ICO Data Protection Registration

ICO Registration

The requirement for organisations that process personal data to register with the UK Information Commissioner's Office (ICO) and pay an annual data protection fee.

Under the Data Protection Act 2018 and UK GDPR, most organisations that process personal data must register with the Information Commissioner's Office (ICO) and pay an annual data protection fee. The fee ranges from £40 to £2,900 depending on the organisation's size and turnover.

Registration involves providing details about the organisation, the types of personal data processed, and the purposes of processing. The ICO maintains a public register of data controllers, which can be searched at ico.org.uk. Failure to register when required is a criminal offence.

Exemptions exist for certain organisations including some not-for-profit bodies, individuals processing data for personal purposes, and organisations that only process data for staff administration, accounts, or advertising their own business. However, most commercial businesses need to register.

BORSCH.AI integrates ICO registration data covering 965,000+ matched UK companies, providing visibility into data protection compliance status. Companies handling personal data without ICO registration may face enforcement action and fines.

600,000
ICO Registration Signals
595,535
ICO-Registered Companies

Frequently Asked Questions

How much does ICO registration cost?

Tier 1 (micro-organisations, turnover under £632K): £40/year. Tier 2 (SMEs, turnover under £36M): £60/year. Tier 3 (large organisations, turnover £36M+): £2,900/year. A £5 discount is available for direct debit payment.

Do all companies need to register with the ICO?

Most businesses that process personal data must register. Exemptions include sole traders processing data only for staff admin/accounts/marketing, some charities, and elected representatives. If in doubt, the ICO provides a self-assessment tool.

What happens if I don't register with the ICO?

Failure to register when required is a criminal offence punishable by a fine. The ICO can also issue enforcement notices requiring registration. Separately, data protection breaches can attract fines of up to £17.5 million or 4% of global turnover.

Related Terms

Back to Glossary
Data sourced from 53 official UK government and regulatory bodies including Companies House, FCA, HMRC, and Land Registry. Updated daily.