Starting a practice
GDPR for Therapists: A Guide to Client Records and Data Protection
A practical guide to UK GDPR for therapists: whether you need to register with the ICO, what counts as special category data, how long to keep records, and what to do if something goes wrong.
On this page14 sections
Client notes are some of the most sensitive personal data a small business handles anywhere in the UK, and a private therapy practice is a small business whether or not it feels like one. GDPR isn't optional paperwork you get to once the diary is full. It's the legal framework for how you collect, store, use and eventually delete everything a client tells you.
This guide covers GDPR for therapists working in private practice in the UK: whether you need to register with the ICO, what makes therapy notes "special category data," how long to keep records, how to store them securely, what client rights actually mean in practice, and what to do if something goes wrong. It expands on the data protection step in our guide to setting up a private therapy practice.
Important: This is a practical overview, not legal, tax, regulatory or professional advice. Data protection law applies to your specific circumstances, and this article can't account for every variation. Check current ICO guidance and your professional body's position, and get independent advice if you're unsure.
What GDPR for therapists actually covers
GDPR applies to everyone processing personal data in the UK, but a therapy practice has two features that raise the stakes: the records are unusually sensitive, and clients are trusting you with them at a vulnerable moment. The sections below work through the practical decisions this creates, from registration to retention to what happens if something goes wrong.
Do you need to register with the ICO?
Most UK organisations that process personal data as a "controller" (the term for whoever decides why and how data is used) need to pay the ICO's annual data protection fee. The exemptions are narrow and specific: they cover things like staff administration, advertising and marketing for your own business, and basic accounts and records, according to the ICO's own list of exemptions. Processing client contact details, session notes, assessments or referral information to actually deliver therapy isn't one of the listed exemptions, so most private practitioners need to register.
The fee has three tiers based on turnover and staff numbers, set out by the ICO:
| Tier | Who it applies to | Fee |
|---|---|---|
| Tier 1 | Turnover up to £632,000 or no more than 10 staff | £52 (£47 by Direct Debit) |
| Tier 2 | Turnover up to £36 million or no more than 250 staff | £78 (£73 by Direct Debit) |
| Tier 3 | Anyone who doesn't meet Tier 1 or 2 | £3,763 (£3,758 by Direct Debit) |
A sole practitioner or small practice will almost always land in Tier 1. Registration itself doesn't change what you're required to do under GDPR; it's a separate legal requirement to pay a fee and appear on the public register. The ICO publishes a short online self-assessment if you want to check your own position rather than rely on a general guide like this one.
What makes therapy notes "special category data"
Under UK GDPR, certain categories of personal data get extra protection because of the harm that could follow if they were mishandled. Health data is one of them, and the ICO's guidance on special category data is clear that this includes anything revealing a person's physical or mental health. Session notes, assessments, risk information and referral letters all sit inside that definition.
To process special category data lawfully, you need two things at once, not one:
- An ordinary lawful basis under Article 6 (for most therapists in private practice, this is client consent).
- A separate condition for processing special category data under Article 9. Most therapists rely on explicit consent here too, or on the condition covering the provision of health or social care.
In practice, this mostly changes how carefully you should document consent and how you talk to clients about what you record and why, more than it changes your day-to-day note-taking.
Choosing a lawful basis for client data
Before you collect any client data, you should be able to say, clearly, why you're allowed to hold it. For most private practitioners the honest answer is consent: the client has agreed to therapy and understands, in plain terms, what information you'll keep and why. Consent needs to be a genuine, informed choice, not something buried in a contract the client never reads.
Some information falls outside consent. Basic accounting records (invoices, payment history) are usually processed under a separate lawful basis tied to your legal obligation to keep financial records, not client consent to therapy. It's worth being clear in your own mind which lawful basis applies to which kind of data you hold, rather than treating "client agreed to therapy" as a blanket justification for everything in your systems.
How long should you keep client records?
This is the question therapists ask most often, and the honest answer is that there's no single fixed number in UK law. GDPR's storage limitation principle simply requires that you don't keep personal data for longer than you need it for the purpose you collected it. BACP has written that there's no simple answer to how long notes should be kept, but points out that because its own complaints procedure gives a client up to three years after therapy ends to raise a complaint, many practitioners use three years as a practical minimum.
A few things are worth building into your own policy:
- Write your retention period down, even if it's a minimum rather than a hard rule, and tell clients what it is before therapy starts.
- Check your professional body and insurer, since guidance varies and some recommend longer retention where a client was under 18 during treatment, given the extra time they may have to raise a claim after reaching adulthood.
