Top-tier data-processing fees rise sixfold to £2,900 in new ICO funding structure
Large organisations that process personal data will see their annual subsidy contribution rise from £500
The new funding model for the Information Commissioner’s Office will see the annual costs for large businesses increase from £500 to £2,900.
The Data Protection Fee system will require entities that process personal data to pay an annual fee depending on their size. The system is split into three tiers:
- Tier 1: Micro organisations that have an annual turnover of up to £632,000 and/or 10 or fewer members of staff must pay £40
- Tier 2: Small and medium organisations that have an annual turnover of up to £36m and/or 250 or fewer members of staff must pay £60
- Tier 3: Large organisations that do not qualify for either of the first two tiers must pay £2,900
Organisations are exempt from paying the fees if they process data only for one or more of the following reasons: staff administration; advertising, marketing, and public relations; accounts and records; not-for-profit purposes; personal, family, or household affairs; maintaining a public register; judicial functions.
Exemptions also apply to organisations who process personal data without an automating tool, such as a computer.
- ICO planning ‘three-tier system’ of data-processing fees as post-GDPR funding model
- The ten key questions – and nine answers – facing the public sector on GDPR
- Nine in ten businesses and charities have done nothing to prepare for GDPR, government research finds
When calculating their tier, public-sector organisations need only bear in mind numbers of staff – and not annual turnover. All charities that are not exempt will only be liable to pay the tier 1 fee, as will small occupational pensions schemes.
To help organisations work out what they need to pay, the ICO will equip its website with a self-assessment tool before the new rules take effect 25 May – the same day as the EU General Data Protection Regulation comes into effect.
Under the previous two-tier system, data-processing organisations were required to register with the ICO by providing notice of what information they were handling and how it was being used. For this, they were charged a notification fee of either £35, for companies with either fewer than 250 staff or a turnover of under £25.9m, or £500, for every organisation that did not meet either of those criteria.
The new fee structure, which was presented to parliament earlier this week, is designed to fulfil the government’s statutory obligation to ensure the ICO is sufficiently funded.
Commissioner’s progress report includes revelations about UKIP’s non-compliance and a six-figure penalty for a pregnancy website that supplied data for Labour Party marketing
Paul Maltby claims councils must first renew ageing infrastructure before realising the benefits of machine learning and automation
Director general Kevin Cunnington gives speech detailing how the organisation has ‘changed the way we work with departments’
David Lidington says Carillion collapse shows need to increase range of suppliers working with public sector
The cautionary tale of the Leicestershire teenager who hacked high-ranking officials of NATO allies shows the need for improved password security
Calm has turned a section of the 57,509-word EU document into a sleep-inducing audio book