How to check whether a company is registered with the ICO
The official register is the ICO's register of fee payers, it is free to search at ico.org.uk, and it shows whether an organisation has paid its annual data protection fee and when that payment expires. It does not show whether the organisation complies with the UK GDPR.
Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.
The one-line answer
Search the ICO's register of fee payers at ico.org.uk/ESDWebPages/Search. It is free and needs no account. An entry proves an organisation has paid its data protection fee and that the payment is in date. It proves nothing about whether that organisation actually complies with data protection law.
Where the official register is, and what it actually shows
The ICO publishes one public register of organisations that pay the data protection fee. The landing page is Register of fee payers and certificate downloads, and the search form itself is at ico.org.uk/ESDWebPages/Search.
The ICO says there are more than one million fee payers on the register. The search page describes it as covering organisations and people registered with the ICO under the Data Protection Act 2018, so sole traders appear under their own names as well as companies.
| Detail | Published on the register? |
|---|---|
| Controller's name and address | Yes. For a registered company this is the registered office address |
| Registration reference | Yes. References begin with Z, A or C |
| Payment tier (1, 2 or 3) | Yes |
| Date registered and registration expiry date | Yes |
| Any other trading names | Yes |
| Data protection officer's contact details | Yes, if the organisation has told the ICO it has a DPO |
| Data protection officer's name | Only if the DPO ticked the opt-in consent box |
| Freedom of information statement | Yes, where the controller states it is a public authority under the Freedom of Information Act 2000 or a Scottish public authority under the Freedom of Information (Scotland) Act 2002 |
| Contact details of individuals nominated as the ICO's contact points | No |
| What personal data the organisation holds, or what it does with it | No |
That final row is the one procurement teams most often misread. The register is a record of fee payment and basic identity. It does not describe an organisation's processing, its security, or its retention practices.
How to search it reliably
The ICO's own tip on the search page is to search by one field at a time, preferably the registration reference, and it adds that if you do not know the reference, searching by just the postcode or name is most likely to find the registration. Filling in name and postcode together therefore cuts against the ICO's own advice, and is an easy way to make a genuine registration look missing.
-
Step 1
Start with the registration reference
If a supplier has given you a reference — on an invoice, a privacy notice or a tender response — put it in the Registration reference box and leave Name and Postcode empty. The ICO's search help gives
Z5347709as an example format; some references carry a two-letter prefix instead, such asZB050228. - Step 2 Fall back to the postcode If you do not have the reference, the ICO recommends searching by just the postcode or name. Use the registered office postcode for a limited company. That is often not the trading address you deal with.
- Step 3 Search the legal name, not the brand The register lists the controller's registered legal name. Large groups typically register one legal entity rather than the customer-facing brand. Other trading names are recorded, so it is worth trying both.
-
Step 4
Use wildcards to widen a name search
The ICO's search help says that to match text occurring anywhere within a word you put a
*either side of it. Its own worked examples use a trailing star:macG*finds names beginning macG, such as MacGregor, and a postcode search ofSK9 5*finds entries containing SK9 5, such as SK9 5AF. The ICO warns that a stem as broad asmacd*will exceed the 100-record limit. - Step 5 Watch the 100-record limit Where more than one entry matches, the ICO shows a selection list of up to 100 entries. If your search is too broad, the ICO tells you to be more specific rather than showing you everything.
Two working days for changes, up to seven for a brand-new registration
The ICO's search page says data controllers are officially registered from the date it receives payment, but that changes to the register may take up to two working days to appear. For a first-time registration the ICO's own registration service is more cautious: it says it will usually send confirmation the following working day and publish the registration on the register of fee payers within seven working days. Plan for seven. If you have a query about the register, the ICO gives 0303 123 1113.
What it means if a company is not on the register
An absent entry is not evidence of wrongdoing. Several innocent explanations are more likely than non-compliance.
- They are exempt. The ICO lists exemptions where processing is only for staff administration; advertising, marketing and public relations; accounts and records; not-for-profit purposes; personal, family or household affairs; maintaining a public register; judicial functions; or processing personal information without an automated system. Members of the House of Lords, elected representatives and prospective representatives have also been exempt since 1 April 2019.
- You searched the wrong name. The contracting entity may be a subsidiary, not the brand on the website.
- The registration is very recent. See the publication lag above.
- They are a processor, not a controller. The fee duty under the Data Protection (Charges and Information) Regulations 2018 falls on controllers.
