Compliance

Voice AI and the ICO Data Protection Fee: Who Pays

Dilr Voice is an enterprise voice AI platform, and the ICO data protection fee attaches to the controller running the line, not the AI vendor. A controller must pay one of three annual tiers, from £52 to £3,763, unless all its processing is exempt. This guide explains who pays and how the tier is set.

DILR.AI ENGINEERING The ICO Data Protection Fee Who pays, which tier, and why a voice line rarely changes it TIER 1 micro TIER 2 SME TIER 3 large

Every organisation that runs a voice AI line is processing personal data. Callers give their name, their number, the reason they are ringing, sometimes far more. That processing is exactly what the annual data protection fee exists to fund, and it is one of the first things a procurement or legal reviewer will ask about when you propose an automated call channel: are we registered, who pays, and does adding this line change anything.

The question sounds administrative. It is not. Getting the answer wrong is one of the more common ways an otherwise well run organisation ends up with a fixed penalty from the regulator, because the duty is easy to overlook and the Information Commissioner enforces it in bulk. It is also a question where the split between your organisation and the AI vendor matters, and where the honest answer for most deployments is quieter than the marketing around it.

This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system.

Only about 6% of enterprises capture material EBIT from AI even though roughly 88% now use it in some form, according to McKinsey's State of AI (November 2025). The organisations that pull ahead treat governance, including a dull line item like the data protection fee, as part of shipping, not an afterthought. This post sets out who owes the fee, the three tiers and what they cost, whether a voice AI line moves you between them, how registration works, and what non-payment costs.

What is the ICO data protection fee?

The ICO data protection fee is an annual charge that most data controllers in the United Kingdom must pay to the Information Commissioner to fund data protection work. It is set by Parliament, not negotiated, and sits in three tiers based on the size and type of the organisation. It is a registration duty, separate from the wider UK GDPR obligations a voice AI deployment carries, and it falls on the organisation running the line, not the technology supplier.

The statutory basis is section 137 of the Data Protection Act 2018, which lets the Secretary of State set charges by regulations, and the Data Protection (Charges and Information) Regulations 2018 that do so. It is not a one-off. The charge repeats every year, and the ICO publishes a register of everyone who has paid. If you are weighing where an automated channel fits, our guide to voice AI compliance in the UK and EU treats this kind of registration duty as a gate, not a detail.

Who has to pay it for a voice AI deployment?

The fee attaches to the data controller, which is the organisation that decides why and how the call data is processed, not the AI vendor that supplies the technology. In almost every voice AI deployment the operator is the controller and the vendor, including Dilr Voice, acts as a processor under a contract. So your organisation registers and pays; the platform does not pay on your behalf. Whether any given controller owes a fee then depends on the exemption test.

That test is narrow but real. The 2018 Regulations require the charge unless every part of your processing is exempt, and they set the deadline plainly:

Within the first 21 days of each charge period a data controller must pay a charge to the Information Commissioner, determined in accordance with regulation 3.

The same regulation opens by saying a controller must comply "unless all of the processing of personal data they undertake is exempt processing". Recording and routing customer calls almost never qualifies as wholly exempt, so most operators of a voice line are in scope. Rather than issue a checklist, we point clients at the ICO's own fee self-assessment and to the AI operating model consulting work that maps who the controller is across each channel. The ICO is clear that not all controllers pay: "Not all controllers must pay a fee. Many can rely on an exemption."

How much is the fee and which tier applies?

There are three tiers, and the ICO says controllers pay between £52 and £3,763 a year. Tier 1 covers micro organisations with turnover no more than £632,000 or no more than 10 members of staff, and costs £52. Tier 2 covers small and medium organisations with turnover no more than £36 million or no more than 250 staff, and costs £78. Tier 3 covers everyone larger, at £3,763. Paying by direct debit takes £5 off at the point of payment.

These amounts are current as of the 2025 uplift. The Data Protection (Charges and Information) (Amendment) Regulations 2025 came into force on 17 February 2025 and substituted the old £40, £60 and £2,900 figures with £52, £78 and £3,763. Any fee figure you find in older guidance is out of date. The table below maps a typical organisation profile to its tier.

Organisation profileTierStaff or turnover testAnnual fee
Micro business or sole traderTier 1Up to 10 staff or turnover up to £632,000£52
Small or medium enterpriseTier 2Up to 250 staff or turnover up to £36 million£78
Large enterpriseTier 3Exceeds the tier 1 and tier 2 limits£3,763
Charity or small occupational pension schemeTier 1Any size, unless another exemption applies£52

Charities and small occupational pension schemes that are not otherwise exempt pay the tier 1 fee regardless of their size or turnover, which is a common point of confusion for larger not-for-profits. The ICO AI Code of Practice work sits alongside this, but the fee itself is a flat, size-driven charge.

