Knowledge centre

Data protection · high risk

Check whether the data protection fee applies

Use the official self-assessment and record the evidence behind the result.

Reviewed 04/08/2026Version 2

What this check is—and is not

Many organisations that process personal information must pay a data protection fee unless an exemption applies. Paying or being exempt does not by itself make all data use compliant.

Do this now

  1. List the personal data the business uses, why it uses it and whether it is only for exempt purposes.
  2. Use the ICO's current self-assessment rather than a third-party summary.
  3. Answer for the real activity, including marketing, CCTV, staff, customer records and online services where relevant.
  4. Save the result, date and the facts used to reach it.
  5. If a fee is due, use the official registration and payment route.
  6. Set a review when the activity changes and before any renewal date.

What good looks like

The business can show a dated decision based on the official tool. The named organisation, contact details and fee tier are correct, and the owner knows that privacy notices, security, lawful handling and individual rights are separate duties.

Common mistakes

  • Assuming every sole trader or every very small business is exempt.
  • Paying a fee without checking which legal entity should be registered.
  • Treating registration as permission to collect any data.
  • Forgetting to reassess after adding staff, CCTV, marketing or new services.

When to get help

Contact the ICO or a data-protection professional if the activity does not fit the tool, involves sensitive data, large-scale monitoring, children or complex sharing.

Keep in your roadmap

Save the official result or receipt, organisation name, review trigger and renewal reminder. Keep the fee decision alongside the business data map.