ICO Data Protection Register

How to check whether a company is registered with the ICO

The official register is the ICO's register of fee payers, it is free to search at ico.org.uk, and it shows whether an organisation has paid its annual data protection fee and when that payment expires. It does not show whether the organisation complies with the UK GDPR.

Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.

The one-line answer

Search the ICO's register of fee payers at ico.org.uk/ESDWebPages/Search. It is free and needs no account. An entry proves an organisation has paid its data protection fee and that the payment is in date. It proves nothing about whether that organisation actually complies with data protection law.

Where the official register is, and what it actually shows

The ICO publishes one public register of organisations that pay the data protection fee. The landing page is Register of fee payers and certificate downloads, and the search form itself is at ico.org.uk/ESDWebPages/Search.

The ICO says there are more than one million fee payers on the register. The search page describes it as covering organisations and people registered with the ICO under the Data Protection Act 2018, so sole traders appear under their own names as well as companies.

Detail Published on the register?
Controller's name and address Yes. For a registered company this is the registered office address
Registration reference Yes. References begin with Z, A or C
Payment tier (1, 2 or 3) Yes
Date registered and registration expiry date Yes
Any other trading names Yes
Data protection officer's contact details Yes, if the organisation has told the ICO it has a DPO
Data protection officer's name Only if the DPO ticked the opt-in consent box
Freedom of information statement Yes, where the controller states it is a public authority under the Freedom of Information Act 2000 or a Scottish public authority under the Freedom of Information (Scotland) Act 2002
Contact details of individuals nominated as the ICO's contact points No
What personal data the organisation holds, or what it does with it No

That final row is the one procurement teams most often misread. The register is a record of fee payment and basic identity. It does not describe an organisation's processing, its security, or its retention practices.

How to search it reliably

The ICO's own tip on the search page is to search by one field at a time, preferably the registration reference, and it adds that if you do not know the reference, searching by just the postcode or name is most likely to find the registration. Filling in name and postcode together therefore cuts against the ICO's own advice, and is an easy way to make a genuine registration look missing.

  1. Step 1 Start with the registration reference If a supplier has given you a reference — on an invoice, a privacy notice or a tender response — put it in the Registration reference box and leave Name and Postcode empty. The ICO's search help gives Z5347709 as an example format; some references carry a two-letter prefix instead, such as ZB050228.
  2. Step 2 Fall back to the postcode If you do not have the reference, the ICO recommends searching by just the postcode or name. Use the registered office postcode for a limited company. That is often not the trading address you deal with.
  3. Step 3 Search the legal name, not the brand The register lists the controller's registered legal name. Large groups typically register one legal entity rather than the customer-facing brand. Other trading names are recorded, so it is worth trying both.
  4. Step 4 Use wildcards to widen a name search The ICO's search help says that to match text occurring anywhere within a word you put a * either side of it. Its own worked examples use a trailing star: macG* finds names beginning macG, such as MacGregor, and a postcode search of SK9 5* finds entries containing SK9 5, such as SK9 5AF. The ICO warns that a stem as broad as macd* will exceed the 100-record limit.
  5. Step 5 Watch the 100-record limit Where more than one entry matches, the ICO shows a selection list of up to 100 entries. If your search is too broad, the ICO tells you to be more specific rather than showing you everything.

Two working days for changes, up to seven for a brand-new registration

The ICO's search page says data controllers are officially registered from the date it receives payment, but that changes to the register may take up to two working days to appear. For a first-time registration the ICO's own registration service is more cautious: it says it will usually send confirmation the following working day and publish the registration on the register of fee payers within seven working days. Plan for seven. If you have a query about the register, the ICO gives 0303 123 1113.

What it means if a company is not on the register

An absent entry is not evidence of wrongdoing. Several innocent explanations are more likely than non-compliance.

Where an organisation genuinely should have paid and has not, the consequence is a civil penalty, not a prosecution. The ICO's own fixed-penalties document states that a breach of the Charges Regulations is a matter falling under section 149(5) of the Data Protection Act 2018 — the fourth type of failure — and that section 155(1) allows the Commissioner to serve a penalty notice. The ICO publishes the fixed amounts it will use.

Tier Annual fee Fixed penalty for non-payment
Tier 1 — micro organisations £52 £400
Tier 2 — small and medium organisations £78 £600
Tier 3 — large organisations £3,763 £4,000
Statutory maximum, where a controller fails to give the ICO enough information to determine the fee or exemption and there are aggravating factors £4,350

Non-payment is not a criminal offence

The ICO's published position is that failure to pay the fee is dealt with by a fixed civil penalty notice under the Data Protection Act 2018, not by prosecution. Guidance that calls it a criminal offence is describing the old notification regime, not the law as it stands. The fees shown above are the amounts set by the Data Protection (Charges and Information) (Amendment) Regulations 2025 (SI 2025/63), in force since 17 February 2025, and each is reduced by £5 if paid by direct debit.

For due diligence there is a second, separate ICO list: penalty notices issued for non-payment of the data protection fee, broken down by year. The ICO says that for privacy reasons it does not include personally identifiable sole traders or partnerships, and does not include any penalty notice subject to an ongoing appeal.

How to find and download your own registration certificate

There is no separate certificate portal or login. The "Download registration certificate" button on the ICO's register of fee payers page points at the same public search form everyone else uses.

  1. Step 1 Search for your own entry The ICO recommends searching for your certificate using your registration reference only. If you do not have it, it recommends searching by your postcode.
  2. Step 2 Open your entry and click the certificate link Each entry page carries a Registration certificate PDF link at the address ico.org.uk/ESDWebPages/RegistrationCertificate/ followed by your reference.
  3. Step 3 Check the expiry date before you submit Registration runs for a year and must be renewed annually to stay valid. Buyers and PQQ portals normally want a certificate that is in date on the submission date, so check the expiry shown on your entry, not just that you appear at all.
  4. Step 4 Allow time for a new registration The register of fee payers page says new registrations and certificates take two working days to become available to download, but the ICO's registration service says a first-time registration is published on the register within seven working days. Do not leave this to the afternoon of a tender deadline.

