendment) Regulations 2025, the fee is £52 in tier 1, £78 in tier 2 and £3,763 in tier 3, replacing £40, £60 and £2,900. Regulation 3(5) takes £5 off for payment by direct debit, so £47, £73 or £3,758.

  • Tier 1 (micro organisations), £52: turnover of £632,000 or less, or 10 or fewer members of staff, or a charity, or a small occupational pension scheme.
  • Tier 2 (small and medium organisations), £78: not in tier 1, and turnover of £36 million or less, or 250 or fewer members of staff.
  • Tier 3 (large organisations), £3,763: everyone else.

Either test is enough: an organisation with 40 staff and annual turnover under £632,000 is in tier 1. Four rules decide the edge cases.

  1. Staff is broader than employees. Regulation 1(2) defines a member of staff as any employee, worker, office holder or partner. The ICO's Guide to the data protection fee says the number is “the average number working for you during your financial year”, worked out from the monthly totals, and “Each part-time staff member is counted as one member of staff.”
  2. Public authorities ignore turnover. Regulation 3(3) disregards the turnover tests for a public authority; the ICO says public authorities “should categorise themselves according to staff numbers only”.
  3. The tier is fixed on day one. Regulation 3(4) says turnover and staff numbers are “determined on the first day of the charge period”. A nursery or care provider that passes 10 staff mid-year moves tier at its next renewal, not the day it hires.
  4. Charities are capped at tier 1. The ICO says “Charities that are not otherwise subject to an exemption will only be liable to pay the tier 1 fee, regardless of size or turnover.” Regulation 3(6) defines a charity for each UK jurisdiction, so Scottish and Northern Ireland charities are included.

Tell the regulator which tier you are in. The ICO says “We regard all controllers as eligible to pay a fee in tier 3 unless and until they tell us otherwise”, so a small charity that registers without saying so can be asked for £3,763. The ICO's fee self-assessment works through the questions.

03

The data protection fee exemptions, read narrowly

The exemptions are in the Schedule to the 2018 Regulations, and the test in regulation 2(1) is demanding: a controller pays nothing only if all of its processing is exempt. One non-exempt purpose and the fee is due. The ICO's exemptions page lists them; with the Schedule's own qualifications, they are processing only for:

  • staff administration (the Schedule includes volunteers and contractors);
  • advertising, marketing and public relations for your own business or activity;
  • accounts and records of your own transactions;
  • not-for-profit purposes, which the Schedule limits to “establishing or maintaining membership or support for the body or association, or providing or administering activities for individuals who are either a member of the body or association or who have regular contact with it”;
  • personal, family or household affairs;
  • maintaining a public register;
  • judicial functions;
  • members of the House of Lords, elected representatives and prospective representatives;
  • personal information processed without an automated system such as a computer.

Read against what schools, nurseries, charities and care providers actually do, the list is short. Case records about the people you support, children's learning journals, care plans, safeguarding logs and referral notes held on a computer or an app are none of these things. A charity that only keeps its members' details and runs activities for them may be exempt; one that holds records about the people it supports is usually not.

CCTV ends many exemptions. The ICO's health and social care fee page (marked as under review) answers: “I have CCTV on my business premises for crime prevention reasons – do I need to pay a fee? Yes. Images of people caught on camera is their personal data. If you record these images to prevent crime, and crime prevention is not the purpose of your business, then you need to pay.”

An exemption from the fee is not an exemption from the law. The ICO says: “even if you are exempt from paying a fee, you still need to comply with your other data protection obligations.” UK GDPR, the duty to answer subject access requests and the duty to manage breaches apply to an exempt charity as fully as to a fee payer.

04

Who pays: schools, nurseries, childminders, charities and care providers

Schools. The Department for Education's Data protection in schools: responsibilities says “For most of the personal data you collect, store and use, the school or the multi-academy trust is the data controller” and “As a data controller, your school needs to register with the Information Commissioner's Office”, adding that “The responsibility and accountability for compliance sits with governors and trustees.” Regulation 5 lets a school pay once where its governing body and head teacher are both controllers: the requirements “may be satisfied in respect of that governing body and head teacher in the name of the school”, with the school's name, address and staff count. In a multi-academy trust the trust is usually the controller, so the trust pays.