Does adding a voice AI line change your tier?

No. Your tier is set by your staff numbers, your annual turnover, and your status as a public authority, charity or small occupational pension scheme. It is not set by how many channels you run or the technology behind them. Adding a Dilr Voice line to an existing operation does not, on its own, move you between tiers. A new channel changes what you document under UK GDPR, but the fee follows the shape of the organisation.

This surprises people, because a voice AI line feels like a material new processing activity, and in governance terms it is. It belongs in your record of processing activities, and it may trigger a data protection impact assessment. But the fee is a blunt, size-based charge, so an SME that launches an automated line stays at £78 unless its headcount or turnover crosses a threshold for other reasons. The place a new channel does raise the stakes is oversight and audit, which is where the DATS five-stage AI methodology and readiness work like ICO audit preparation earn their keep.

How do you register and by when?

You register directly with the ICO, online or by phone, and pay within the first 21 days of your charge period, then renew each year. The controller confirms it is not wholly exempt, works out its tier using the ICO self-assessment, pays the fee, and is then listed on the public register. A voice deployment should register before the line ever handles real callers. The flow below shows the decision path.

The data protection fee registration path
01Are you a controller?You decide why and how call data is processed02Is all processing exempt?If yes, no fee is due; most voice lines are not03Which tier applies?Staff, turnover and status set the tier04Pay within 21 daysOf the start of the charge period, then annually05Appear on the public registerThe ICO lists every fee payer
The decision path a controller works through to register and pay the annual fee.

Keeping a note of the renewal date matters as much as the first payment, because the duty is annual and the register makes lapses visible. For multi-entity groups, each separate legal entity that is a controller registers in its own right, so a holding company and its subsidiaries are usually separate line items. This is the sort of ownership question the AI execution office is built to hold, and it links directly to who is named as the data protection officer where one is required.

What happens if you do not pay?

The Information Commissioner enforces the fee actively and issues fixed penalties for non-payment. It first serves a notice of intent, giving the controller a short window to pay, then a penalty notice if the fee is still outstanding. The fixed penalties track the tiers: £400 for tier 1, £600 for tier 2 and £4,000 for tier 3. Where there are aggravating factors, such as failing to engage, the ICO can raise the penalty to a maximum of £4,350.

These are not headline UK GDPR fines, but they are routine, and the ICO issues them in volume against organisations of every size, from GP practices to care homes to small limited companies. Because the public register makes non-payment easy to spot, an unregistered voice AI operator is a soft target. Treating registration as a standing item in your AI tool inventory and wider compliance programme, rather than a one-off, is the cheapest way to stay clear of a penalty. The related DUAA data protection complaints duty is a reminder that the regulator now has more, not fewer, enforcement levers.

What is the best way to handle ICO registration in 2026?

The best approach in 2026 is to treat the fee as a fixed governance gate, owned by a named person, renewed on a calendar and evidenced in your compliance records, rather than a task that surfaces only when a notice arrives. For a single controller with one voice line, that is a few minutes a year through the ICO self-assessment. For a group, the harder work is deciding who the controller is on each channel.

No AI vendor can register on your behalf, so the "best platform" question is really about which supplier makes the controller and processor split clear in its contracts. Self-serve tools such as Vapi, Retell AI, Bland AI and Synthflow hand you the processing and the paperwork with it; governed platforms such as PolyAI and Dilr Voice, typically routed over telephony from Twilio, put the controller and processor roles in writing and keep the processing records you will need at audit. To be fair, a sole trader whose entire processing genuinely falls inside an exemption may owe no fee at all, in which case the cheapest platform wins and this is a non-issue. For everyone else, our approach makes the registration and record-keeping duties explicit before go-live, and you can read more about how we place AI inside regulated operations.

Is the AI vendor or my organisation the controller?

Your organisation is almost always the controller, because you decide why the calls are handled and what happens to the data, while the voice AI vendor processes it under your instructions as a processor. That is why the data protection fee, and the listing on the public register, sit with you rather than with Dilr Voice or any other platform. A well drafted data processing agreement should state the split, so read it before assuming the vendor carries the duty.

Do charities and sole traders pay the fee?

