Since the entering into force of the Data Protection Act 2018, a data controller does not have to notify/register with the DPA prior to the first processing of personal data – it is enough to pay the data protection fee. Controllers who have a current registration (or notification) under the 1998 Act do not have to pay the new fee until that registration has expired.
Registration fees depend on size and turnover and there are three tiers of fees ranging from £40 to £2,900, but for most organisations the registration fee amounts to £40 or £60. Charities and small occupational pension schemes pay only £40 regardless of their size and turnover.
- Tier 1 – micro organisations – a maximum turnover of £632,000 for a financial year or no more than 10 members of staff: the fee is £40.
- Tier 2 – small and medium organisations – a maximum turnover of £36 million for a financial year or no more than 250 members of staff: the fee is £60.
- Tier 3 – large organisations – If you do not meet the criteria for tier 1 or tier 2, the fee is £2,900.