Most guidance a therapist finds online about data protection is either written for large NHS trusts, lifted from American HIPAA rules that do not apply here, or so abstract that it is hard to know what to actually do on a Monday morning. This article tries to be the opposite: a practical, UK-specific account of what data protection law asks of a private practice, why the rules are stricter for therapists, and what has shifted now that the biggest reform of UK data protection law since GDPR is in force.

Two things to keep in mind before the detail.

First, the law recently changed. The Data (Use and Access) Act 2025 (the DUAA) took effect in stages through 2026, so some of what you may have read even a year ago is now out of date.6 Where something has shifted, this article flags it.

Second, almost everything below flows from one fact: under UK GDPR you are the data controller for your clients’ information, and the tools you use (your practice software, your note-taker, your video platform) are your processors. You carry the legal accountability; they act on your instructions. Hold onto that distinction and most of the obligations stop feeling arbitrary.

In this article

  • Why therapy data is treated as special
  • Why consent is usually the wrong lawful basis
  • Four obligations worth checking: the ICO fee, a policy document, a privacy notice, and a DPIA
  • The 72-hour breach rule
  • Subject Access Requests, and the new right to complain
  • How long to keep notes, and when you can refuse to delete them
  • What the Data (Use and Access) Act 2025 changed
  • Controller versus processor: what your software carries

Why therapy data is treated as special

UK GDPR splits personal data into ordinary data and “special category” data. Special category data is the short list of information considered sensitive enough to warrant extra protection: health, sex life, sexual orientation, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetics, and biometrics.1

Data about someone’s mental health is health data, and health data is special category. That single classification is what makes a therapy practice different from most small businesses. The information you hold is, by definition, in the most protected class the law recognises.

It is worth noticing how easily special category data appears in a practice. It is not only your session notes. An entry in your diary that says “assessment, anxiety” is health data. An invoice with your practice name on a client’s bank statement can reveal that they are receiving therapy, which is itself health information.2 A referral email, an intake form, a risk note, a voicemail transcript: most of what passes through a practice touches the protected category at some point.

The practical consequence is that the bar for lawfulness, security, and transparency is higher for you than the generic “be sensible with data” advice aimed at small businesses. The rest of this article is really about what that higher bar means in concrete terms.

Why consent is usually the wrong lawful basis

Processing personal data needs a lawful basis under Article 6. Processing special category data needs that plus a separate condition under Article 9. You have to satisfy both, and record both, before you start.3

The natural instinct is to reach for consent. For the therapeutic relationship, and for talking to clients about confidentiality, that instinct is right. As the legal basis for holding clinical records, consent is usually the wrong choice, and it helps to see why.

Consent can be withdrawn at any time. If it is the only thing that lets you hold a client’s notes and they withdraw it, your basis disappears, even though you may still need those records to defend a complaint. Consent also has to be freely given, which can sit awkwardly with the power dynamic in a therapeutic relationship.

There is a sturdier option built for exactly this situation. For Article 6, most self-employed therapists rely on performance of a contract: you need the records to deliver the service the client came to you for. For Article 9, the provision of health or social care condition (Article 9(2)(h), given effect by Schedule 1 of the Data Protection Act 2018) is designed for professionals delivering care under a duty of confidentiality.3 It does not collapse the moment a client changes their mind.

Consent still has its place, for the things that genuinely are optional: text reminders, or contacting a client’s GP. The point is narrower. Do not hang your core record-keeping on it.

Four obligations worth checking

Some requirements follow naturally from having a privacy notice and keeping your files secure. Four others are easy to overlook, partly because they are specific to handling special category data and so rarely appear in general small-business guidance. All four are things a regulator would expect a professional handling health data to have in place.

1. The ICO data protection fee

Under the Data Protection (Charges and Information) Regulations 2018, almost any organisation or sole trader that processes personal data electronically has to pay an annual data protection fee to the Information Commissioner’s Office, unless a narrow exemption applies. A self-employed therapist holding client records on a computer is squarely within scope.5

For most small practices the fee sits in the lowest of three tiers: currently £52 a year, or £47 by direct debit (the tiers rose in 2026, so older figures you may find are out of date).5 It is not a large sum, but it is a legal requirement, and the ICO can issue a penalty for not paying. There are limited exemptions, for example if you genuinely keep no records electronically (rare in modern practice), but a common misunderstanding is worth correcting: if you run your practice through a limited company, the “limited company set up only to handle accounts and payments” exemption does not cover you, because you are processing clients’ clinical data through the business, not just your own accounts.5

If you are unsure, the ICO publishes a short self-assessment that tells you whether you need to pay and at which tier.

