GDPR for Therapy Practices: A Plain-English Guide
Last reviewed and published: 16 August 2026. Data protection rules and ICO guidance are updated from time to time, so if you’re reading this some months after the publish date, check the relevant ICO page directly for anything that matters to a decision you’re making. This article is a plain-English summary, not legal advice, and it doesn’t replace checking with your professional or membership body about their own requirements.
GDPR for Therapy Practices: A Plain-English Guide
If you run a therapy practice in the UK, whether that’s counselling, psychotherapy, acupuncture, cosmetic treatments, nursing-based acupuncture, or anything else that involves keeping notes on clients, you’re handling personal data. Some of it, like health information and treatment notes, counts as a special, more sensitive category under the law. This guide pulls together what the Information Commissioner’s Office (ICO), the UK’s data protection regulator, says businesses like yours need to do.
It’s written for practice owners: sole traders working alone and owners of clinics with admin staff, employed therapists, or family and friends helping out. If any of those people can see or handle client information, the rules in this guide apply to your whole practice, not just to you.
We’ve kept this to ICO regulations rather than any single professional body’s rules. Bodies like BACP, UKCP, BPS, HCPC, and your insurer or indemnity provider often have their own record-keeping requirements, and those can be stricter or more specific than GDPR. Always check with them directly for anything they require on top of this.
Do you need to register with the ICO?
Most therapy practices that keep client records on a computer, phone, or any electronic system need to register with the ICO and pay an annual data protection fee. This applies to sole traders as much as limited companies.
The fee has three tiers based on your turnover or staff numbers:
- Tier 1 (micro-organisations, up to £632,000 turnover or 10 staff): £52 a year, or £47 by direct debit. Most solo practitioners and small clinics fall here.
- Tier 2 (up to £36 million turnover or 250 staff): £78 a year.
- Tier 3 (everyone else): £3,763 a year.
“Staff” for this purpose includes employees, workers, and partners, so if you have admin help or other therapists working under your practice, check whether that pushes you toward a different tier. The ICO has a free online self-assessment tool that tells you which tier applies and whether you’re exempt. Running your practice through a limited company doesn’t exempt you. The exemption for companies that only process data for their own accounts doesn’t cover you if you’re also holding client treatment records, which almost every therapy practice is.
Failing to register when you should is a criminal offence, and the ICO does issue fixed penalties for non-payment.
Client notes are “special category data”
Anything that reveals a client’s health, whether that’s a counselling note, an acupuncture treatment record, or details from a cosmetic consultation, falls under what GDPR calls “special category data.” This includes physical and mental health information, so it applies whether you’re a talking therapist, an acupuncturist, a nurse offering aesthetic treatments, or anything in between.
To process this lawfully, you need two separate things:
- 1: A lawful basis under Article 6 of GDPR, most commonly that the processing is necessary for a contract with the client, or for your legitimate interests.
- 2: A specific condition under Article 9, on top of the lawful basis. For most therapy and treatment records, this is the “health or social care” condition.
The ICO specifically advises against relying on consent alone as your basis for ongoing clinical or treatment records. Consent can be withdrawn at any time, which creates problems if you still need the records for your own professional or insurance purposes after a client withdraws it.
If you rely on the health or social care condition, UK law requires you to have an “appropriate policy document” in place. This doesn’t need to be complicated. It’s a short written document explaining what special category data you hold, why, and your approach to retention and security. It’s worth having even if no one ever asks to see it, because it shows you’ve thought this through.
Tell clients what you do with their data
Before you start collecting information from a new client, they need a privacy notice, sometimes called a privacy policy. This should be written in plain language and explain:
- – what personal data you collect and why
- – your lawful basis and Article 9 condition for health-related information
- – how long you keep records
- – who else might see the data (a supervisor, an admin assistant, an insurer if there’s a claim)
- – their rights, including access, correction, and (with some exceptions, covered below) erasure
- – how to contact you with concerns, and that they can complain to the ICO
This can live on your website and be handed to clients before their first session. If a family member or friend helps you with bookings or admin, they need to know this notice applies to how they handle client details too.
