Skip to content
WebAsk
Clinic compliance

ICO Data Protection Fee: Do I Need to Pay?

ICO data protection fee: who must pay, the exemptions in the law's words, the £52, £78 and £3,763 tiers, the penalties, and what it means for UK clinics.

WebAsk founder Ansar Cheema
Ansar Cheema

Founder · · 18 min read

A salon owner opens a letter from the Information Commission (the ICO) about the data protection fee. It quotes her company's Companies House number. She keeps client details and allergy notes on a booking app. Does she have to pay?

So, do you need to pay the ICO data protection fee? Yes, if you decide how and why personal information is used, unless every use is on a short exempt list. The law calls you a data controller, and a data controller "must pay a charge". Client notes on an app are not on the list, as we read it. With 10 or fewer staff, she would pay £52 a year, or £5 less by direct debit.

Checked against the regulations and the ICO's guidance on 5 October 2026. WebAsk is a web agency, not a law firm. This is not legal advice.

TL;DR

A controller pays unless every use of personal data is exempt: £52, £78 or £3,763 a year, £5 less by direct debit. Patient and client notes are not on the exempt list, as we read it. Paying puts you on the ICO's register of fee payers, and your other data protection duties still apply.

Who must pay: controllers, not processors

The ICO's glossary is plain: "Only controllers need to pay the data protection fee." Its fee checker adds: "If a business is using personal information for work purposes, it's acting as a data controller." A processor only follows another business's instructions, and pays nothing for that work.

Regulation 2 of the Data Protection (Charges and Information) Regulations 2018 says:

"A data controller must comply with the requirements of this regulation unless all of the processing of personal data they undertake is exempt processing."

A data controller must pay "Within the first 21 days of each charge period". For a new business, the first period starts "on the date on which the person becomes a data controller".

Since 30 September 2026 the charge is paid to the Information Commission. It replaced the Information Commissioner (SI 2026/386, Schedule 3, paragraph 23; SI 2026/1015). legislation.gov.uk has yet to apply that change to its text. The amounts have stood since 17 February 2025 (SI 2025/63).

Data protection fee exemptions, in the law's words

The Schedule lists the exempt purposes. Beside each is the ICO's own label.

The regulations' words (Schedule, paragraph 2(2))The ICO's label
(a) personal data "not being processed wholly or partly by automated means or recorded with the intention that it should be processed wholly or partly by automated means""Processing personal information without an automated system such as a computer."
(b) "for the purposes of their personal, family or household affairs""Personal, family or household affairs."
(c) "for the purpose of the maintenance of a public register""Maintaining a public register."
(d) "matters of administration in relation to the members of staff and volunteers of, or persons working under any contract for services provided to, the data controller""Staff administration."
(e) "advertising, marketing and public relations in respect of the data controller's business, activity, goods or services""Advertising, marketing and public relations."
(f) "keeping accounts, or records of purchases, sales or other transactions", deciding whether to accept a customer or supplier, and financial forecasts, "in relation to any activity carried on by the data controller""Accounts and records."
(g) a body "not established or conducted for profit", for its membership, support, and activities "for individuals who are either a member of the body or association or who have regular contact with it""Not-for-profit purposes."
(h) a judge, or someone acting for one, "for the purposes of exercising judicial functions""Judicial functions."
(i) to (k) members of the House of Lords, elected representatives and prospective representatives"Since 1 April 2019, members of the House of Lords, elected representatives and prospective representatives are also exempt."

The list is all or nothing: you are exempt only if "all of the processing" you do is exempt. The ICO's checker says: "Answer 'no' if you use or store personal information for any reason other than those listed above."

"Accounts and records" covers "keeping accounts, or records of purchases, sales or other transactions". As we read it, that does not stretch to treatment notes or health questions. No page we read says whether a record of bookings and payments alone fits.

CCTV is not named in the regulations. The ICO's Registration FAQs say:

"Any company using CCTV for crime prevention purposes is required to pay an annual data protection fee to the ICO, regardless of other aspects of your business and operations."

Its checker counts "dashcams, video doorbells, drones and body-worn video cameras for work purposes".

Pay or exempt: nine situations

Each row cites pages read on 5 October 2026. "Our reading" marks our own view where no source decides. "Unsettled" marks a point on which we take no view.

