UK data protection guidance
UK data protection law changed substantially in 2026. These pages answer the questions organisations and individuals are asking most, and say plainly what has changed and what has not.
This is an independent reference site. It is not operated by the Information Commissioner's Office. For formal guidance, always check ico.org.uk.
Registration and fees
-
Do I need to register with the ICO, and how much is the data protection fee in 2026?
Do you need to register with the ICO? The 2026 data protection fee is £52, £78 or £3,763 — unchanged since February 2025. Who pays, who's exempt.
-
How to check whether a company is registered with the ICO
Search the ICO register of fee payers for free, find an organisation's registration reference, and download your own ICO certificate for a tender or PQQ.
-
Is this ICO data protection fee letter genuine — and what happens if you haven't paid?
The ICO data protection fee is real: £52, £78 or £3,763 a year. Here is how to spot a fake letter or a paid middleman, and what happens if you have not paid.
What changed in 2026
-
New rule from 19 June 2026: every UK organisation must have a data protection complaints process
From 19 June 2026 every UK controller must accept data protection complaints, acknowledge them within 30 days and give an outcome. No size exemption.
-
Do I still need a cookie banner in 2026? What actually changed for analytics
From 5 February 2026 some analytics and appearance cookies are exempt from UK consent rules — but only on conditions. What your website must do now.
-
Marketing emails, texts and calls: the maximum fine is now £17.5m
From 5 February 2026 the maximum PECR fine rose from £500,000 to £17.5m or 4% of worldwide turnover. What changed for marketing emails, texts and calls.
-
What is a 'recognised legitimate interest' — and should we switch our lawful basis to it?
Recognised legitimate interest became the UK GDPR's seventh lawful basis on 5 February 2026. The five conditions, the necessity test, and when to switch.
-
Is the ICO still the ICO? What the Information Commission means for you
The ICO has not yet been replaced by the Information Commission. What's in force on 31 July 2026, who is in charge, and whether to rewrite your privacy notice.
-
Can you use AI to screen job applicants or decide about customers? The rules changed in February 2026
UK GDPR Article 22 was replaced by Articles 22A-22D on 5 February 2026. What employers, lenders and insurers must now do when AI makes decisions.
Running a compliant organisation
-
How long do we have to answer a subject access request in 2026?
The UK subject access deadline is still one month. New UK GDPR Article 12A, in force 5 February 2026, lets you pause it for Article 15 requests only.
-
Does my business need a Data Protection Officer?
A DPO is mandatory in only three situations. The DUAA 2025 did not replace DPOs with 'Senior Responsible Individuals' — that proposal died back in May 2024.
-
We've had a data breach — do we have to tell the ICO within 72 hours, and do we have to tell customers?
You must tell the ICO within 72 hours only if a breach is likely to risk people's rights. Telling customers needs high risk. What changed in 2025-26.
Your rights
-
How to ask a company for all the data it holds on you — and what to do if they ignore or redact it
How to make a subject access request under Article 15 UK GDPR, what an organisation may redact, the new stop-the-clock rule, and how to complain in 2026.
-
My data was leaked — can I actually claim compensation, and how much?
Being in a data breach does not automatically mean compensation. What Article 82 requires, what Farley v Paymaster decided, and what payouts really look like.