2. An appropriate policy document

This one is easy to miss, because it applies specifically to special category data and so tends not to appear in general guidance. When you rely on the health or social care condition (or several other Schedule 1 conditions) to process special category data, UK law requires you to have an “appropriate policy document” in place: a short written document explaining how you comply with the data protection principles in relation to that sensitive data, and your retention and erasure approach for it.1

It does not need to be long or lawyerly. A page or two covering what special category data you process, your lawful basis and Article 9 condition, how you keep it secure, how long you keep it, and how you dispose of it is enough for a solo practice. The ICO and the government publish templates you can adapt.7 The point is that, if asked, you can produce it.

3. A privacy notice that actually does the job

You almost certainly have a privacy notice. The question is whether it does what UK GDPR requires, which is to tell people, clearly and accessibly, what data you collect, why, your lawful basis and Article 9 condition, who you share it with (including which processors, such as your software platform), how long you keep it, how it is protected, and what rights they have.1

Two things commonly let practices down here. The first is vagueness about third parties: phrases like “we use secure, industry-standard systems” do not tell a client who actually holds their data. Naming your platform and the fact that it acts as your processor is both more honest and more defensible. The second, new for 2026, is the right to complain (more on that below), which now needs to be signposted in your notice.

4. A DPIA where the processing is high risk

A Data Protection Impact Assessment is a structured risk assessment you carry out before starting a type of processing that is likely to be high risk. Large-scale processing of special category data is one of the ICO’s listed triggers. A solo practice may not be “large scale” in the regulator’s sense, so it is fair to say a DPIA is not automatically required for every private therapist.1 Where it is required, the obligation to carry it out is the controller’s, under Article 35, and it cannot be handed to a vendor.

That last point is worth being clear about, because it is a common misunderstanding. A DPIA is not really an assessment of a piece of software; it is an assessment of your processing, your clients, your purposes, and the harm that would follow if your particular records were exposed. A vendor cannot do that for you, and a vendor telling you it “has completed a DPIA” does not discharge your duty. What a vendor can and should do is supply the inputs: where the data is hosted, who the sub-processors are, what security controls are in place, and what happens to the data on deletion. UK GDPR actually requires processors to give you this help (Article 28). You gather those facts; you reach the conclusion.

Where a DPIA most often earns its place is when you adopt a new tool that touches client data, an AI note-taker, a new video platform, a new booking system. Working through what data passes through the tool, where it is stored, who can access it, and what could go wrong is exactly the exercise a DPIA formalises. It also dovetails with what professional bodies now expect: the BACP’s draft 2025 Ethical Framework asks members to assess the risks of any AI or digital tool before using it. (We cover that in our piece on the new BACP Ethical Framework.)

When something goes wrong: the 72-hour rule

A personal data breach is not only a hack. A laptop left on a train, an email sent to the wrong client, notes visible on a shared screen during an online session: all are breaches.

If a breach is likely to result in a risk to people’s rights and freedoms, you must report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it (UK GDPR Articles 33 and 34). If the risk to the individuals is high, you must also tell the affected people themselves, promptly and in plain language. Given the sensitivity of mental health data, a breach involving therapy records will very often clear the “high risk” bar.

Two practical habits matter. Keep an internal log of any breach, even minor ones you decide are not reportable, with your reasoning; the ICO expects controllers to be able to show that judgement was applied. And know in advance how you would report, because the 72-hour clock is short and starts when you become aware, not when you have finished investigating.

Subject Access Requests, and the new right to complain

Subject Access Requests

A client has the right to ask for a copy of the personal data you hold about them. This is a Subject Access Request (SAR). You generally have one calendar month to respond, usually free of charge, though that can be extended by up to two further months for genuinely complex requests.

The DUAA tidied this area up rather than overhauling it. It confirmed in law that your search needs only be “reasonable and proportionate”, not exhaustive, and that you can effectively pause the clock while you verify the requester’s identity or seek clarification about what they are asking for.6 Both reflect what good practice already looked like.

SARs are one of the trickier moments in a therapy practice because of two complications. First, your notes may contain information about third parties (a partner, a family member) whose data you cannot simply hand over without thought. Second, there are narrow exemptions, for example where disclosure would be likely to cause serious harm to the physical or mental health of the client or another person. These are real but they are exceptions, not a default reason to refuse. Because mishandling a SAR can lead to a complaint or a compensation claim, it is wise to take your professional indemnity insurer’s advice before disclosing clinical notes in response to one.8

The new right to complain

Since 19 June 2026, a client has the right to complain directly to you about how you have handled their data, and you are expected to have a procedure for dealing with such complaints.6 The regulator will generally expect a client to have come to you first before it steps in.