Which tier a school is in depends on what it is. On the face of regulation 3, a charity is in tier 1 even if it is also a public authority, because regulation 3(3) disregards only the turnover tests. An academy trust is an exempt charity under Schedule 3 to the Charities Act 2011, as is the governing body of a foundation, voluntary or foundation special school, so on the face of the Regulations they are in tier 1, while a community school's governing body, which Schedule 3 does not list, would tier by staff numbers alone. That is a reading of the Regulations, not ICO guidance: the ICO has not published how it applies this to schools, and its guide tells public authorities to “categorise themselves according to staff numbers only”, so do not assume tier 1 – confirm your tier with the ICO's self-assessment or with the ICO directly; our data protection officer for schools guide covers the wider duties.

Nurseries and pre-schools. A private nursery tiers by staff and turnover like any business; a company that runs several nurseries counts its staff across all of them, because the company is the controller. A pre-school run by a registered charity pays the tier 1 fee. Our guide to GDPR for nurseries and childminders covers the wider duties.

Childminders. The ICO's data protection fee page says organisations “(including sole traders) that use personal information need to pay a data protection fee, unless they are exempt”. The ICO's health and social care fee page says “A childminder does have to pay the data protection fee” if they take digital photographs of a child, hold records of the child's progress, learning and development, or use contact details to send updates on the child's progress. A childminder with 10 or fewer staff is in tier 1. Regulation 2(5) makes the address given that of the “principal place of business in the UK”, and the register of fee payers is public, so for a childminder working from their own house that is the address that appears.

Charities. Tier 1, £52, whatever their size, unless every purpose is exempt. Our GDPR policy for a small charity guide covers the policy and the data protection officer test.

Care providers. Care homes and domiciliary care agencies hold care and medication records about the people they support, almost always on a computer or care-planning system, so they pay: the ICO's health and social care fee page says a nursing or residential home that provides a nursing service “such as bespoke care plans” and holds residents' medical records electronically is “required to pay the fee”, and gives the same answer for domiciliary care. A provider that is a company tiers by staff and turnover; one that is a registered charity pays £52. Our guide to care home data protection covers the Data Security and Protection Toolkit and breaches.

In the small studio of a community radio charity, the station manager and the volunteer treasurer talk in the doorway while a volunteer presenter works the mixing desk behind them
05

How to pay the data protection fee, the register and the penalties

Pay the fee directly to the regulator, through the ICO's website. Its page on paying the data protection fee lists direct debit (“If you pay by direct debit, you will receive a £5 discount”), credit or debit card, and cheque. A first-time payer gives its name, contact details and the tier it believes it is in; an existing payer is sent a renewal reminder. Registering and paying are the same step under regulation 2, so there is nothing else to buy.

The ICO publishes every fee payer on its register of fee payers. Its page on information it will collect and publish says the register shows the controller's name and address, the registration reference, “The level of fee you have paid (that is tier 1, tier 2 or tier 3)”, the payment and expiry dates, trading names, and the data protection officer's contact details if you have told it you have one. Anyone can search it, including parents, funders and families.

Three details from the ICO's FAQs: “Statutory fees are outside the scope of VAT, so no VAT is charged on it”; the fee is payable “Every 12 months”; and refunds are given “Only in exceptional circumstances”.

If you do not pay, the ICO's FAQs say it will send a reminder and “can issue a notice of intent to issue a monetary penalty notice 28 days after expiry”, after which “You will have 28 days to pay or make representations.” Section 158 of the Data Protection Act 2018 requires the regulator to publish the penalty amounts, and its document Fixed penalties for failure to pay the data protection charge sets them at £400 for tier 1, £600 for tier 2 and £4,000 for tier 3, with the right to increase a penalty up to £4,350, its published maximum, where a controller fails to give enough information to set the fee. The ICO's penalties page says “The maximum penalty is a £4,350 fine.” Section 158(3) allows a published amount of up to “150% of the highest charge payable by a controller in respect of a financial year”. These penalties are for not paying the fee; fines for breaching data protection law itself are a separate regime.

06

What the fee does not tell you about your data

The fee puts an organisation on a public register as a controller of personal data, and that is all it does. It says nothing about where that personal data is.

For schools, nurseries, charities and care providers, some of the most sensitive personal data they handle is in messages. A teaching assistant messages the class teacher about a child who arrived upset. A care worker sends the coordinator a photo of a bruise on a resident's arm. A youth worker texts the safeguarding lead after a session. Those messages often sit in personal messaging apps on staff phones. If the person they are about makes a subject access request, or a phone is lost, the organisation will be asked what it holds, and often cannot say.

ComplyChat is designed for exactly those work conversations: channels the organisation holds, everyone added told the channel is on the record, and on the paid plans a lasting record filed into the organisation's own Microsoft 365. It has nothing to do with the fee. It does not pay or register on your behalf, it does not change your tier, and using it does not make any processing exempt: an organisation that uses ComplyChat still pays the regulator like everyone else.

