Do you need to register with the ICO?
Most businesses that keep customer details on a computer must pay the annual data protection fee — £52 a year for a small business. How to check whether it applies to you, and what UK GDPR actually asks of a one-person business.
If you keep a customer list, take bookings by email, or run a mailing list, you are processing personal data. Under the Data Protection (Charges and Information) Regulations 2018 most organisations that do this — including sole traders — must pay an annual data protection fee to the Information Commissioner's Office. It is not the same thing as 'being GDPR compliant', and it is not optional because you are small.
What it costs
| Tier | Who it applies to | Fee |
|---|---|---|
| Tier 1 | 10 or fewer staff, or turnover up to £632,000 | £52 |
| Tier 2 | 250 or fewer staff, or turnover up to £36 million | £78 |
| Tier 3 | Everyone larger | £3,763 |
Nearly every business in this directory is tier 1. Charities pay the tier 1 fee whatever their size. There is a discount for paying by direct debit.
What happens if you do not pay
The ICO issues monetary penalties for non-payment and publishes the names of the organisations it fines. It is a cheap problem to fix and an expensive and public one to ignore.
The rest of UK GDPR, in plain terms
Paying the fee is registration. It is separate from the duties that apply to how you handle the data:
- Have a reason. You need a lawful basis for holding someone's details — usually performing a contract for a customer, or legitimate interests. Write down which one, once.
- Tell people. A privacy notice on your site saying what you collect, why, how long you keep it and who you share it with. It can be one page.
- Collect less. You do not need a date of birth to sell someone a mug. Data you never collected cannot leak.
- Let people out. People can ask for a copy of their data, ask for corrections, and in many cases ask you to delete it. You normally have one month to respond, and you cannot charge.
- Marketing has separate rules. PECR, not GDPR, governs marketing email. Sending to individuals — which includes sole traders and most partnerships — generally needs consent or an existing customer relationship. Buying a list is not consent.
Keeping it proportionate
For a one-person studio this is a morning's work: pay the fee, put a privacy notice on the site, keep the customer list somewhere access-controlled rather than in a shared inbox, and delete what you no longer need. The regime is scaled — nobody expects a ceramicist to appoint a data protection officer.
For what it is worth, this directory is registered with the ICO and its registration number, lawful basis and full assessment are published on our privacy page. If you want to see what one of these looks like written out, it is there.
Sources
Everything above was checked against these on 12 August 2026. Fees and thresholds change — if you are about to act on a number, follow the link and confirm it.