Anyone can download anyone's certificate

The certificate link sits on the public entry. A buyer can pull your certificate without asking you, and you can pull a supplier's without asking them. That cuts both ways: it is a quick verification route, and it means the certificate is not a confidential document.

Data protection officers, and downloading the whole register

You can sometimes see who an organisation's DPO is. The ICO publishes DPO contact details where an organisation has reported a DPO, and publishes the DPO's name only where that individual has consented via an opt-in box. The ICO's own entry, reference Z5347709, shows how that looks: a named officer with a departmental address, an email address and a telephone number.

A blank DPO field therefore does not mean there is no DPO. It may mean the organisation has not reported one, or that the DPO declined to have their name published. The ICO says that where a DPO has opted out and it is asked to release the name under the Freedom of Information Act 2000, it will have to consider whether it can disclose it, will not routinely provide it, but may have to disclose it if its position is challenged in law and it is ordered to do so.

The full register is available in bulk from the ICO's download the register page as a ZIP dataset — around 73 MB when checked in late July 2026 — with a published SHA256 checksum. It is updated daily, and the ICO asks re-users to use the latest version. The data is made available under the ICO's copyright and re-use statement, and while it is offered for re-use under the Open Government Licence, the ICO is explicit that the licence does not apply to the personal data in the dataset and that your own obligations apply when you process it.

Copies and mirrors of the register exist elsewhere on the web, including this site. They are not official, and none of them controls how often the ICO's own data changes. For anything that has to stand up in a contract, an audit file or a dispute, use the ICO's own search and keep the dated PDF certificate.

Registration is not proof of GDPR compliance

Paying a fee is a payment, not an audit

The ICO does not inspect an organisation before adding it to the register. Tier is a proxy for size, not for risk practices — and the ICO's guide states in terms that it regards all controllers as eligible to pay a fee in tier 3 unless and until they tell it otherwise, so a tier 3 entry can simply mean nobody supplied staff and turnover figures. The ICO also states plainly that even if you are exempt from paying a fee, you still need to comply with your other data protection obligations.

If you are vetting a processor or a supplier, the register answers one narrow question. These are the things it cannot answer, and which you would need to ask for separately:

Will the register change when the ICO becomes the Information Commission?

Not yet, and nothing about the register has changed so far. The Information Commission was established as a body corporate on 20 August 2025 under section 117 of the Data (Use and Access) Act 2025, commenced by SI 2025/904 (all of section 117 except subsection (4)(a)). But sections 118 and 119 — which abolish the office of Information Commissioner and transfer its functions — are not in force as at 31 July 2026. Section 119 is still marked prospective on legislation.gov.uk. The regulator you are searching is legally still the Information Commissioner.

DSIT said on 15 July 2026, announcing seven non-executive board members, that "later this year, the Commission will take over all the functions and responsibilities of the ICO". No commencement date has been appointed, and no plan for migrating the register's web addresses has been published.

Two practical points follow. First, the duty to pay is unaffected by the renaming: the Data Protection (Charges and Information) Regulations 2018 still apply, and the tiers are still £52, £78 and £3,763. Second, avoid hard-coding ico.org.uk/ESDWebPages/... links into tender templates or supplier questionnaires that you will not revisit — link to the register of fee payers landing page instead, and re-check the address before a transfer date is announced.

Common questions

How do I check if a company is registered with the ICO for free?

Go to the ICO's register search at ico.org.uk/ESDWebPages/Search and enter one field at a time — ideally the registration reference, otherwise just the postcode or name. There is no charge, no account and no login. If the organisation is a fee payer you will see its name, address, tier, registration date and expiry date, plus a downloadable certificate.

Is my ICO registration number the same as my company number?

No. They are issued by different bodies and look different. An ICO registration reference begins with Z, A or C — for example Z5347709 or ZB050228. A Companies House company number is normally eight characters and usually numeric. A tender asking for your "ICO number" wants the reference on your register entry and certificate.

A supplier says they don't need to register — is that plausible?

It can be. The ICO lists exemptions covering processing only for staff administration; advertising, marketing and public relations; accounts and records; not-for-profit purposes; personal, family or household affairs; maintaining a public register; judicial functions; and processing personal information without an automated system such as a computer. Very few businesses that use a computer for customer data fall inside these. If they claim exemption, ask which one and why. Being exempt from the fee does not exempt them from data protection law.

How long does a new ICO registration take to appear on the register?

The ICO gives two figures. Its search page says a controller is officially registered from the date payment is received but that changes to the register may take up to two working days to appear, and the register of fee payers page says new registrations and certificates take two working days to become available to download. Its registration service page is more cautious for first-time registrations, saying it will usually confirm the following working day and publish the registration within seven working days. If a tender closes tomorrow, that is a real risk.

Can I see who a company's data protection officer is?

Sometimes. The ICO publishes DPO contact details where the organisation has told it a DPO exists, and publishes the DPO's name only where that person has consented by ticking an opt-in box. If the field is blank it may mean no DPO was reported, or that the DPO opted out of having their name published.

Does being on the ICO register mean a company is GDPR compliant?

No. The register records that the annual data protection fee has been paid and is in date. The ICO does not assess or audit an organisation before listing it, and the payment tier reflects size and turnover, not the quality of its data protection practices. Treat a register entry as one tick in a due diligence pack, not as assurance.

Sources

This page summarises the following primary sources. Where they disagree with this summary, they take precedence.

Related guidance