Two sole traders, same trade, same town. One pays the Information Commissioner's Office £52 a year she never owed. The other has never heard of the fee, does owe it, and is one automated ICO letter away from a £400 penalty. Both of them believe they have data protection handled.
The question of whether you owe the fee is genuinely answerable in about three minutes, and this article answers it. It also covers the three things that changed in 2026 and now apply to you whether you pay a fee or not — including one that became a legal duty on 19 June 2026 and has no small-business exemption.
Does a sole trader owe the ICO fee? Usually not
The fee comes from the Data Protection (Charges and Information) Regulations 2018. You owe it if you process personal data as a controller — unless everything you do with personal data falls inside the exempt purposes. Three of those purposes cover most of what an ordinary one-person business does:
- Staff administration — recruitment, payroll, sickness records, for your own staff.
- Advertising, marketing and public relations — but only for your own business activity, goods or services. If you obtain someone's details from a third party, it has to be to market your own offering, not somebody else's.
- Accounts and records — keeping your accounts, deciding whether to accept someone as a customer or supplier, and recording purchases, sales and other transactions. The people you hold data about are limited to past, present and prospective customers and suppliers.
Read that list against a typical trade. Your client names and numbers, your job history, your invoices, your supplier records, your own mailing list — all inside. Which is why the honest answer for a great many sole traders is that no fee is due at all.
The two things that break the exemption
Almost every sole trader who thinks they are exempt and is not has been caught by one of these:
- CCTV. Any camera used for a non-domestic purpose takes you outside the exemption — a camera over the workshop door, one covering the van bay, a dashcam kept for business reasons. It does not matter that everything else you do would have been exempt. One camera makes the whole business chargeable.
- A purpose that is not on the list. Holding health or treatment notes is not "accounts and records" — a sports massage therapist's intake forms, a mobile chiropodist's clinical notes, a personal trainer's par-Q screening. Nor is profiling, tracking, or processing data on somebody else's behalf.
The ICO runs a free self-assessment at ico.org.uk/for-organisations/data-protection-fee/self-assessment/. It is about a dozen questions and it gives you a definitive answer. Do it once and write down the date you did it, because being able to say when you checked is worth something and "I assumed" is worth nothing.
What it costs if you do owe it
Three tiers, unchanged for 2026/27. The current amounts were set by the Data Protection (Charges and Information) (Amendment) Regulations 2025 and came into force on 17 February 2025:
- Tier 1 — micro: no more than 10 staff or turnover no more than £632,000. £52 a year, or £47 by direct debit. This is the tier essentially every sole trader falls into.
- Tier 2 — small and medium: no more than 250 staff and turnover no more than £36 million. £78, or £73 by direct debit.
- Tier 3 — large: everyone else. £3,763, or £3,758 by direct debit.
Not paying carries a fixed penalty: £400 at tier 1, £600 at tier 2 and £4,000 at tier 3. The ICO can increase that up to a statutory maximum of £4,350 where there are aggravating factors, the most common being a business that simply does not respond to its letters. These go out in batches after written warnings, so nobody is ambushed — they are penalties for ignoring post, not for a misunderstanding.
Priya, mobile hairdresser. Holds client names, mobile numbers and appointment history. Texts her own clients about her own availability. No staff, no cameras, nothing processed for anyone else. Every purpose sits inside accounts and records plus advertising her own services. Fee due: £0.
Dan, self-employed locksmith. Identical client records — plus a camera over the van bay that also films the pavement. That is non-domestic CCTV, so the exemption fails for the whole business, not just the camera. Tier 1 applies: £52, or £47 by direct debit — 13p a day.
If Dan ignores it. Warning letter, then a £400 fixed penalty, with headroom to £4,350 if he still will not engage. Being wrong costs at least eight times what being right costs, and the gap widens the longer it is left.
No fee due is not the same as no obligations
A "no fee" result means one thing only: you do not send the ICO £52. Every duty under the UK GDPR still applies to you in full. The four that matter to a one-person business:
- A lawful basis. For client work it is usually performance of a contract. For marketing it is usually consent. For keeping records after a job ends it is usually legal obligation — HMRC requires you to keep business records for at least five years after the 31 January filing deadline, which is also your answer when someone asks why you still hold their invoice.
- A privacy notice. What you collect, why, how long you keep it, who you share it with, and how to complain. One page. It belongs on your website and, if you have no website, in your terms.
- Subject access. Someone can ask what you hold about them. You have one month from receipt to respond, extendable by up to two further months if the request is complex or you have received several from the same person — but you must tell them inside the first month that you are extending, and why.