Your situationPay or exempt?TierSource
Sole trader with client records on a booking appPay, unless every use is on the exempt list. Consultation forms, allergy notes and treatment history are not on it (our reading). A record of bookings and payments alone: unsettledTier 1 with 10 or fewer staff: £52Schedule, paragraph 2(2)(f); regulation 2(1); ICO fee checker, questions 6 and 12
Clinic keeping patient notes on a computerPay on a yes to the checker's health question (see Aesthetic clinics and beauty salons, below). On a no, treatment notes are still not an exempt purpose (our reading)By staff and turnoverICO fee checker, question 9 and its result; regulation 2(1); Schedule, paragraph 2(2)
Dental practiceThe principal "would be required to pay" if they have "responsibility and control of the patient records". Partners each responsible for their own patients' information: "each partner would need to pay a separate fee"By staff and turnoverICO Registration FAQs, dental answers
Only staff payroll and the business's own accountsExempt, if that is all: staff administration and accounts are on the list. Any CCTV changes the answerNoneSchedule, paragraph 2(2)(d) and (f); ICO fee checker result
Paper records onlyExempt, unless "recorded with the intention" that they are processed by automated means, such as forms you mean to type into a system (our example). The ICO counts emails, messaging apps and cloud systems as electronic. CCTV changes the answerNoneSchedule, paragraph 2(2)(a); ICO fee checker, question 6 and its result
Any business using CCTVPay. The ICO's Registration FAQs: any company using CCTV for crime prevention "is required to pay". The checker counts dashcams and video doorbells used for workBy staff and turnoverICO Registration FAQs; ICO fee checker, CCTV question
Charity or other not-for-profitExempt only if all its processing is exempt; the ICO says the not-for-profit exemption "may apply". CCTV for crime prevention "falls outside of the exemption"A charity that must pay: tier 1, £52. Other not-for-profits: by staff and turnoverSchedule, paragraph 2(2)(g); regulation 3(2)(a)(iii); ICO Registration FAQs
A business that only handles data for othersNo fee for that work: "Only controllers need to pay the data protection fee." Its own staff, customer and marketing data are its own uses, checked separately (our reading)None for the processing it does for othersICO glossary; ICO fee checker, question 7 and its result
A group of companies, or one company with several sites"Separate fees must be paid for each company individually if it is a data controller." One company with several sites: "one fee would cover all of the sites", if no site trades as a separate organisation and the company "determines why and how personal data is used"Each company by its own staff and turnover (our reading; no ICO page we read covers group turnover)ICO Registration FAQs; regulation 3(2)

Do clinics need to register with the ICO?

Dental practices: the ICO's own answers

The ICO's Registration FAQs answer dental practices directly:

"If the principal of a practice has responsibility and control of the patient records in the practice, they would be required to pay a data protection fee."

Where each partner is responsible for their own patients' information, and would take it with them on leaving, "each partner would need to pay a separate fee". Partners who control the records together for the practice "may" pay in the firm's name (regulation 4).

For associates and hygienists, "It is not possible to give a definitive answer". The ICO asks four questions, such as whether your patient list would follow you if you left. Any yes means "you are likely to be a data controller and will need to pay the ICO a data protection fee".

The ICO's register of fee payers is not the GDC's register or CQC registration. For the GDC's website rules, see our GDC guide.

Aesthetic clinics and beauty salons

The fee checker asks: "Do you use information for health, education or childcare services?" Its examples include "dentists" and "private healthcare". On 5 October 2026, a yes led to "you're required to pay the data protection fee", with no exemptions question.

Whether an aesthetic or beauty service counts as "private healthcare" is your answer to give. No source we read decides it. Answer no, and the exemptions question follows.

Article 9(1) of the UK GDPR names "data concerning health" as a special category. Using it needs a lawful basis and an Article 9 condition, set out in our post on appointment reminders and health data.

Sole traders and booking apps

The ICO's fee hub says "organisations (including sole traders)" that use personal information "need to pay a data protection fee, unless they are exempt". The checker counts "smart phones" and "cloud systems" as electronic use, so a booking app counts (our reading). "You should include yourself in the number of staff you have."

How much is the ICO fee for a small business?

