Top-tier data-processing fees rise sixfold to £2,900 in new ICO funding structure
Large organisations that process personal data will see their annual subsidy contribution rise from £500
The new funding model for the Information Commissioner’s Office will see the annual costs for large businesses increase from £500 to £2,900.
The Data Protection Fee system will require entities that process personal data to pay an annual fee depending on their size. The system is split into three tiers:
- Tier 1: Micro organisations that have an annual turnover of up to £632,000 and/or 10 or fewer members of staff must pay £40
- Tier 2: Small and medium organisations that have an annual turnover of up to £36m and/or 250 or fewer members of staff must pay £60
- Tier 3: Large organisations that do not qualify for either of the first two tiers must pay £2,900
Organisations are exempt from paying the fees if they process data only for one or more of the following reasons: staff administration; advertising, marketing, and public relations; accounts and records; not-for-profit purposes; personal, family, or household affairs; maintaining a public register; judicial functions.
Exemptions also apply to organisations who process personal data without an automating tool, such as a computer.
- ICO planning ‘three-tier system’ of data-processing fees as post-GDPR funding model
- The ten key questions – and nine answers – facing the public sector on GDPR
- Nine in ten businesses and charities have done nothing to prepare for GDPR, government research finds
When calculating their tier, public-sector organisations need only bear in mind numbers of staff – and not annual turnover. All charities that are not exempt will only be liable to pay the tier 1 fee, as will small occupational pensions schemes.
To help organisations work out what they need to pay, the ICO will equip its website with a self-assessment tool before the new rules take effect 25 May – the same day as the EU General Data Protection Regulation comes into effect.
Under the previous two-tier system, data-processing organisations were required to register with the ICO by providing notice of what information they were handling and how it was being used. For this, they were charged a notification fee of either £35, for companies with either fewer than 250 staff or a turnover of under £25.9m, or £500, for every organisation that did not meet either of those criteria.
The new fee structure, which was presented to parliament earlier this week, is designed to fulfil the government’s statutory obligation to ensure the ICO is sufficiently funded.
A recent study finds that the pandemic has boosted budgets – but legacy tech remains a big barrier to progress
An annual survey from techUK shows that significant barriers remain for smaller firms wishing to supply government, according to Henry Rex
Deals awarded to Post Office and Digidentity also include the transfer of data to government
Newly created entity will also focus on data infrastructure
It’s been one of the most challenging years for healthcare providers, but Salesforce sees lasting change from accelerated digital transformation
Cloud-based applications can provide ways for agencies and departments to innovate and operate in new ways, as the past year has highlighted they must, writes Oracle
Higher Education institutions are some of the most consistently targeted organisations for cyberattacks. CrowdStrike explores the importance of the right cybersecurity measures.