Home Blog Do You Have to Register With the ICO, and What's It Cost?

GDPR

Do You Have to Register With the ICO, and What's It Cost?

Posted by Kevin Yun|September 1, 2026

If you are a controller processing personal data in the UK and no exemption applies, yes, and the fee is £52, £78 or £3,763 a year depending on your size. Most SaaS companies land in tier 1 or tier 2. The exemptions are real but narrow, because they only apply where your processing is exclusively for one of a short list of purposes, which a product business never satisfies.

This article covers the three tiers and how they are calculated, the exemptions and why "only" is the operative word, who is liable, what happens if you do not pay, and the questions the ICO's own guidance does not settle.

The Three Tiers And What Sets Them

Figures below are from the ICO's own guide to the data protection fee, checked 8 August 2026. Fee schedules change, so verify before you pay.

Tier 1, micro organisations, £52. You have a maximum turnover of £632,000 for your financial year or no more than 10 members of staff.

Tier 2, small and medium organisations, £78. You have a maximum turnover of £36 million or no more than 250 members of staff.

Tier 3, large organisations, £3,763. Everything that does not meet tier 1 or tier 2.

The conjunction matters more than anything else on this page. It is or, not and. Plenty of secondary guidance renders it as "and," which produces the wrong answer for exactly the profile a funded SaaS often has: eight employees and turnover above the threshold, or substantial headcount on modest revenue. Either limb alone puts you in the tier.

Staff numbers are defined broadly to include employees, workers, office holders and partners, counted as a monthly average across your financial year, with each part-time person counted as one. The ICO is explicit that it does not matter whether staff are based in the UK or overseas. A UK company with a distributed engineering team counts all of them.

Paying by direct debit takes £5 off at the point of payment. There are also fixed positions for some organisations: charities pay tier 1 regardless of size, as do small occupational pension schemes, and public authorities categorise on staff numbers alone.

One quiet default is worth knowing. The ICO states that it regards all controllers as eligible for tier 3 unless and until they tell it otherwise.

The Exemptions, And Why "Only" Does All The Work

You do not need to pay if you process personal data only for one or more of a listed set of purposes: staff administration; advertising, marketing and public relations; accounts and records; not-for-profit purposes; personal, family or household affairs; maintaining a public register; judicial functions; or processing without an automated system. Members of the House of Lords, elected representatives and prospective representatives have been exempt since 1 April 2019.

Read the list and then read the word before it. The exemption applies where those are the only purposes. A SaaS company processes customer data to deliver a product, which appears nowhere on that list, so the exemption fails at the first hurdle no matter how well the other purposes fit.

The exemption is genuinely useful to a narrow set of organisations: a holding company with no trading activity, a small consultancy keeping only its own accounts and staff records, a business that has genuinely never automated anything. It is not a startup exemption and there is no revenue floor.

One rule overrides all of this and is worth knowing because it catches organisations that would otherwise be exempt. The ICO states that any company using CCTV for crime prevention purposes must pay the fee regardless of any other aspect of its business, and that such organisations need not take the self-assessment at all because the answer will always be yes. An office with a camera on the door is enough. The same applies to a dashcam used for work purposes, which the ICO treats as non-domestic and therefore in scope.

Two further points that catch people. Being exempt from the fee does not exempt you from anything else in UK GDPR; your other obligations are untouched. And the register is public, which means anyone assessing you as a vendor can check whether you are on it in about fifteen seconds.

Who Is Actually Liable

The obligation falls on controllers. The ICO's guidance frames the requirement as applying where you are processing personal data as a controller.

For a B2B SaaS this produces a distinction worth being precise about. For your customers' end-user data you are typically a processor, and that role does not itself trigger the fee. For your own employee records, your marketing contacts, your billing data and your website analytics, you are a controller.

That might look like a route to an exemption, since staff administration, marketing and accounts are all on the exempt list. It usually is not, because a product business is a controller for more than that: prospect data you enriched rather than collected, support records, security logging, and anything you use to improve the product rather than to run the account. Establishing which hat you wear for which dataset is the same exercise as maintaining your record of processing activities, and doing one gives you the other.

What Happens If You Do Not Pay

The ICO publishes its position plainly. Failure to pay or renew can attract a monetary penalty of up to £4,000 on top of the fee owed, and its registration FAQ states that fines range from £400 to £4,000. It writes to organisations it believes should be registered, with a response deadline, whether or not a fee turns out to be due.

This is enforced rather than theoretical. The ICO reports issuing 126 monetary penalties for non-payment between May 2021 and January 2022, and it publishes the names of most organisations it fines. Note the economics too: the top of the penalty range is roughly seventy-seven times the tier 1 fee, for an obligation that costs less than a team lunch to discharge. This is not an area where non-compliance is a considered risk position.

Renewal is annual and it is your responsibility, though the ICO does send reminders. Reassess your tier at renewal, because the thresholds are the kind of thing a company crosses without noticing.

Payment is also not the same as compliance, and it is worth saying because the confusion is common. Registration funds the regulator and puts you on a public list. It does not certify anything, and it is a much weaker signal than a completed security audit or the evidence a buyer will actually ask for, in the same way that regulators' published wording matters more than vendor summaries when working out whether testing obligations apply to you.

Common Mistakes With ICO Registration

Reading the tier criteria as "and" rather than "or." Either turnover or staff count puts you in a tier on its own. This single misreading is the most common source of wrong payments.

Counting only UK staff. The ICO states that staff based overseas count too. A UK entity with a distributed team may be in a higher tier than headcount in the London office suggests.

Assuming the exemption list covers a SaaS. It applies only where the listed purposes are your sole purposes. Delivering a product to customers is not on the list, so the exemption fails immediately.

Confusing the fee with compliance. Registration is an administrative payment. It does not certify your practices and it does not answer a customer's security review.

Forgetting to reassess at renewal. Tiers are based on the last financial year. Crossing a threshold changes the fee, and the register does not update itself.

FAQ

Do I need to register with the ICO if I am a processor, not a controller?

The fee obligation is framed around processing as a controller. Most SaaS companies are controllers for something, though, including their own staff and marketing data, so the question is usually not whether you hold controller data but whether any exemption covers all of it.

Does a non-UK company have to pay the ICO fee?

This is the question the published guidance answers least clearly, and it depends on your connection to the UK rather than on where you are incorporated. Use the ICO's own registration self-assessment, and if the result is ambiguous for your structure, get it confirmed rather than inferred.

How much is the ICO fee for a startup?

£52 for tier 1, which covers organisations with turnover up to £632,000 or no more than 10 staff, less £5 if you pay by direct debit. Most early-stage companies sit here, moving to £78 as they grow.

Is the ICO register public?

Yes. Anyone can search it and download registration certificates, which means prospective customers and partners can check your entry without asking you. It is a small thing that occasionally comes up during vendor review.

Closing Thought

For a £52 annual payment this topic generates a remarkable amount of confusion, and most of it traces to one conjunction and one adverb. Turnover or staff, not both. Processing only for the listed purposes, not mostly.

There is a smaller point underneath that is worth sitting with. The register is public, the fee is trivial, and checking it takes seconds, which makes an absent registration a cheap and unusually reliable signal to anyone assessing you. It is one of the few compliance facts about your company that a stranger can verify without your cooperation. ComplyDog hosts a compliance portal on your own domain covering your DPA, subprocessor list, data subject request handling and security page, which is where the things buyers actually ask for belong. It does not pay your ICO fee, which takes about five minutes on the ICO's own site.