GDPR for Therapists: What You Actually Need to Know
GDPR sounds intimidating. For most newly qualifying therapists, it sits on the to-do list alongside ICO registration and Privacy Notices — things you know you need to sort, but aren't quite sure where to start.
The good news: the requirements for a solo therapy practice are manageable. You don't need a lawyer, and you don't need to spend hours reading legislation. You need to understand a handful of concepts, put a few things in place, and keep them updated as your practice grows.
This page covers everything you need to know.
You're a data controller. Here's what that means.
The moment you store a client's name, email address, or any information about their mental health, you become a data controller under UK GDPR. That's true whether you keep paper notes in a locked drawer or use dedicated practice management software.
Being a data controller means you're responsible for:
Collecting only the data you genuinely need
Storing it securely
Being transparent with clients about what you hold and why
Keeping it only for as long as necessary
Responding if a client asks to see, correct, or delete their records
None of this is as onerous as it sounds. For most solo practitioners, it comes down to a few practical steps.
What you need to have in place
ICO registration If you process personal data electronically — which includes keeping client notes on your laptop, using an online booking system, or having a contact form on your website — you must register with the Information Commissioner's Office. Registration costs £52 per year (£47 by direct debit) and takes around 20 minutes at ico.org.uk. Not registering carries fines starting at £400, so this is one to do early.
A Privacy Notice A Privacy Notice tells your clients what data you collect, why you collect it, how long you keep it, and what their rights are. It's a legal requirement under UK GDPR and should be:
Available on your website (typically in the footer)
Sent to or shared with new clients before their first session
Written in plain English — not copied from a legal template full of jargon
See the section below for exactly what your Privacy Notice needs to include.
Secure storage "Secure" doesn't mean you need specialist software, but it does mean taking reasonable steps. In practice this means:
Password-protecting any device that holds client information
Using encrypted note-taking or practice management software rather than plain text files
Not communicating sensitive client information over WhatsApp or standard SMS
Keeping physical notes in a locked cabinet if you use paper records
A data retention policy You need to know how long you're keeping client records and why. The standard guidance for therapy records is seven years after the end of work with an adult client, or until a minor client reaches age 25 or 26. Write this down — even a simple internal document stating your policy is sufficient.
A process for Subject Access Requests Clients have the right to ask for a copy of the personal data you hold about them. You have one month to respond. It's worth knowing in advance how you'd handle this — which records you hold, where they're stored, and what format you'd provide them in.
What your Privacy Notice must include
This is the section most therapists find hardest to write from scratch. Your Privacy Notice must cover:
Who you are — your name, business name, and contact details
What data you collect — name, contact details, presenting issues, session notes, any relevant medical or background information
Why you collect it — to provide therapy, to fulfil your duty of care, to meet professional body requirements
The lawful basis — for therapy records this is typically legitimate interests; for any special category data (health information) you should also reference substantial public interest or explicit consent
How long you keep it — your retention periods for different types of record
Who you share it with — your clinical supervisor (by name or role), your GP or emergency services in risk situations, no one else without consent
Client rights — the right to access their data, correct inaccuracies, and in some circumstances request deletion
How to complain — clients can raise concerns with you directly, or escalate to the ICO at ico.org.uk
A note on supervision
Many therapists worry that discussing client material with their supervisor breaches GDPR. It doesn't. Sharing anonymised case material in supervision is considered part of legitimate professional practice and falls under legitimate interests as a lawful basis. Your Privacy Notice should mention that you work with a clinical supervisor and that this may involve discussing case material in general terms.
Common questions
Do I need client consent to keep clinical notes? No. Consent is actually one of the harder lawful bases to rely on for therapy records, because it can be withdrawn. Most practitioners use legitimate interests or substantial public interest instead. What you do need is a clear Privacy Notice explaining what you keep and why.
Can I use WhatsApp to communicate with clients? Strictly speaking, WhatsApp does not meet the data security requirements for communicating sensitive health information. In practice, many therapists use it for admin messages like appointment reminders. If you do, keep it to non-clinical content and note your approach in your Privacy Notice.
What if a client asks me to delete their records? The right to erasure isn't absolute. For clinical records, you have a legitimate reason to retain notes for the standard retention period even if a client requests deletion — particularly where there may be future safeguarding or legal considerations. You should acknowledge the request, explain why you're retaining the records, and document your decision.
Do I need a cookie banner on my website? Yes, if your website uses any analytics tools (including Google Analytics), advertising pixels, or third-party embeds. A cookie consent banner is required under UK PECR regulations. Most website platforms make this straightforward to add.
Do I need a Data Processing Agreement with my website provider? If your website host or any software you use processes personal data on your behalf — which includes most booking systems, contact forms, and email marketing tools — you should have a Data Processing Agreement in place. Reputable providers will have a standard DPA available on request or in their terms of service.
Getting this right from day one
Setting up your GDPR compliance properly at the start of your practice saves a lot of time and anxiety later. The core requirements — ICO registration, a well-written Privacy Notice, secure storage, and a clear retention policy — are all achievable without specialist legal help.
If you'd rather not spend the time working through it yourself, this is one of the things Clay Consulting handles as part of practice setup. We'll make sure your Privacy Notice is in place, your ICO registration is done, and your data handling is set up correctly before you see your first client.