Where an organisation genuinely should have paid and has not, the consequence is a civil penalty, not a prosecution. The ICO's own fixed-penalties document states that a breach of the Charges Regulations is a matter falling under section 149(5) of the Data Protection Act 2018 — the fourth type of failure — and that section 155(1) allows the Commissioner to serve a penalty notice. The ICO publishes the fixed amounts it will use.
| Tier | Annual fee | Fixed penalty for non-payment |
|---|---|---|
| Tier 1 — micro organisations | £52 | £400 |
| Tier 2 — small and medium organisations | £78 | £600 |
| Tier 3 — large organisations | £3,763 | £4,000 |
| Statutory maximum, where a controller fails to give the ICO enough information to determine the fee or exemption and there are aggravating factors | — | £4,350 |
Non-payment is not a criminal offence
The ICO's published position is that failure to pay the fee is dealt with by a fixed civil penalty notice under the Data Protection Act 2018, not by prosecution. Guidance that calls it a criminal offence is describing the old notification regime, not the law as it stands. The fees shown above are the amounts set by the Data Protection (Charges and Information) (Amendment) Regulations 2025 (SI 2025/63), in force since 17 February 2025, and each is reduced by £5 if paid by direct debit.
For due diligence there is a second, separate ICO list: penalty notices issued for non-payment of the data protection fee, broken down by year. The ICO says that for privacy reasons it does not include personally identifiable sole traders or partnerships, and does not include any penalty notice subject to an ongoing appeal.
How to find and download your own registration certificate
There is no separate certificate portal or login. The "Download registration certificate" button on the ICO's register of fee payers page points at the same public search form everyone else uses.
- Step 1 Search for your own entry The ICO recommends searching for your certificate using your registration reference only. If you do not have it, it recommends searching by your postcode.
-
Step 2
Open your entry and click the certificate link
Each entry page carries a Registration certificate PDF link at the address
ico.org.uk/ESDWebPages/RegistrationCertificate/followed by your reference. - Step 3 Check the expiry date before you submit Registration runs for a year and must be renewed annually to stay valid. Buyers and PQQ portals normally want a certificate that is in date on the submission date, so check the expiry shown on your entry, not just that you appear at all.
- Step 4 Allow time for a new registration The register of fee payers page says new registrations and certificates take two working days to become available to download, but the ICO's registration service says a first-time registration is published on the register within seven working days. Do not leave this to the afternoon of a tender deadline.
Anyone can download anyone's certificate
The certificate link sits on the public entry. A buyer can pull your certificate without asking you, and you can pull a supplier's without asking them. That cuts both ways: it is a quick verification route, and it means the certificate is not a confidential document.
Data protection officers, and downloading the whole register
You can sometimes see who an organisation's DPO is. The ICO publishes DPO contact details where an organisation has reported a DPO, and publishes the DPO's name only where that individual has consented via an opt-in box. The ICO's own entry, reference Z5347709, shows how that looks: a named officer with a departmental address, an email address and a telephone number.
A blank DPO field therefore does not mean there is no DPO. It may mean the organisation has not reported one, or that the DPO declined to have their name published. The ICO says that where a DPO has opted out and it is asked to release the name under the Freedom of Information Act 2000, it will have to consider whether it can disclose it, will not routinely provide it, but may have to disclose it if its position is challenged in law and it is ordered to do so.
The full register is available in bulk from the ICO's download the register page as a ZIP dataset — around 73 MB when checked in late July 2026 — with a published SHA256 checksum. It is updated daily, and the ICO asks re-users to use the latest version. The data is made available under the ICO's copyright and re-use statement, and while it is offered for re-use under the Open Government Licence, the ICO is explicit that the licence does not apply to the personal data in the dataset and that your own obligations apply when you process it.
Copies and mirrors of the register exist elsewhere on the web, including this site. They are not official, and none of them controls how often the ICO's own data changes. For anything that has to stand up in a contract, an audit file or a dispute, use the ICO's own search and keep the dated PDF certificate.
Registration is not proof of GDPR compliance
Paying a fee is a payment, not an audit
The ICO does not inspect an organisation before adding it to the register. Tier is a proxy for size, not for risk practices — and the ICO's guide states in terms that it regards all controllers as eligible to pay a fee in tier 3 unless and until they tell it otherwise, so a tier 3 entry can simply mean nobody supplied staff and turnover figures. The ICO also states plainly that even if you are exempt from paying a fee, you still need to comply with your other data protection obligations.
If you are vetting a processor or a supplier, the register answers one narrow question. These are the things it cannot answer, and which you would need to ask for separately:
- Whether they hold a record of processing activities, or have carried out a DPIA where one is required.
- What technical and organisational measures they actually have in place.
- Whether they have suffered a personal data breach, and whether it was reported. Enforcement action is published separately, on the ICO's action we've taken pages, not on the register.
- Whether their Article 28 processor contract terms are adequate.
- Where personal data will be stored and who it will be transferred to.
Will the register change when the ICO becomes the Information Commission?
