Running a practice
Do physiotherapists need to register with the ICO?
Almost certainly yes, it costs £52 a year, and it takes about fifteen minutes. Here is how to work out your fee tier and what happens if you skip it.
By Stephen Thomas · · 5 min read

Short answer: almost certainly yes, it costs £52 a year for a practice your size, and doing it takes about fifteen minutes.
It is one of those obligations that is trivially easy to meet and mildly embarrassing to have missed, which is a bad combination, because the people most likely to have missed it are exactly the ones who would be most mortified to be asked.
Plain-English summary, not legal advice. The ICO's own guidance is linked throughout and is genuinely readable.
Why you almost certainly need to
Under the Data Protection (Charges and Information) Regulations 2018, most organisations that process personal data must pay an annual data protection fee to the Information Commissioner's Office.
There are exemptions, but the one people hope applies ("I'm just a sole trader") is not among them. Being small does not exempt you; it puts you in the cheapest tier. And the exemption for purely personal or household activity obviously does not cover treating members of the public for money.
More to the point: as a physiotherapist you process special category data (health information), which is the most sensitive class the legislation defines. If there were a category of processing the ICO would expect to see registered, it is yours.
If you want to check rather than take my word for it, the ICO has a self-assessment tool that takes a couple of minutes.
What it costs
Three tiers, set by government rather than by the ICO:
| Tier | Who it covers | Annual fee | By Direct Debit |
|---|---|---|---|
| Tier 1: micro | Up to 10 staff or turnover up to £632,000 | £52 | £47 |
| Tier 2: SME | Up to 250 staff or turnover up to £36m | £78 | £73 |
| Tier 3: large | Everyone above that | £3,763 | £3,758 |
Note the or. A one-person practice turning over £45,000 is comfortably Tier 1. So is a three-physio clinic. Essentially every independent physiotherapy practice in the country is Tier 1, at £52 a year, or £47 if you set up a direct debit, which also removes the risk of forgetting to renew.
For context, that is under a pound a week, and roughly a third of the cost of one appointment.
What happens if you do not
The ICO can issue a fixed monetary penalty for non-payment. They do chase it, and they publish enforcement action.
But the fine is not really the risk. The risk is what non-registration signals if something else goes wrong. If you ever have a data breach to report, or a patient complaint that reaches the ICO, or an insurer's due-diligence questionnaire, "not registered" is the first thing found and it colours everything after it. It reframes an accident as a pattern of not taking data protection seriously.
Registration is cheap insurance against that inference, quite apart from being the law.
How to do it
- Go to the ICO registration page.
- Work through the self-assessment (a few minutes).
- Provide your organisation details, a contact, and the tier you fall into.
- Pay. Choose direct debit: £5 cheaper and it renews itself.
- Keep the registration number. Put it on your privacy notice and your website footer.
You will get a registration number and an entry in the public register. That entry is itself useful: it is something you can point a patient or an insurer at.
While you are in there: the things that actually matter
Paying the fee is the easy part and, on its own, does nothing to protect anybody. The obligations that follow are the substance:
Have a privacy notice for your patients. What you collect, why, your lawful basis, how long you keep it, who you share it with, and their rights. It needs to be available to patients: a page on your website and a mention at intake is the normal arrangement.
Know your lawful bases. For clinical records, the usual pairing is Article 6(1)(f) legitimate interests or 6(1)(b) contract, combined with Article 9(2)(h), provision of health or social care, for the special category data. Consent is generally not the right basis for clinical records, which surprises people. If care depends on the record, consent that could be withdrawn at any moment is the wrong mechanism.
Know your processors. Your practice software, your email provider, your accountant. Each is processing patient data on your behalf and you should have a data processing agreement with each. Your software supplier should publish theirs; if they will not tell you who their sub-processors are, that is informative.
Have a breach plan. Reportable breaches must reach the ICO within 72 hours of you becoming aware. That is not long to work out who to call. Knowing in advance what you would do is most of the work.
Handle Subject Access Requests. A patient can ask for a copy of everything you hold, and you have one month. In practice this means being able to produce a complete record for one patient without a day of copy-and-paste, which is a software question as much as a process one.
Where Movari fits, briefly
Movari is your processor; you remain the controller. That split is written into our Data Processing Agreement, which is published rather than available on request, along with the full list of sub-processors and where each one operates.
The Subject Access Request problem is handled by a per-patient export that produces the complete record plus every uploaded document as a single download. And the eight-year retention duty stays with you, which is why you can export everything at any time without asking us.
None of that removes your registration obligation. Nothing can: it attaches to you, not to your software.
Sources: ICO data protection fee · ICO self-assessment. Fees quoted as at July 2026; check the ICO before paying, because they are revised.
This is all handled for you on Movari.
Request early access