- Review, don't just accumulate. A retention period only works if you actually act on it, rather than keeping every record indefinitely because deleting anything feels risky.
If you're deciding on the structure for your practice's finances and record-keeping obligations more broadly, our guide to sole trader versus limited company for therapists covers the separate (and usually longer) retention rules that apply to business and tax records.
Storing records securely: notes, email, booking systems and cloud tools
GDPR doesn't mandate a specific piece of software, but it does require "appropriate technical and organisational measures" to keep personal data secure. In practice, for a small therapy practice, that usually means:
- Encrypted or password-protected storage for notes, whether that's a dedicated practice management tool or an encrypted folder, not a plain document on a shared family computer.
- A secure, professional email address, ideally one that supports encryption at rest, rather than routing sensitive client correspondence through a personal inbox shared with other accounts.
- Checking your booking and payment tools, since a contact form, calendar or payment system on your website is also processing personal data on your behalf, and you're responsible for it being handled appropriately.
- Access control, so that if you work with a VA, bookkeeper or colleague, they only see the client information they genuinely need.
Our guide to website maintenance for therapists covers the practical side of this, including backups and keeping the software behind your booking forms and contact pages up to date, which is itself part of keeping data secure.
Client rights: access, correction and erasure
Clients have a set of rights over their own data under UK GDPR, and it's worth knowing the shape of them even if requests are rare in a small practice:
- The right to access their own data (a "subject access request"), which you generally have one month to respond to.
- The right to correction if information you hold about them is inaccurate.
- The right to erasure, sometimes called the right to be forgotten. The ICO is explicit that this right is not absolute: it applies in specific circumstances, and you can refuse in others, for example where you have a genuine legal or professional reason to keep a record, such as being able to respond to a future complaint.
If a client asks about their records, treat it as a genuine request rather than an inconvenience, but you don't have to delete everything on demand. Explain, calmly and in writing, what you can and can't do and why.
A newer duty: handling complaints yourself
This is the part of GDPR for therapists that's changed most recently, so it's worth its own section rather than a line in a general checklist. Since 19 June 2026, the Data (Use and Access) Act 2025 has put a new statutory duty on every organisation that processes personal data, and the ICO has confirmed the new legal duty applies to all organisations handling personal data, regardless of size. In practice, you now need to:
- Give clients a way to complain to you directly about how you've handled their data, not just point them to the ICO. An email address is enough; you don't need a dedicated portal.
- Acknowledge a complaint quickly and respond within 30 days, explaining what you found and what you did about it.
- Tell clients they can complain to you, as well as to the ICO. The ICO's guidance is specific that this needs to happen at the point you collect their information, which for most therapists means it belongs in your privacy policy, not just somewhere you'd mention it if asked.
The ICO's own step-by-step guide for small organisations is worth reading in full if you don't already have a complaints process; it's short and written for exactly this size of business, not a large employer with a dedicated compliance team.
If your privacy policy still only mentions the right to complain to the ICO, that's now out of date. UpTopWeb has already added this clause to every customer's privacy policy as part of keeping them current, which is one of the things that separates a website that's actually maintained from one that was simply built once and left alone.
What to do if you have a data breach
A data breach isn't only a hack. Losing an unencrypted laptop, sending a client's notes to the wrong email address, or a booking system being compromised all count. The ICO's guidance on personal data breaches sets out the core rule: if a breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO within 72 hours of becoming aware of it, and tell the affected individuals without undue delay if the risk is high. Not every incident meets that bar, but you should still record it internally either way.
Having a rough plan before anything happens helps: know where your data lives, know who to contact, and don't wait to fully understand the incident before starting the 72-hour clock.
GDPR on your therapist website
Your website is also processing personal data the moment it has a contact form, a booking widget, an email newsletter sign-up or analytics running in the background. That means it needs a clear, accurate privacy policy explaining what you collect and why. Our guide to what a therapist website should include covers this alongside the other pages and trust signals a therapist site needs.
Cookie banners and cookie consent
If your website sets anything beyond strictly necessary cookies (analytics, embedded video, marketing pixels or a chat widget, for example), this isn't governed by UK GDPR alone. The Privacy and Electronic Communications Regulations (PECR) require you to get consent before those cookies are set, not just disclose them somewhere on the site. The ICO is specific that consent must be a genuine, unambiguous positive action (more than simply continuing to browse), that you cannot set non-essential cookies before that consent is given, and that people need a way to decline non-essential cookies that's genuinely as easy as accepting them.
