ICO (Information Commissioner’s Office)
Category: Regulation and compliance
Also known as: the Information Commissioner’s Office, the data protection regulator, the Information Commissioner
Related concepts: UK GDPR, Data Protection Act 2018, FCA
What the ICO is
The Information Commissioner’s Office is the UK’s independent regulator for information rights, covering both data protection and access to information. It is the body businesses register with, report personal data breaches to, and answer to if something goes wrong with personal information they hold.
The law it enforces
The ICO’s remit spans the UK GDPR and the Data Protection Act 2018, the Privacy and Electronic Communications Regulations, which govern electronic direct marketing and cookies, and the Freedom of Information Act 2000 and Environmental Information Regulations 2004 for public authorities. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and amended parts of the data protection framework; the ICO states that the provisions affecting data protection law and the Privacy and Electronic Communications Regulations are now in force.
Registration and the data protection fee
Organisations, including sole traders, that use personal information generally have to pay an annual data protection fee to the ICO unless they are exempt. There are three tiers. Tier 1 costs £52 and applies to organisations with a maximum turnover of £632,000 for the financial year, or no more than 10 members of staff. Tier 2 costs £78 and applies where turnover is no more than £36 million, or staff no more than 250. Tier 3 costs £3,763 and applies to everyone else. Paying by direct debit attracts an automatic £5 discount at the point of payment.
The fee is small and the obligation is easy to overlook, particularly for a business that has changed size since it last registered.
Enforcement and the size of penalties
The ICO has a range of enforcement tools, from assessments and reprimands through enforcement notices to monetary penalties. The maximum penalty amounts are set by section 157 of the Data Protection Act 2018. The standard maximum is, for an undertaking, £8,700,000 or 2% of total annual worldwide turnover in the preceding financial year, whichever is higher, and £8,700,000 in any other case. The higher maximum is £17,500,000 or 4% of total annual worldwide turnover, whichever is higher, and £17,500,000 in any other case. Those are ceilings rather than expectations, and the great majority of ICO cases end well below them — but they set the scale of the tail risk.
Breach reporting
A personal data breach that meets the threshold in the UK GDPR must be reported to the ICO without undue delay and, where feasible, not later than 72 hours after the controller becomes aware of it. Where the breach is likely to result in a high risk to the rights and freedoms of individuals, those individuals must be told as well. The 72-hour clock is the reason incident response is a planning exercise rather than an improvisation: the decision about whether a breach is reportable has to be made while the facts are still incomplete.
Where insurance fits, and where it does not
Cyber insurance is the policy that engages with all of this. Cover typically funds the incident response: forensic investigation, legal advice on whether the breach is notifiable, notification of affected individuals, call-centre and credit-monitoring support, and the legal costs of responding to a regulatory investigation. Many policies also offer cover for regulatory fines and penalties, but only where such cover is insurable by law — whether a particular penalty is insurable is a legal question that turns on the penalty and the jurisdiction, and no policy can promise otherwise.
What insurance cannot do is shift the duty. The controller remains the controller. Nor does it repair the reputational consequence, or the operational disruption, or the fact that the ICO’s findings become public. Insurance pays for the response; the governance still has to be yours. Directors should also note that data governance failures can surface as allegations against them personally, which is where directors’ duties and directors’ and officers’ cover come into it.
Frequently asked questions
Do we have to register with the ICO?
Most organisations that process personal information, including sole traders, must pay an annual data protection fee unless an exemption applies. The fee is banded in three tiers by turnover and staff numbers, and the ICO publishes a self-assessment tool to work out which tier applies to you.
How large can an ICO penalty be?
Section 157 of the Data Protection Act 2018 sets a standard maximum of the higher of 8.7 million pounds or 2% of total annual worldwide turnover for an undertaking, and a higher maximum of the higher of 17.5 million pounds or 4%. Those are statutory ceilings; actual penalties are set case by case and are usually far lower.
Does cyber insurance pay ICO fines?
Many cyber policies offer cover for regulatory fines and penalties only where insurance of that fine is permitted by law. Whether a specific penalty is insurable is a legal question, so the practical value of the cover is usually in the investigation and defence costs, the incident response and the notification expense rather than in the fine itself.
Related entries
- /wiki/uk-gdpr/
- /wiki/data-protection-act-2018/
- /wiki/fca/
- /wiki/directors-duties-companies-act-2006-uk-2026/
- /wiki/directors-and-officers-insurance/
This entry is part of the Apex Insurance Wiki. It is insurance information about how UK cover responds to the rules described, and is not legal or regulatory advice. Rules, limits and wordings change; the position stated is as at August 2026. Check the primary source and take your own professional advice before relying on any of it.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