If you go looking for this in UK GDPR, you will not find it. The right sits in the Data Protection Act 2018, at a new section 164A. What UK GDPR does is require you to tell people about it: when you respond to a Subject Access Request, or when you decline to act on a request, you now have to mention both the client’s right to complain to you and their existing right to complain to the ICO (Articles 12 and 15).

For a private practice, what this asks for is modest: a clear route by which a client can raise a concern about how you have handled their data, a process for responding to it, and a mention of both complaint routes in your privacy notice and in your replies to access requests.

How long to keep notes (and why erasure rarely forces deletion)

There is no single statutory retention period for private therapy records, which is why practitioners get such different answers when they ask. What the law actually requires is the storage limitation principle: keep records no longer than you need them, decide on a justified retention period, and write it down.

In practice, the most common benchmark in UK private practice is a minimum of around seven years from the end of therapy, with the same period running from the date of death for a deceased client. That figure tracks the standard limitation period for most civil claims in England and Wales, under the Limitation Act 1980: if a complaint or claim is brought, your contemporaneous records are your defence, and disposing of them too early can leave you exposed.9 Some reference points sit either side of this. The BACP’s own professional conduct process allows roughly three years from the end of counselling to bring a complaint, which some practitioners treat as a floor.8 The NHS Records Management Code of Practice points to far longer periods (commonly cited as twenty years after treatment, or ten years after death), which are not binding on private practice but which some clinicians adopt.10 Records relating to children usually warrant longer retention, typically until the young person reaches adulthood plus a further period. And your indemnity insurer may stipulate its own minimum, so check your policy.9

A point that causes real confusion: the so-called “right to be forgotten” (the right to erasure) is not absolute. Article 17 of UK GDPR sets out the exceptions, and two of them matter here: where you need the records to comply with a legal obligation, and where you need them to establish or defend a legal claim. On that basis you can generally decline to erase clinical notes during your retention period.4 The cleaner approach is to set this out in your privacy notice in advance, so a client who asks for deletion understands why their core clinical record will be kept for a defined time, even as you delete anything you genuinely no longer need.8

When the retention period does end, deletion has to be real: electronic records permanently removed, including from backups, and paper securely shredded. Keeping a brief record of what you destroyed and when is good evidence that you applied your own policy.8

What the Data (Use and Access) Act 2025 changed, and what it left alone

It helps to be clear-eyed about the DUAA, because it has been described both as a minor tidy-up and as a seismic shift, and neither is quite right. It is the most significant reform of UK data protection law since UK GDPR, but it amends the existing regime rather than replacing it. The core architecture, the principles, lawful bases, special category protections, and individual rights, all remain.6

The changes most relevant to a therapy practice:

  • A right to complain directly to you, and a duty to have a complaints procedure, from 19 June 2026. The right is in section 164A of the Data Protection Act 2018; UK GDPR requires you to tell people about it.
  • SARs: the “reasonable and proportionate” search standard and the ability to pause the clock for clarification are now settled in law.
  • A new “recognised legitimate interests” basis under Article 6 for a defined set of activities such as safeguarding and crime prevention, which removes the usual balancing test for those specific purposes. This is useful background for safeguarding disclosures, but note the catch for therapists: it is an Article 6 basis only. It does not remove the need for a separate Article 9 condition when the data is special category, which yours almost always is.
  • International transfers: the old “essentially equivalent” test for sending data abroad is replaced by a new “data protection test” (broadly, that protections are not materially lower than the UK’s). Relevant if you use tools that store or process data outside the UK.
  • The regulator is changing shape: the ICO is being reorganised into a new body, the Information Commission, with a more conventional corporate structure. This transition is being implemented through 2026; in the meantime “ICO” remains the name in everyday use.
  • Cookies and PECR: the rules on website cookies were relaxed for certain low-risk uses, but penalties under the electronic communications rules rose sharply (to a maximum of £17.5m or 4% of turnover). For a small practice website this mostly means: keep your cookie banner honest and minimal.

What the DUAA did not do is weaken the protections around health data, dilute your duty to identify a lawful basis, or change the fundamentals of what a therapist has to do. If anything, the new complaints duty adds a small obligation rather than removing one.

Controller versus processor: what your software carries, and what stays with you

Return to the distinction from the start. You are the controller. Your practice management platform, your note-taker, your video tool, are processors acting on your instructions. The law (UK GDPR Article 28) requires that any processor you use is bound by a written contract, a Data Processing Agreement, that sets out what they can do with the data, the security they must maintain, their use of any sub-processors, how they will help you with breaches and access requests, and what happens to the data when you leave (return or deletion).

