Does a data controller need to register with the ICO?
Andrew Mckinney
Updated on June 07, 2026
Do I need ICO registration? As part of the Data Protection Act, any entity that processes personal information will need to register with the ICO and pay a data protection fee unless they are exempt.
Can a data subject be a data controller?
This led the French Data Protection Authority to argue in its guidance on blockchains and the GDPR that a data subject could indeed be a data controller in relation to personal data that relates to themselves.
Are we a data processor or controller?
The data controller is the person (or business) who determines the purposes for which, and the way in which, personal data is processed. By contrast, a data processor is anyone who processes personal data on behalf of the data controller (excluding the data controller’s own employees).
Does GDPR distinguish between B2B and B2C?
Does the GDPR distinguish between B2B and B2C? While the GDPR does not make any distinction between business types in general, there may be some differences in practice.
Can a data controller process data?
Definition of a Data Controller A data controller can process collected data using its own processes. In some instances, however, a data controller needs to work with a third-party or an external service in order to work with the data that has been gathered.
Do all companies need to pay ICO?
Every organisation or sole trader who processes personal information needs to pay a data protection fee to the ICO, unless they are exempt.
What happens if not registered with ICO?
You need to renew your data protection fee each year, or tell the ICO if your registration is no longer required. If you fail to do so, the ICO can issue a monetary penalty of up to £4,000 on top of the fee you are required to pay.
What is more important data security or data privacy or data utility?
For example, encryption helps ensure data privacy, but it could also be a data security tool. The main difference between data security and data privacy is that privacy is about ensuring only those who are authorized to access the data can do so. Data security is more about guarding against malicious threats.
Can you have two data controllers?
If two or more controllers jointly determine the purposes and means of processing the same personal data, they are joint controllers. However, they are not joint controllers if they are processing the same data for different purposes.
Does GDPR apply to B2B emails?
Does GDPR apply to B2B emails? Yes. Before sending a cold email you’ll need to verify that you’re allowed to contact them under the GDPR. There are six ways to establish a lawful basis to process someone’s personal data: consent, contract, legal obligation, vital interests, public task and legitimate interest.