EN

Region and language

All articles

Subject access requests for therapy notes: a step-by-step guide for UK practitioners

How to handle a subject access request for therapy notes in the UK. Deadlines, fees, ID, redaction, the serious harm test, children and template replies.

Countries covered : United Kingdom

A subject access request (SAR) is a request from a person for a copy of the personal information an organisation holds about them. For a private practitioner, that usually means session notes, assessment reports, letters, emails and texts about one client. The right comes from Article 15 of the UK GDPR. The rules on how and when to reply sit in Articles 12 and 12A.

If you practise in France, read our French version on patient access to therapy notes, as the rules there are different.

How to recognise a subject access request

There is no special form. The ICO says there are no formal requirements for a valid request. The client does not need to say "subject access" or quote the law. It just needs to be clear that they want their personal information.

  • A request can be verbal or written.
  • A request on social media is valid where you have a presence there.
  • Someone else can ask for the client, such as a relative, friend or solicitor. You must be satisfied they have authority, usually a written authority signed by the client.

The ICO says you should record requests made by phone or in person, so you can confirm the details.

The deadline: one month, sometimes three

You must respond without undue delay and within one month. Since 5 February 2026, Article 12(3) of the UK GDPR refers to the "applicable time period", set out in a new Article 12A. This was added by section 76 of the Data (Use and Access) Act 2025.

Under Article 12A, the period is one month starting from the latest of three events:

  • the day you receive the request;
  • the day you receive information you asked for to confirm identity;
  • the day the client pays a fee you were allowed to charge.

How to count the month

The ICO explains that the month runs to the same date in the next month. A request received on 1 January is due on 1 February. If that date does not exist, use the last day of the month, so 31 January becomes 28 February (29 in a leap year). If the deadline falls on a weekend or bank holiday, you have until the end of the next working day.

Extending by two months

You can extend by two further months if the request is complex or the person has sent several requests. You must tell the client within the first month and give your reasons. The ICO says a large volume of information alone does not make a request complex.

Stopping the clock

If you reasonably need more information to identify what the client wants, you can ask. The waiting time does not count. The ICO gives an example. A request received on 14 May is due on 14 June. If you ask for clarification on 15 May and get the reply on 18 May, the new deadline is 18 June. You cannot ask as a routine step.

Identity checks

You must be satisfied that you know who is asking and that the information is about them. The ICO says checks should be proportionate. Ask for formal ID only when necessary, for example when you have a real doubt. A higher risk of harm from disclosure can justify more checks. You do not need to keep copies of the ID.

Fees

In most cases you cannot charge. Article 12(5) says the response must be free of charge. You can charge a reasonable fee for administrative costs only in two cases:

  • the request is manifestly unfounded or excessive (you could also refuse it, but you carry the burden of showing why);
  • the client asks for further copies of information you have already sent.

What the client is entitled to

Article 15 covers three things:

  • confirmation that you process their personal information;
  • a copy of that personal information;
  • supplementary information, such as your purposes, the categories of data, who you share it with, how long you keep it, and their rights, including the right to complain to the ICO.

Much of this is already in your privacy notice. Our guide on how long to keep counselling notes in the UK helps you state your retention period clearly.

Reasonable and proportionate searches

Section 78 of the Data (Use and Access) Act 2025 added Article 15(1A). It says the client is only entitled to what you can provide based on a reasonable and proportionate search. Think of every place where you hold information about the client:

  • your notes system or software, including information held by a provider that acts as your processor;
  • paper notes kept in a structured filing system;
  • emails, including ones moved to "Deleted items";
  • messages on your phone.

The ICO says the request covers the information you hold when you receive it. Changing or deleting information with the aim of preventing its disclosure is an offence under the Data Protection Act 2018. Separate process notes may well be in scope. See our article on process notes and client records.

Information about other people

Therapy notes often mention partners, parents, children or colleagues. The ICO sets out three steps:

  1. Can you comply without identifying the other person, for example by removing names?
  2. Has the other person consented? If so, you must disclose. You do not have to ask them.
  3. Is it reasonable to disclose without consent? Weigh the type of information and any duty of confidence.

Where a duty of confidence exists, the ICO says withholding third-party information without consent is usually reasonable. Give as much as you can, using redacted versions. A separate "health data test" applies to health professionals named in a health record. If they compiled or contributed to it, or were involved in the client's care or treatment, it is reasonable to disclose their information. Keep a note of each decision and your reasons.

Health data and the serious harm test

Therapy notes are data concerning health. Part 2 of Schedule 3 to the Data Protection Act 2018 adds specific rules. The "serious harm test" is met if disclosure would be likely to cause serious harm to the physical or mental health of the client or another person. Where it is met, you can withhold that part of the data.

Who is a "health professional" matters here. Section 204 of the Act gives a list. It includes registered doctors, nurses and child psychotherapists. It also includes people registered in a profession covered by the Health Professions Order 2001, which covers practitioner psychologists, occupational therapists, physiotherapists and speech and language therapists, among others. On our reading, counsellors and adult psychotherapists do not appear as such in the list.