TierWho (regulation 3(2))Fee (regulation 3(1))Fixed penalty (ICO, section 158 document)
1: micro organisationsTurnover of £632,000 or less, or 10 or fewer staff, or a charity, or a small occupational pension scheme£52£400
2: small and medium organisationsNot in tier 1, and turnover of £36 million or less, or 250 or fewer staff£78£600
3: large organisationsNot in tier 1 or tier 2£3,763£4,000

The fee is "reduced by £5.00" if you pay by direct debit (regulation 3). Turnover and staff are measured "on the first day of the charge period". Public authorities count staff only.

The ICO's guide says staff includes "all your employees, workers, office holders and partners", averaged over your financial year. "Each part-time staff member is counted as one member of staff." It adds: "We regard all controllers as eligible to pay a fee in tier 3 unless and until they tell us otherwise." No VAT is charged on the fee.

How to check, register and renew

The ICO's fee self-assessment "Takes about 10 minutes". If you need to pay, register online. It "Takes about 15 minutes", and you can pay by direct debit, card, BACS or cheque. "We do not provide invoices as registration is required by law."

The register of fee payers shows each payer's name and address, registration reference, tier and dates. "You can search our register to see if an organisation is registered with us."

"Your fee covers a 12 month period from the renewal date (not the payment date), but we will not regard you as covered until we receive a payment we can attribute to you." The ICO "will contact you before your previous payment expires". A direct debit is taken "each year until the direct debit is cancelled".

If you are exempt, "You do not need to tell us you're exempt." If the ICO has written quoting your Companies House number, though, the checker results we read asked for its exemptions form. Agencies that offer to pay the fee for you "have no official standing or powers under data protection law", the ICO says. It recommends you "pay the ICO directly".

What happens if you do not pay?

After a reminder, the ICO's FAQs say:

"If you don't pay, or tell us why you are no longer required to pay a fee, we can issue a notice of intent to issue a monetary penalty notice 28 days after expiry. You will have 28 days to pay or make representations."

Pay the fee then, and the ICO's payment page says "you will not be sent a penalty". A penalty notice must give at least 28 days to pay (Schedule 16).

Not paying is a failure under section 149(5) of the Data Protection Act 2018, and section 155 allows a penalty notice. The fixed penalties are £400, £600 and £4,000 by tier, in the ICO's fixed-penalty document. The ICO reserves the right to raise this "up to a statutory maximum of £4,350" where a controller fails to give "sufficient information to determine the appropriate fee/exemption", "depending on aggravating factors". Its penalties page says "The maximum penalty is a £4,350 fine." Its Registration FAQs say the ICO "can issue a monetary penalty of up to £4,000 on top of the fee you are required to pay".

Our arithmetic: £4,350 is 150% of £2,900, the tier 3 fee until 17 February 2025. Section 158(3) lets the ICO specify up to "150% of the highest charge". The fixed-penalty document, required by section 158(1), says: "Fixed penalties will be imposed in accordance with the law and with this document." Section 158(4) lets the ICO "alter or replace the document".

What paying the fee does not do

Paying the fee does not show that you handle data well. As we read it, the register records nothing about how you use data. The ICO tells new fee payers: "Everyone in your business is responsible for complying with information rights laws."

Other duties still apply:

  • Privacy information when you collect personal data, covered in our website legal requirements post.
  • A lawful basis, plus an Article 9 condition for health details (see the clinic section above).
  • Records of processing (Article 30). Firms with fewer than 250 staff can be spared this duty. That relief does not apply where processing "includes special categories of data", such as health data.
  • Security: "appropriate technical and organisational measures" (Article 32).

A checklist for the ICO fee

  1. List every use of personal information, including CCTV, dashcams and video doorbells.
  2. For each, decide: do you choose how and why it is used, or follow another business's instructions?
  3. Check each use against the exempt list. One use outside it means you pay.
  4. Take the ICO's self-assessment, answering the health question for what your business actually does.
  5. Work out your tier on the first day of your charge period.
  6. Pay within 21 days of becoming a controller. A direct debit renews each year.
  7. Search the register for your entry and its expiry date.

Where to start

  1. Take the ICO's fee self-assessment, answering for what your business actually does.
  2. Check the rest of your clinic website. Our clinic website checklist covers forms, cookies and reviews.
  3. Get in touch if you are planning a new website or booking system.

Want a rules check on your clinic website?

For an aesthetic clinic, dental practice or beauty and wellness business, the free website audit includes a rules check. It flags what it sees on a fixed list of points and reports what the site shows or leaves out, but it gives no legal verdict and is not legal advice.

Get a free site audit