Skip to content

Research · authority data, public-interest

← Tracker

United Kingdom

Authority: ICO (Information Commissioner's Office)

Last reviewed: 19 Jul 2026

Data-protection authority
The regulator responsible for enforcement.

The Information Commissioner's Office (ICO) enforces the UK GDPR and DPA 2018.

Source: Data Protection Act 2018, s. 114· Reviewed 19 Jul 2026

DPO appointment
When a Data Protection Officer must be appointed.

Mandatory for public authorities and for core processing that requires systematic monitoring or large-scale special-category processing.

Source: UK GDPR Art. 37· Reviewed 19 Jul 2026

Controller registration / licensing
Whether controllers must register or be licensed with the authority.

No licensing regime. Most controllers must pay the annual data-protection fee to the ICO under the 2018 Fee Regulations.

Source: Data Protection (Charges and Information) Regulations 2018· Reviewed 19 Jul 2026

Registration / licence fees
Statutory fees payable to the authority.

Annual fee £52 (Tier 1, micro) · £78 (Tier 2, SME) · £3 763 (Tier 3, large). No fee for the licence itself — licensing not required.

Source: ICO Data Protection Fee, 2024· Reviewed 19 Jul 2026

Breach notification clock
How quickly a personal-data breach must be notified.

Notify the ICO within 72 hours of becoming aware of a personal-data breach; notify affected data subjects without undue delay where high risk.

Source: UK GDPR Arts. 33–34· Reviewed 19 Jul 2026

Data-subject rights
Core rights afforded to data subjects.

Access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making.

Source: UK GDPR Arts. 15–22· Reviewed 19 Jul 2026

Cross-border transfers
Rules governing transfers of personal data out of the jurisdiction.

Adequacy decisions, UK IDTA / Addendum to EU SCCs, BCRs, or Article 49 derogations.

Source: UK GDPR Arts. 44–49· Reviewed 19 Jul 2026

Penalties
Maximum administrative or criminal penalties for non-compliance.

Up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements.

Source: DPA 2018, s. 157; UK GDPR Art. 83· Reviewed 19 Jul 2026