Keeping data secure, including with family or admin help
Data minimisation means only collecting what you actually need for treatment, not extra fields “just in case.” Look at your intake forms and cut anything you can’t justify.
If anyone other than you sees client information, whether that’s a paid receptionist, another therapist in your clinic, or a family member helping with scheduling, you’re responsible for how they handle it. Practical steps that matter here:
- password-protect and, where possible, encrypt digital records
- don’t leave paper notes where visitors or other clients could see them
- give access only to people who genuinely need it for their role
- have a plan for what happens to records if you’re unavailable (illness, holiday) so cover arrangements don’t mean handing over full access unnecessarily
- use secure file transfers for sending sensitive data to another party (e.g. Swisstransfer with a password set)
Using AI tools in your practice
If you use any AI tool that touches client information, transcription apps, AI-assisted note-taking, scheduling assistants, or anything that drafts correspondence using client details, a few extra things apply on top of everything above.
You’re the data controller for that processing, and the AI provider is your processor. That means you need a proper data processing agreement with them, not just clicking accept on their terms of service without checking what those terms actually say.
Check where the data goes and whether the provider uses it to train their own models. Many free or general-purpose AI tools use input data for training by default. Typing a client’s session details into one of these could mean repurposing health data beyond what the client agreed to, which breaches the purpose limitation principle and your duty of confidentiality.
The stakes are higher here because it’s the same special category data covered earlier in this guide. If an AI tool is processing what amounts to a clinical note, you need the same Article 9 condition and appropriate policy document to cover that processing, not just your own records.
Your privacy notice should mention it if AI tools are part of your workflow anywhere client data is involved, since clients have a right to know.
It’s worth doing a data protection impact assessment (DPIA) before adopting any AI tool that touches client health data, even informally. The ICO publishes a free AI and data protection risk toolkit for this.
This is a fast-moving area. The ICO has flagged dedicated guidance on agentic AI as part of its 2026/27 work programme, so check ico.org.uk for anything published after this article if AI tools are a significant part of how you work.
How long should you keep records?
This is the area with the most confusing information online, so it’s worth being clear about what the ICO actually requires versus what’s a sector convention.
GDPR itself doesn’t set a fixed number of years.
The relevant rule is the “storage limitation” principle: you keep personal data for only as long as you need it for the purpose you collected it, then delete or anonymise it. The ICO’s own guidance says you must be able to justify why a record is still there. If you can’t say why you need it, you can’t say how long it should stay.
That said, “as long as necessary” isn’t much use on its own, so here’s what shapes a realistic retention period for a therapy practice:
- – Legal claims. Under the Limitation Act 1980, a client generally has 6 years to bring a claim for breach of contract, or 3 years for a personal injury claim (which can include a claim relating to psychological harm), from the point they became aware of it. Many practices keep records for at least this long to be able to defend a claim if one arises.
- – Minors. If you see clients under 18, a common approach is to keep their records until they turn 25 (or 26 if they were 17 at their last session), reflecting the extended time a young person has to bring a claim after reaching adulthood. This mirrors the approach used across UK health records generally, not a GDPR-specific rule.
- – Your professional or membership body. BACP, UKCP, BPS, HCPC, and others often publish their own recommended minimum retention periods, and your insurer may have its own requirement tied to how long you need records to support a claim on your policy. These can be longer than what GDPR strictly requires, and where they are, you should follow them. This is genuinely the point where you need to check with your specific body rather than rely on a general guide, because requirements do differ between them.
- – Reviewing, not just setting and forgetting. The ICO expects you to periodically review what you hold, not just apply one retention period forever and never look at it again. If a small organisation doing low-risk, occasional processing, you may not need a formal written retention policy, but you still have to review and delete data you no longer need.
A sensible approach for most practices: write down your retention period for each type of record (client notes, correspondence, invoices, safeguarding-related records), base it on the longer of your professional body’s recommendation and the legal claim periods above, and review it against your actual client base periodically.
What clients can ask you for
Clients have a right to ask for a copy of their own data. This is called a Subject Access Request (SAR), and it doesn’t have to be made in writing or use any particular wording. If a client says something like “can I see what notes you have on me,” that’s a valid request.
