If your users can store anything they like including personal data whether you intend it or not you will be liable, unless you write it into your contracts appropriately to ensure you are covered in that they are defined as the data controller in data protection terms, and even then you could probably still be considered liable if they saw that you hadn't provided reasonable protections like encryption.
If your system can contain data covered by the DPA you probably will be required to register, I would suggest contacting the ICO who will be able to tell you for sure.



Pages in this thread:
Print Thread
mrrd