UK GDPR for counsellors and private therapists: the practical checklist
A plain-English UK GDPR checklist for counsellors and private therapists. Lawful basis, ICO fee, privacy notice, DPIA, contracts, transfers, security, retention, breaches and access requests.
Countries covered : United Kingdom
UK GDPR is the UK version of the General Data Protection Regulation. It works alongside the Data Protection Act 2018 and sets the rules for anyone who uses personal information about other people. For a counsellor, that covers client notes, diary, invoices, emails and the tools that store them.
You are the data controller for your practice. You decide why and how client data is used. The tools you pay for usually act as processors, which means they handle data on your instructions.
Each item below says what the law or the ICO says, then what to do. It is general information, not legal advice. The BACP also has a GDPR FAQ for members that covers similar ground and points to its Good Practice in Action resources.
The checklist
1. Know that client notes are special category data
Article 9(1) of UK GDPR lists types of data that are prohibited from processing unless a condition applies. Data concerning health is one of them. Notes about a client's mood, history, symptoms or progress in therapy are health data.
The ICO says you must identify both a lawful basis under article 6 and a separate condition for processing special category data. You need both, not one or the other.
2. Choose and write down your article 6 lawful basis
Article 6(1) gives six lawful bases. In plain English they are consent, contract, legal obligation, vital interests, public task and legitimate interests. Article 6(1)(b) covers processing that is necessary for the performance of a contract to which the client is party, or to take steps at the client's request before entering into one. A private counsellor with a paying client may look at this basis. Others may look at legitimate interests in article 6(1)(f).
The ICO says you always need an article 6 basis, and you must keep records of your choice when you process special category data. Pick one, explain it in your privacy notice and take advice if you are unsure.
3. Check the article 9(2)(h) health or social care condition
Article 9(2)(h) allows processing that is necessary for, among other purposes, medical diagnosis and the provision of health or social care or treatment. It applies on the basis of domestic law or under a contract with a health professional. It is subject to the safeguards in article 9(3).
Article 9(3) says the data must be processed by or under the responsibility of a professional subject to an obligation of professional secrecy, or by another person also subject to an obligation of secrecy under domestic law.
Section 11(1) of the Data Protection Act 2018 explains what that means in the UK. The secrecy safeguard covers processing carried out by or under the responsibility of a health or social work professional, or by another person who owes a duty of confidentiality under an enactment or rule of law. "Health professional" and "social work professional" are defined terms in the Act. Check carefully whether your own work fits either limb, especially if no statutory body regulates you, and take advice if unsure.
The ICO also lists health or social care as needing condition 2 in Schedule 1 of the 2018 Act. It says you must identify whether you need an "appropriate policy document". Check this point against the ICO guidance, or ask an adviser.
4. Pay the ICO data protection fee
The ICO says organisations, including sole traders, that use personal information need to pay a data protection fee unless they are exempt. The BACP FAQ says that all businesses, including sole traders, processing personal information electronically must register with the ICO.
The amounts are set by regulation 3 of the Data Protection (Charges and Information) Regulations 2018, as amended from 17 February 2025.
- Tier 1, micro organisations: £52.
- Tier 2, small and medium organisations: £78.
- Tier 3, large organisations: £3,763.
The charge is £5 less if you pay by direct debit. Under regulation 2, the charge is due within the first 21 days of each 12-month charge period. Most solo practitioners will fall into tier 1, but read the tier tests in the regulation or use the ICO self-assessment. Our guide to ICO registration for counsellors and therapists goes into more detail.
5. Write a privacy notice clients can read
Under article 13, when you collect data from the client directly, you must give privacy information at the time you obtain it. For example, when a new client first gives you their details. The ICO lists what you must always include.
- Your name and contact details.
- The purposes of the processing.
- Your lawful basis.
- How long you keep the data, or the criteria you use to decide.
- The client's rights, with the right to object flagged clearly and separately.
- The right to complain to the ICO.
Some items apply only if relevant. They include recipients such as your note-taking tool, details of any transfer outside the UK, and the right to withdraw consent if you rely on consent. Keep the language plain.
6. Decide whether you need a DPIA
A data protection impact assessment, or DPIA, is a written review of the risks of a type of processing and how you reduce them. Article 35(1) requires one where processing is likely to result in a high risk to people's rights and freedoms.
The ICO's list of processing likely to need a DPIA includes innovative technology, including AI, when combined with another criterion from the European guidelines. It also says that in most cases a combination of two factors indicates the need for a DPIA. Large-scale processing of special category data always needs one. The ICO adds that if in any doubt, it recommends doing a DPIA.
If you bring in new technology that handles therapy content, a short DPIA is a clear way to show your thinking. Our article on professional confidentiality and AI covers questions worth asking.
7. Have a contract with every tool that handles client data
Article 28 requires a contract between a controller and a processor. The ICO says it must set out the subject matter and duration of the processing, its nature and purpose, the types of personal data, the categories of people concerned, and your obligations and rights. It must also contain minimum terms.
- The processor acts only on your documented instructions.
- People handling the data are bound by confidentiality.
- The processor takes appropriate security measures.
- It uses sub-processors only with your prior specific or general written authorisation.
- It helps you answer rights requests and meet your other obligations.
- At the end, it deletes or returns the data, at your choice.
- It allows audits and inspections.
This applies to your practice system, cloud storage, video platform and any AI note-taking tool. Ask each provider, Delta included, for its data processing agreement, and keep a copy.
8. Check where your tools store data
If a tool stores or processes data outside the UK, that is an international transfer. Paragraph 4 of Schedule 21 to the Data Protection Act 2018 says a transfer to a destination listed in paragraph 5 is treated as approved by regulations made under article 45A of UK GDPR. Paragraph 5(1) lists the EEA states, Gibraltar and certain EU institutions, among others.