What this means in practice is that some of the compliance burden genuinely sits with your tools, and some of it cannot be delegated. Your processor is responsible for things like securing the infrastructure, encrypting the data, controlling access, and maintaining backups. You remain responsible for choosing processors that are actually compliant, for instructing them properly, for any risk assessment your processing needs, and for everything client-facing: your privacy notice, your lawful basis, your retention decisions, your SAR responses, your complaints procedure.

So when you assess any tool that touches client data, four questions cut to the heart of it: Is there a Data Processing Agreement, and does it name the provider as your processor? Where is the data hosted, and under which country’s law? Who are the sub-processors? And can you export and permanently delete the data when you need to? A provider that cannot answer these clearly is a provider you cannot evidence good practice with.

How My-Therapy-Suite helps

Most of what is above is about being able to evidence good practice consistently, not about doing anything exotic. For practitioners using a digital system, the practical question is whether that system makes the evidencing easier or harder. A few of these areas are built into how My-Therapy-Suite handles records and data.

Data handling and storage

The platform is hosted in the UK, which makes it straightforward to answer the “where is my data, and under whose law” question. Our Data Processing Agreement names My-Therapy-Suite as your data processor under UK GDPR, and our security and data page sets out the controls in place, the sub-processors involved, and how client information is protected, including encryption, access controls, and backups. That is the documentation you would otherwise have to assemble yourself to answer the four processor questions above.

Privacy notice, agreements, and intake

Custom intake forms and working agreements can be sent, completed, and stored alongside the client record rather than living in email, which makes it easier to show what a client was told and agreed to, and when.

Records and retention

Session notes, supervision notes, and a risk log sit in the client file and support free-text reasoning, so that when a decision needs explaining it can be recorded and timestamped against the client. Records can be exported and permanently deleted when a retention period ends.

None of this makes a practice compliant on its own. No platform can choose your lawful basis, write your privacy notice, or make a judgement call on a Subject Access Request for you, and using one does not remove the need for supervision, professional judgement, or independent legal advice where it matters. What a good system does is lower the friction in producing the evidence that good practice is actually happening.

Where to start

You do not need to do all of this at once. A sensible order:

  1. Confirm whether you need to pay the ICO data protection fee, and pay it if so. It is the quickest item to close.
  2. Review your privacy notice against the list above, and add a clear route for clients to complain about data handling, plus a signpost to the ICO.
  3. Put a simple data protection complaints procedure in place, to reflect the change that took effect in June 2026.
  4. Put a short appropriate policy document in place for your special category processing.
  5. Decide and write down your retention period, and explain in your privacy notice how it interacts with deletion requests.
  6. For each tool that touches client data, confirm there is a Data Processing Agreement, check where the data is hosted, and make sure you can export and delete it.
  7. Before adopting any new AI, video, or booking tool, run a short risk assessment (a light DPIA) and keep it on file.

None of these is technically difficult. The work is in getting things on paper and being able to point to the record if anyone asks.

This article is general information, current as of July 2026, not legal advice, and it does not create a client relationship. UK data protection law is actively changing through 2026 as the remaining parts of the Data (Use and Access) Act come into force, so check the ICO’s current guidance and, for anything specific to your situation, your professional body and your indemnity insurer.

Sources

  1. ICO, Special category data — a guide to lawful basis.
  2. ICO, What are the rules on special category data?
  3. Data Protection Act 2018, Schedule 1 (conditions for processing special category data) and section 10 (special categories of personal data); UK GDPR, Articles 6, 9, 12 and 15. The right to complain to a controller is at section 164A DPA 2018, inserted by section 103 of the Data (Use and Access) Act 2025.
  4. UK GDPR, Articles 17, 28, 33 and 34 (right to erasure; processors; personal data breach notification). The consolidated text is available via the ICO and legislation.gov.uk.
  5. ICO, Guide to the data protection fee (tier amounts); ICO, Data protection fee — self-assessment; ICO, Paying a data protection fee — human health and social care sector.
  6. ICO, Statement on the commencement of the Data (Use and Access) Act, 5 February 2026; Data (Use and Access) Act 2025; GOV.UK, Data (Use and Access) Act 2025: plans for commencement.
  7. ICO, Appropriate policy document — guidance and template; GOV.UK, example Appropriate Policy Document.
  8. BACP, Data protection and GDPR FAQs and Notes and record keeping.
  9. Limitation Act 1980 (legislation.gov.uk); Howden, Guidance for Therapists on Note and Record Keeping.
  10. NHS Records Management Code of Practice, NHS Transformation Directorate. Not binding on private practice, but a common reference point.