The ICO published finalised guidance on cookies and similar technologies in April 2026, and has been actively auditing UK websites' cookie banners against exactly this point: a prominent "Accept" button next to a small, easy-to-miss link to "manage settings" isn't treated as a genuine choice. In practice, a compliant banner should:
- Explain in plain language what you use cookies for (for example, "to understand how visitors use this site" for analytics), not just that "this site uses cookies"
- Offer "Accept" and "Reject" as equally easy, equally visible choices on the first screen, not one button plus a buried settings link
- Not set analytics, marketing or embed cookies until the visitor has actively consented
- Link through to a fuller cookie policy for anyone who wants the detail, without making that the only way to actually decline
Strictly necessary cookies, the ones a site genuinely can't function without (remembering the visitor's cookie choice itself, or session security), don't need consent, but your cookie policy should still explain what they are.
Cookies are only one part of what makes a website itself GDPR compliant; see our GDPR compliant website checklist for therapists for the contact form, third-party embed and data storage checks that sit alongside this.
GDPR checklist for private practice
- Registered with the ICO and paying the correct fee tier (or confirmed you're genuinely exempt)
- Clear, written record of your lawful basis for processing client data
- A retention period decided, written down and told to clients
- Notes and client communication stored securely, not on shared personal accounts
- A process for responding to access, correction or erasure requests
- A way for clients to complain to you directly, acknowledged and answered within 30 days
- A basic breach response plan, even a simple one
- An accurate privacy policy that explains how to complain to you as well as to the ICO
- A cookie banner that makes rejecting non-essential cookies as easy as accepting them
Start with the basics, then build the rest
You don't need a compliance department to handle this well. Register if you need to, be honest with yourself about how long you're actually keeping records and why, store client data somewhere secure, and be ready to explain your approach if a client or the ICO ever asks. Most of GDPR, for a small therapy practice, comes down to being able to answer a simple question clearly: what do you hold, why, and for how long.
Frequently asked questions
Do therapists need to register with the ICO and pay the data protection fee?
Almost always, yes. The ICO's fee exemptions cover a short list of specific purposes (staff administration, advertising and marketing for your own business, basic accounts and records, and a few others), and processing client contact details, session notes or assessments to deliver therapy isn't on that list. Most sole-practice therapists fall into Tier 1, currently £52 a year (£47 by Direct Debit). Use the ICO's own self-assessment tool to check your specific situation rather than assuming either way.
Do therapists need their own data protection complaints process?
Yes, since 19 June 2026. The Data (Use and Access) Act 2025 introduced a statutory duty on every organisation that processes personal data, requiring you to give clients a way to complain to you directly, acknowledge and respond within 30 days, and tell them in your privacy policy that they can complain to you as well as to the ICO. If your privacy policy still only mentions the ICO, it needs updating.
How long should therapists keep client records under UK GDPR?
There's no single legally mandated period. UK GDPR's storage limitation principle just says you shouldn't keep personal data longer than necessary for the purpose you collected it. BACP has said there's no simple answer, but notes that because its own complaints process gives a client up to three years after the work ends to raise a complaint, many practitioners treat three years as a practical minimum. Check whether your professional body, insurer or supervisor recommends a specific period, and put your own retention policy in writing.
Can a client ask a therapist to delete their records?
They can ask, but the right to erasure isn't absolute. It applies in specific circumstances, for example where the data is no longer necessary for the purpose it was collected for, or consent has been withdrawn and there's no other lawful basis. It doesn't override a genuine legal or professional reason you have for keeping a record, such as defending against a future complaint. You have one month to respond to a request either way.
What counts as special category data in therapy notes?
Health data is special category data under UK GDPR, and therapy notes, assessments and anything revealing a client's mental health are squarely inside that definition. To process it lawfully you need both an ordinary lawful basis under Article 6 (most therapists rely on consent) and a separate condition under Article 9, most commonly explicit consent or the health and social care condition. This needs more care than processing an ordinary enquiry form.
Do therapist websites need a cookie consent banner?
Yes, if the site sets anything beyond strictly necessary cookies, for example analytics, embedded video or marketing pixels. Under PECR, consent must be a genuine positive action, non-essential cookies can't be set before that consent is given, and visitors need a way to decline that's as easy as accepting. The ICO has been actively checking UK websites against this, and a banner with a prominent Accept button next to a small, easy-to-miss settings link isn't treated as a real choice.
A therapist website built with data protection in mind
UpTopWeb builds calm, professional websites for therapists with a proper privacy policy, secure forms and hosting handled for you, so this is one less thing to worry about.
Get a free website