The ICO guide to international transfers, published on 15 January 2026, says that when a transfer is covered by adequacy regulations, information can flow freely without any additional safeguard. It adds that you should still make checks on any organisation you share data with under your other UK GDPR obligations. So a tool hosted in France or Ireland does not need an extra transfer document, but it still needs a contract and a place in your privacy notice. For more, see our article on UK client data stored in the EU.
9. Put sensible security in place
Article 32 requires security measures that are appropriate to the risk. Its examples include encryption, the ability to restore access after an incident and regular testing of your measures.
For a small practice this often comes down to simple habits. Lock your devices. Use strong, unique passwords and two-step sign-in. Keep software up to date. Store paper notes in a locked cabinet. Check which security features your tools offer before you trust them with therapy content.
10. Set a retention period and stick to it
The storage limitation principle in article 5(1)(e) says personal data must be kept in a form that identifies people for no longer than is necessary. The ICO says UK GDPR does not set specific time limits. You decide, you must be able to justify the period, and you should not keep data indefinitely "just in case".
The ICO expects you to review what you hold and erase or anonymise data you no longer need. A written retention period for therapy notes shows you thought about it. Check what your professional body and insurer expect too.
11. Know what to do if there is a breach
Article 33(1) says you must notify the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This does not apply if the breach is unlikely to result in a risk to people's rights and freedoms.
The ICO says you do not need to report every breach. You assess the likely risk first. If the risk to people is high, you must also tell them without undue delay. Article 33(5) says you must document every breach, including the facts, its effects and what you did about it, whether you report it or not.
12. Be ready for rights requests
Clients have rights over their data, including the right to access it. The ICO says you must respond to a subject access request without undue delay and at the latest within one month. You can extend by up to two more months in some cases, if you tell the person why within the first month. In most cases you cannot charge a fee. The ICO's guide to subject access covers the details.
Keep it up to date
Review the list once a year and whenever you change tools. Check your ICO fee, privacy notice, contracts and retention, and note any breaches.
Where Delta fits
Delta is an AI assistant for mental health and allied health practitioners. During the session it transcribes what is said, then prepares a session report that you review. The report is added to the client file.
For this checklist, treat Delta like any other tool that handles client data. Its data is hosted in France with a host certified for health data (HDS, the French health data hosting certification), and AI processing, transcription included, runs on servers located in France. Client names and identifying details are pseudonymised before AI processing, no audio file is kept, data is never used to train models, and data is encrypted in transit and at rest. You still need to ask for its data processing agreement, name it in your privacy notice and decide whether a DPIA is needed. See the security page, our explainer on HDS certified hosting and the page for therapists.
Does GDPR apply to counsellors in private practice?
Yes. UK GDPR applies to anyone who uses personal information for their work, including sole traders. Client notes contain health data, which is special category data under article 9. That means extra conditions apply on top of the usual rules.
Do counsellors have to register with the ICO?
The ICO says organisations, including sole traders, need to pay a data protection fee unless they are exempt. The BACP says all businesses processing personal information electronically must register with the ICO. For a micro organisation the fee is £52 a year, or £47 by direct debit.
What lawful basis should a counsellor use under UK GDPR?
You need an article 6 lawful basis and an article 9 condition. For private clients, contract under article 6(1)(b) is one basis practitioners consider, and the health or social care condition in article 9(2)(h) is one article 9 condition to check. Write your choice down and take advice if you are unsure.
Is consent the right basis for therapy notes?
Not necessarily. Consent is one of six article 6 bases, and the ICO says you must identify the basis that fits your processing. Consent for data protection purposes is separate from consent to therapy. If you rely on consent, your privacy notice must explain the right to withdraw it.
Do I need a DPIA as a solo therapist?
A DPIA is required where processing is likely to result in a high risk. The ICO says innovative technology, including AI, combined with another risk factor usually points to one, and that if in doubt you should do one.
Can I use a note-taking tool hosted in the EU?
Transfers to EEA states are treated as approved under Schedule 21 to the Data Protection Act 2018. The ICO says no additional safeguard is needed where adequacy regulations apply. You still need a data processing agreement with the provider and a mention in your privacy notice.
How quickly must I report a data breach?
If a breach is likely to result in a risk to people, you must tell the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If the risk is high, you must also tell the people affected. You must document every breach, even ones you do not report.
Sources
- UK GDPR, article 6, legislation.gov.uk
- UK GDPR, article 9, legislation.gov.uk
- UK GDPR, article 32, legislation.gov.uk
- UK GDPR, article 33, legislation.gov.uk
- Data Protection Act 2018, section 11, legislation.gov.uk
- Data Protection Act 2018, Schedule 21, paragraph 4, legislation.gov.uk
- Data Protection Act 2018, Schedule 21, paragraph 5, legislation.gov.uk
- Data Protection (Charges and Information) Regulations 2018, regulation 2, legislation.gov.uk
- Data Protection (Charges and Information) Regulations 2018, regulation 3, legislation.gov.uk
- ICO, Data protection fee
- ICO, Data protection fee self-assessment
- ICO, What are the rules on special category data?
- ICO, What privacy information should we provide?
- ICO, When should we provide privacy information?
- ICO, When do we need to do a DPIA?
- ICO, What needs to be included in the contract?
- ICO, International transfers: a guide
- ICO, Storage limitation
- ICO, Personal data breach
- ICO, Personal data breach assessment
- ICO, A guide to subject access
- BACP, GDPR FAQ
Try Delta for 14 days
Try Delta free for 14 days, no card needed, and see how it fits into your practice.
Try it free