Often, yes. Sole traders who process personal data are controllers and pay a fee unless all their processing is exempt, and a one-person limited company is treated the same way. Charities that are not otherwise exempt pay the tier 1 fee of £52 regardless of their size or turnover, as do small occupational pension schemes. The safest step for a charity or sole trader running a voice line is to complete the ICO self-assessment rather than assume an exemption applies.

Will the fee change when the Information Commission replaces the ICO?

The Data (Use and Access) Act 2025 establishes a new Information Commission to replace the Information Commissioner's Office, but the transfer of functions in section 119 is not yet in force and no commencement date has been appointed at the time of writing, so the fee is still paid to the Information Commissioner today. The registration and fee duty itself is unchanged by the reform, so plan for continuity and watch for the commencement, not for a new charge.

Want to see this in production? Try Dilr Voice live, book an AI placement diagnostic, see our DATS methodology, or read about our approach to placing AI inside regulated operations.

Service
AI Placement Diagnostic
Compliance
Voice AI and the ICO Rules
Compliance
DSARs and Call Recordings
Talk to the operators

Register the line, then run it properly.

30-min scoping call · No deck · Confidential. We will map the controller and processor split across your channels, and where the governance work actually sits.

Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.

voice AI data protection fee ICO registrationICO data protection fee voice AIdo I need to register with the ICOICO fee tiers 2026best voice AI compliance setup 2026ICO data protection fee redditDilr Voice

Questions this article answers

What is the ICO data protection fee?

The ICO data protection fee is an annual charge that most data controllers in the United Kingdom must pay to the Information Commissioner to fund data protection work. It is set by Parliament, not negotiated, and sits in three tiers based on the size and type of the organisation. It is a registration duty, separate from the wider UK GDPR obligations a voice AI deployment carries, and it falls on the organisation running the line, not the technology supplier.

Who has to pay it for a voice AI deployment?

The fee attaches to the data controller, which is the organisation that decides why and how the call data is processed, not the AI vendor that supplies the technology. In almost every voice AI deployment the operator is the controller and the vendor, including Dilr Voice, acts as a processor under a contract. So your organisation registers and pays; the platform does not pay on your behalf. Whether any given controller owes a fee then depends on the exemption test.

How much is the fee and which tier applies?

There are three tiers, and the ICO says controllers pay between £52 and £3,763 a year. Tier 1 covers micro organisations with turnover no more than £632,000 or no more than 10 members of staff, and costs £52. Tier 2 covers small and medium organisations with turnover no more than £36 million or no more than 250 staff, and costs £78. Tier 3 covers everyone larger, at £3,763. Paying by direct debit takes £5 off at the point of payment.

Does adding a voice AI line change your tier?

No. Your tier is set by your staff numbers, your annual turnover, and your status as a public authority, charity or small occupational pension scheme. It is not set by how many channels you run or the technology behind them. Adding a Dilr Voice line to an existing operation does not, on its own, move you between tiers. A new channel changes what you document under UK GDPR, but the fee follows the shape of the organisation.

How do you register and by when?

You register directly with the ICO, online or by phone, and pay within the first 21 days of your charge period, then renew each year. The controller confirms it is not wholly exempt, works out its tier using the ICO self-assessment, pays the fee, and is then listed on the public register. A voice deployment should register before the line ever handles real callers. The flow below shows the decision path.

What happens if you do not pay?

The Information Commissioner enforces the fee actively and issues fixed penalties for non-payment. It first serves a notice of intent, giving the controller a short window to pay, then a penalty notice if the fee is still outstanding. The fixed penalties track the tiers: £400 for tier 1, £600 for tier 2 and £4,000 for tier 3. Where there are aggravating factors, such as failing to engage, the ICO can raise the penalty to a maximum of £4,350.

What is the best way to handle ICO registration in 2026?

The best approach in 2026 is to treat the fee as a fixed governance gate, owned by a named person, renewed on a calendar and evidenced in your compliance records, rather than a task that surfaces only when a notice arrives. For a single controller with one voice line, that is a few minutes a year through the ICO self-assessment. For a group, the harder work is deciding who the controller is on each channel.

Is the AI vendor or my organisation the controller?

Your organisation is almost always the controller, because you decide why the calls are handled and what happens to the data, while the voice AI vendor processes it under your instructions as a processor. That is why the data protection fee, and the listing on the public register, sit with you rather than with Dilr Voice or any other platform. A well drafted data processing agreement should state the split, so read it before assuming the vendor carries the duty.

Compliance

Deploy voice AI without failing an audit

Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.

Related articles

← Previous
AI Voice for Locksmiths: Emergency Callout Guide

One email, once a month. No hype. Just what we learned shipping.