This has practical effects if you are not on that list:

  • To withhold health data under the serious harm test, you must first get an opinion from the "appropriate health professional" that the test is met (paragraph 5).
  • To disclose health data, you need an opinion that the test is not met (paragraph 6). This does not apply if the client has already seen the information or knows about it.
  • The opinion must be from the last six months, and you should ask again if that is reasonable.

The appropriate health professional is the one currently or most recently responsible for the client's care or treatment in connection with the matter. The ICO says that if none is available, you can appoint someone with the necessary experience and qualifications. The Act words this fallback more narrowly. If you cannot get an opinion in time, the ICO says you must withhold the health information. If unsure, contact the ICO or your professional body.

Children and parents

The ICO is clear that the right of access belongs to the child, not the parent. First decide whether the child is mature enough to understand their rights. If so, you should normally respond to the child directly. In Scotland, a child aged 12 or over is usually considered mature enough. This presumption does not apply in England, Wales or Northern Ireland, where you assess each child.

If the child is not competent, a person with parental responsibility can usually act for them, unless this goes against the child's best interests. Schedule 3 also protects confidences. When a parent asks for the health data of a child under 18 (16 in Scotland), you do not have to disclose what the child shared expecting it would not reach that parent, or asked you to keep private.

Step by step: handling a SAR in a small practice

  1. Log the request. Note the date, channel and wording. Confirm a verbal request in writing.
  2. Check identity and authority. Ask only for what you need, straight away.
  3. Set the deadline. Count one month from the latest of receipt, ID or fee, and diarise it.
  4. Clarify only if needed. Note the dates the clock stopped and restarted.
  5. Search. Notes, software, paper files, emails and texts. Ask your software provider about anything you cannot export.
  6. Review. Mark third-party information and anything that may meet the serious harm test. Plan any health professional opinion early.
  7. Extend if justified. Tell the client before the first month ends and explain why.
  8. Redact and send securely. If the request came electronically, reply electronically unless the client asks otherwise.
  9. Keep a file note. Record what you sent, what you withheld and why.

Template wording for your replies

Adapt these paragraphs to your situation. They are a starting point, not legal advice. For more ready-made letters, see our clinical document templates.

Acknowledgement

Dear [name], thank you for your request of [date] for a copy of the personal information I hold about you. I am treating it as a subject access request under the UK GDPR.

[If needed] To protect your information, please confirm your identity by [method]. I will start the one month response period once I receive this.

I will reply by [date].

Extension notice (within the first month)

Dear [name], I am writing about your request of [date]. Because [reason], I need to extend the response period by up to two further months. I will reply by [date] at the latest.

Covering letter with the response

Dear [name], please find enclosed a copy of the personal information I hold about you, in response to your request of [date].

The enclosed documents include [list, for example session notes from [date] to [date], letters and emails]. I have also enclosed my privacy notice. It explains why I hold your information, who I share it with, how long I keep it and your rights.

[If relevant] Some information has been removed because it is about other people, or because [brief reason]. Where I have removed information, this is marked on the document.

If you are unhappy with my response, please tell me and I will review it. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

How Delta fits in

Delta is an AI assistant for mental health and allied health practitioners. During the session, Delta transcribes what is said, then prepares a session report that you review and validate. You can also dictate observations right after the session or add written notes. Each validated report is added to the client's file, so the whole follow-up sits in one place when a request arrives. Data is hosted in France with a host certified for health data (HDS, the French health data hosting certification). AI processing, transcription included, runs on servers in France. The client's name and identifying details are pseudonymised before AI processing, no audio file is kept, data is never used to train models, and data is encrypted in transit and at rest. As with any provider, ask Delta for its data processing agreement. See the security page or the page for therapists.

Do I have to give a client a copy of my therapy notes?

Yes, in most cases. Therapy notes about the client are their personal information, so they are covered by the right of access. You can withhold specific parts, such as information about other people or health data likely to cause serious harm, but you must justify each decision.

How long do I have to respond to a subject access request?

One month, counted from the latest of the day you receive the request, the day you receive ID you asked for, or the day a permitted fee is paid. You can extend by two further months for complex requests or several requests from the same person. You must tell the client within the first month and explain why.

Do process notes have to be disclosed?

If they contain personal information about the client and you hold them, they are likely to be in scope. Deleting or changing them after a request to prevent disclosure is an offence under the Data Protection Act 2018. Exemptions, such as the serious harm test, apply to the content, not to the label you give the notes.

Can a parent see their child's therapy notes?

The right belongs to the child. If the child is mature enough to understand it, you should normally respond to the child. If not, a parent with parental responsibility can usually act for them, but information the child shared expecting it would stay private from that parent can be withheld.

I am a counsellor, not a health professional. Does that change anything?

Probably. On our reading, counsellors do not appear as such in the list in section 204 of the Data Protection Act 2018. Schedule 3 then requires an opinion from the appropriate health professional before you withhold health data under the serious harm test, and before you disclose it unless the client already knows the information. Check with the ICO or your professional body.

Sources

Cookie policy