- Breach reporting. Where a breach poses a risk to people's rights and freedoms, you report it to the ICO without undue delay and within 72 hours of becoming aware. Where the risk is high, you tell the affected people too. A lost, unencrypted laptop with a client list on it is the classic sole-trader version — and encryption is precisely what turns that from a notifiable breach into a bad afternoon.
Three things changed in 2026
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and its main provisions commenced on 5 February 2026. Three of them reach a one-person business.
1. Marketing fines went up thirty-five-fold
The Privacy and Electronic Communications Regulations govern marketing emails, texts and cookies. For more than twenty years the maximum penalty for breaching them was £500,000. From 5 February 2026 it is £17.5 million or 4% of global annual turnover, whichever is higher — the same ceiling as the UK GDPR. No sole trader is going to see a number like that. The point is the change in posture: electronic marketing has stopped being the cheap corner of data protection law.
2. Some cookies no longer need consent — but narrowly
From the same date, storing or reading information purely for statistical purposes about how your website is used, with a view to improving it, is exempt from the consent requirement. So is remembering how the site looks for a returning visitor. The catch is the word "solely": the data has to be used only to improve your own service and not shared with anyone else except to help with those improvements, and you must still offer a simple, free way to object.
That wording excludes Google Analytics and the Meta pixel, both of which pass data onward for the provider's own purposes. If your site runs either, the banner stays. The ICO's finalised guidance on storage and access technologies was published on 29 April 2026.
3. You now need a complaints route — this one is a legal duty
From 19 June 2026, every controller must operate a process through which people can complain about how their personal data has been handled. You must acknowledge a complaint within 30 days of receiving it, investigate it without undue delay, and tell the person the outcome. If you can investigate and give a substantive answer inside the 30 days, a separate acknowledgement is not needed.
There is no exemption for small businesses. For a sole trader this is genuinely small — a named email address, a line in the privacy notice saying where to send a complaint and that you will acknowledge within 30 days, and a note in your diary. But it has to exist, and someone has to be able to find it.
The marketing rule that catches sole traders selling to sole traders
PECR splits everyone you might email into two groups, and the dividing line is not the one people expect. It is not business versus consumer — it is corporate subscriber versus individual subscriber.
- Corporate subscribers — limited companies, LLPs and Scottish partnerships. You may send them marketing email without prior consent, as long as you identify yourself and give an opt-out in every message.
- Individual subscribers — consumers, and sole traders, and ordinary partnerships. PECR treats them exactly like private individuals. Consent, or the soft opt-in. Nothing else will do.
The soft opt-in requires all four of these, not three:
- You obtained the address in the course of a sale, or negotiations for a sale, of your product or service.
- You are marketing your own similar products or services.
- You gave a clear opportunity to refuse when you collected the address.
- You give an opportunity to refuse in every message you send.
This is why a bought list of "UK tradespeople" is unusable. You cannot tell from an email address which of them are limited companies and which are sole traders, you never sold to any of them, and the soft opt-in fails at the first condition. The same logic applies to scraped contact pages and to LinkedIn exports.
Security: the same habits that stop fraud
Data protection and fraud prevention run on one toolkit:
- Two-factor authentication on email first, then banking, then anything holding client data. Email first because it is the reset route into everything else.
- A password manager. Unique passwords everywhere beats one strong password reused, because reuse means one leaked site hands over all of them.
- Device encryption and a backup you have actually restored from. An untested backup is a hope, not a control.
- Hold less. The cheapest way to secure client data is not to keep what you no longer need. Old quotes, dead leads, a decade of read receipts — deleting them is compliance and housekeeping at once, and it sits naturally alongside tidy bookkeeping records.
What to do this week
- Run the ICO self-assessment. Three minutes. Save the result with the date.
- If you owe the fee, pay by direct debit. £47 rather than £52, and it renews itself instead of lapsing quietly.
- Add the complaints line to your privacy notice — where to send one, and that you will acknowledge within 30 days. Statutory since 19 June 2026.
- Open your site and see what the banner actually loads. Google Analytics or a Meta pixel means the new exemptions do not reach you and consent is still required.
- Split your mailing list by entity type. Limited companies and LLPs on one side, sole traders and ordinary partnerships on the other. Only the first group can be emailed without consent.
- Turn on two-factor authentication on your email account, and restore one file from your backup to prove it works.
Where we help
We are accountants, not data protection lawyers, and the ICO self-assessment is something you can run yourself in less time than it takes to read this. What we do is stop the bill being a surprise: the fee, where it applies, is an allowable business expense, and the records you keep for us are the same records the retention question turns on. Fixed fees from £19 + VAT a month, Self Assessment included. Get started.