You have one calendar month to respond, starting from the day you receive the request (not the day after). This can be extended by up to three months for requests that are genuinely complex, for example, a very long treatment history or a request involving a lot of sensitive material.
There’s a specific safeguard for health information: if disclosing part of a record would be likely to cause the client (or someone else) serious mental or physical harm, that part can be withheld. This isn’t a general excuse to withhold notes you’d rather not share, and it’s meant to be applied narrowly.
Clients also have a right to erasure (“right to be forgotten”) in certain circumstances, also with a one-month response window. This right isn’t absolute. If you still have a legal reason to keep the data, for example, it’s within your retention period for defending a potential claim, or your professional body requires you to retain it, you can generally refuse the erasure request and should explain why.
If something goes wrong: data breaches
A data breach isn’t just hacking. It includes things like emailing client notes to the wrong address, losing an unencrypted laptop or phone with client records on it, or someone unauthorised gaining access to your files.
If a breach is likely to pose a risk to your clients (financial loss, identity theft, distress, loss of confidentiality), you must report it to the ICO within 72 hours of becoming aware of it. If the risk is high, you must also tell the affected clients directly, without undue delay. The ICO has a self-assessment tool to help you work out whether a given incident needs reporting, and a helpline for small organisations and sole traders working out what to do in the first 72 hours.
Keep a simple log of any incident even if you decide it doesn’t need reporting: what happened, who was affected, and what you did about it. That record matters if the ICO or a client ever asks.
Clients based overseas
If you occasionally see a client who’s a holidaymaker, or you work with a client while they’re abroad, the position on which country’s data protection law applies isn’t automatic and depends on the specifics. If this is a one-off, it’s worth a quick check before you rely on your usual UK GDPR approach. If you regularly see clients based outside the UK, for example, ongoing online sessions with someone living in the EU, get proper advice on this rather than assuming UK GDPR alone covers you, since EU GDPR can apply separately.
Consent forms
Your client consent and intake forms should reflect the points above: what you collect, why, your legal basis, how long you keep it, and who might see it. Beyond that, the right wording for your specific forms is worth getting checked by a data protection professional or your professional body, since a template that works for a solo therapist won’t necessarily fit a multi-therapist clinic with admin staff.
Quick checklist
- Registered with the ICO (or confirmed you’re exempt) and paying the correct fee tier
- Identified your Article 6 lawful basis and Article 9 condition for treatment records
- Have an appropriate policy document if relying on the health or social care condition
- Privacy notice available to clients before their first session
- Written retention periods for each record type, based on legal claim limits and your professional body’s requirements
- A plan for responding to access and erasure requests within one month
- A basic breach response plan, including who to contact and how to log incidents
- Checked overseas-client implications if relevant to your practice
Summary FAQs
Do sole trader therapists need to register with the ICO?
Yes, if you keep client records electronically. Most solo practitioners fall into Tier 1, currently £52 a year, or £47 by direct debit.
Is GDPR different for talking therapies versus acupuncture or cosmetic treatments?
No. Any information revealing a client’s physical or mental health counts as special category data under GDPR, regardless of the type of therapy or treatment.
How long do I legally have to keep client records?
GDPR doesn’t set a fixed number of years. It requires you to keep records only as long as necessary, guided by legal claim time limits, your professional body’s own rules, and your insurer’s requirements. See the “How long should you keep records” section above for the detail.
Can a client ask me to delete their records?
Yes, but this right isn’t absolute. If you still have a legal reason to keep the data, such as being within your retention period for a potential claim, you can generally refuse and should explain why.
Do I need a data processing agreement if I use an AI note-taking app?
Yes. If an AI tool processes client information on your behalf, you’re the data controller and the AI provider is your processor, so you need a proper agreement covering how that data is used and stored
Author: Michelle Bebbington – Course Co-ordinator and Assessor
References
Data protection fee: ico.org.uk/for-organisations/data-protection-fee/data-protection-fee/
Special category data: ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/special-category-data/
Right of access (subject access requests): ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/
Right to erasure: ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-erasure/
Storage limitation principle: ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/
Personal data breaches, a guide: ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/
Artificial intelligence and data protection: ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/

