Published 7 September 2026 · updated 9 September 2026 · 4 min read
Organisations that process personal data generally have to pay a data protection fee to the Information Commissioner's Office, unless they are exempt. It is a legal requirement, separate from anything Companies House or HMRC ask of you.
Who has to pay
If your company processes personal data — customer records, employee records, a mailing list, CCTV — it is likely in scope. The fee is tiered by size and turnover, and the ICO publishes the current amounts and a self-assessment tool on its own website. Check there rather than trusting a figure quoted elsewhere, including here.
Who is exempt
Exemptions exist, and they are narrower than people assume. Processing only for core business purposes such as staff administration, accounts and records, or advertising your own business, can qualify — but adding almost any other activity, such as CCTV or marketing to purchased lists, takes you out of it.
What happens if you do not
The ICO can issue a monetary penalty for non-payment, and it does. It writes to companies at their registered office, which is another reason that address needs to be one somebody actually reads.
Paying it is not compliance
The fee is an administrative requirement. It does not mean you are handling personal data lawfully. You still need a lawful basis for processing, a privacy notice, sensible retention periods and a way to answer a subject access request.
Practical steps for a new company
- Run the ICO's self-assessment when you start processing data, not a year later.
- Pay the fee if you are in scope, and diarise the renewal.
- Write a privacy notice that describes what you actually do.
- Decide how long you keep things, and why.
Nothing here is advice about your situation
It is general information about how UK company registration works, written to be accurate at the time of publication. Rules and fees change. Where a decision matters — tax, structure, an insolvent company — take advice on your own facts.