Not yet, and nothing about the register has changed so far. The Information Commission was established as a body corporate on 20 August 2025 under section 117 of the Data (Use and Access) Act 2025, commenced by SI 2025/904 (all of section 117 except subsection (4)(a)). But sections 118 and 119 — which abolish the office of Information Commissioner and transfer its functions — are not in force as at 31 July 2026. Section 119 is still marked prospective on legislation.gov.uk. The regulator you are searching is legally still the Information Commissioner.
DSIT said on 15 July 2026, announcing seven non-executive board members, that "later this year, the Commission will take over all the functions and responsibilities of the ICO". No commencement date has been appointed, and no plan for migrating the register's web addresses has been published.
Two practical points follow. First, the duty to pay is unaffected by the renaming: the Data Protection (Charges and Information) Regulations 2018 still apply, and the tiers are still £52, £78 and £3,763. Second, avoid hard-coding ico.org.uk/ESDWebPages/... links into tender templates or supplier questionnaires that you will not revisit — link to the register of fee payers landing page instead, and re-check the address before a transfer date is announced.
Common questions
How do I check if a company is registered with the ICO for free?
Go to the ICO's register search at ico.org.uk/ESDWebPages/Search and enter one field at a time — ideally the registration reference, otherwise just the postcode or name. There is no charge, no account and no login. If the organisation is a fee payer you will see its name, address, tier, registration date and expiry date, plus a downloadable certificate.
Is my ICO registration number the same as my company number?
No. They are issued by different bodies and look different. An ICO registration reference begins with Z, A or C — for example Z5347709 or ZB050228. A Companies House company number is normally eight characters and usually numeric. A tender asking for your "ICO number" wants the reference on your register entry and certificate.
A supplier says they don't need to register — is that plausible?
It can be. The ICO lists exemptions covering processing only for staff administration; advertising, marketing and public relations; accounts and records; not-for-profit purposes; personal, family or household affairs; maintaining a public register; judicial functions; and processing personal information without an automated system such as a computer. Very few businesses that use a computer for customer data fall inside these. If they claim exemption, ask which one and why. Being exempt from the fee does not exempt them from data protection law.
How long does a new ICO registration take to appear on the register?
The ICO gives two figures. Its search page says a controller is officially registered from the date payment is received but that changes to the register may take up to two working days to appear, and the register of fee payers page says new registrations and certificates take two working days to become available to download. Its registration service page is more cautious for first-time registrations, saying it will usually confirm the following working day and publish the registration within seven working days. If a tender closes tomorrow, that is a real risk.
Can I see who a company's data protection officer is?
Sometimes. The ICO publishes DPO contact details where the organisation has told it a DPO exists, and publishes the DPO's name only where that person has consented by ticking an opt-in box. If the field is blank it may mean no DPO was reported, or that the DPO opted out of having their name published.
Does being on the ICO register mean a company is GDPR compliant?
No. The register records that the annual data protection fee has been paid and is in date. The ICO does not assess or audit an organisation before listing it, and the payment tier reflects size and turnover, not the quality of its data protection practices. Treat a register entry as one tick in a due diligence pack, not as assurance.
Sources
This page summarises the following primary sources. Where they disagree with this summary, they take precedence.
- ICO — Search the register (official register of fee payers search)
- ICO — Register of fee payers and certificate downloads
- ICO — Using the search (wildcards and the 100-record limit)
- ICO — Guide to the data protection fee: information we will collect and publish
- ICO — Guide to the data protection fee (tiers, tier 3 default assumption, £5 direct debit discount)
- ICO — Exemptions from the data protection fee
- ICO — Register and pay the fee (publication on the register within seven working days)
- ICO — Fixed penalties for failure to pay the data protection charge (section 158 DPA 2018 document)
- ICO — Penalty notices issued for non-payment of the data protection fee
- ICO — Download the register of fee payers (bulk dataset)
- Data Protection Act 2018, section 149 — enforcement notices, including the fourth type of failure at s.149(5)
- The Data Protection (Charges and Information) (Amendment) Regulations 2025 (SI 2025/63) — fees of £52, £78 and £3,763 from 17 February 2025
- Data (Use and Access) Act 2025, section 117 — the Information Commission (in force 20 August 2025 by SI 2025/904, except s.117(4)(a))
- Data (Use and Access) Act 2025, section 119 — transfer of functions to the Information Commission (not in force)
- GOV.UK — Seven non-executive members appointed to Information Commission board, 15 July 2026
Related guidance
-
Do I need to register with the ICO, and how much is the data protection fee in 2026?
Do you need to register with the ICO? The 2026 data protection fee is £52, £78 or £3,763 — unchanged since February 2025. Who pays, who's exempt.
-
Is this ICO data protection fee letter genuine — and what happens if you haven't paid?
The ICO data protection fee is real: £52, £78 or £3,763 a year. Here is how to spot a fake letter or a paid middleman, and what happens if you have not paid.