A question for the next leadership or board meeting: when we renewed the data protection fee, did anyone ask where our conversations about the people we look after are held?

07

Questions people ask

Do I need to pay a data protection fee?

Yes, if you are a controller of personal data and not all of your processing is exempt: regulation 2(1) of the Data Protection (Charges and Information) Regulations 2018 requires every data controller to pay “unless all of the processing of personal data they undertake is exempt processing”. The ICO says organisations “(including sole traders)” that use personal information need to pay unless they are exempt.

How much is the ICO fee?

The data protection fee is £52 for tier 1, £78 for tier 2 and £3,763 for tier 3, set by regulation 3 of the 2018 Regulations since 17 February 2025, with £5 off for paying by direct debit. Most small organisations, and every charity, are in tier 1.

Does a charity need to pay the ICO fee?

Usually yes, but only the tier 1 fee of £52: regulation 3(2)(a)(iii) puts every charity in tier 1 whatever its size, and the ICO says charities not otherwise exempt “will only be liable to pay the tier 1 fee, regardless of size or turnover”. A charity pays nothing only if all its processing is exempt, for example limited to its not-for-profit membership, support and activities, with no CCTV.

What happens if I don't pay the ICO fee?

The regulator will send a reminder and can then serve a penalty notice: its published fixed penalties are £400 for tier 1, £600 for tier 2 and £4,000 for tier 3, and it says it may increase a penalty up to £4,350 where a controller fails to give enough information to set the fee. The Data Protection Act 2018 allows the published amount to be up to 150% of the highest tier fee (section 158(3)).

Am I exempt from paying the data protection fee?

Only if all your processing falls within the exempt purposes in the Schedule to the 2018 Regulations: staff administration, your own advertising and marketing, your own accounts and records, not-for-profit membership and activities, personal or household affairs, a public register, judicial functions, elected representatives, or records not held on a computer. CCTV for crime prevention is not on the list, and the ICO says it means you need to pay.

Is the ICO data protection fee legitimate?

Yes. The data protection fee is a statutory charge under section 137 of the Data Protection Act 2018 and the 2018 Regulations, paid directly to the regulator through the ICO's website; it is outside the scope of VAT. Since 30 September 2026 the regulator is the Information Commission, still known as the ICO.

08

Official guidance and your next step

The law is the Data Protection (Charges and Information) Regulations 2018 (regulations 2, 3 and 5 and the Schedule), made under section 137 of the Data Protection Act 2018, with penalties under section 158. The regulator's guidance is its Guide to the data protection fee, its fee self-assessment and its fixed penalties document. Schools in England should also read the Department for Education's Data protection in schools. Quotations are from those pages as published on 8 October 2026; the ICO's pages had not then been updated for the Information Commission, so check them again before relying on a name or a figure.

This guide summarises the fee rules, which apply across the UK; the schools guidance quoted is for England. It is not legal advice.

Then do one thing: look your organisation up on the register of fee payers today, and check that the name, tier and expiry date are right. If you are not there, work through the self-assessment this week.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. The fee registers an organisation as a controller of personal data; some of the most sensitive of that data is in messages staff send about the people they look after. Explore Free personal messaging, or compare the paid plans if your organisation needs a lasting Microsoft 365 record.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Data Protection Act 2018 legislation.gov.uk
  2. Data protection fee FAQs ico.org.uk
  3. Data Protection (Charges and Information) Regulations 2018 legislation.gov.uk
  4. Data (Use and Access) Act 2025 legislation.gov.uk
  5. Commencement regulations (SI 2026/1015) legislation.gov.uk
  6. Regulation 3 legislation.gov.uk
  7. Data Protection (Charges and Information) (Amendment) Regulations 2025 legislation.gov.uk
  8. Guide to the data protection fee ico.org.uk
  9. Fee self-assessment ico.org.uk
  10. Schedule to the 2018 Regulations legislation.gov.uk
  11. Exemptions page ico.org.uk
  12. Health and social care fee page ico.org.uk
  13. Data protection in schools: responsibilities gov.uk
  14. Regulation 5 legislation.gov.uk
  15. Schedule 3 to the Charities Act 2011 legislation.gov.uk
  16. Data protection fee page ico.org.uk
  17. Paying the data protection fee ico.org.uk
  18. Register of fee payers ico.org.uk
  19. Information it will collect and publish ico.org.uk
  20. Fixed penalties for failure to pay the data protection charge ico.org.uk
  21. Penalties page ico.org.uk
  22. Section 158(3) legislation.gov.uk