Let us start with the truth about GDPR private practice rules. If you run a solo therapy practice in the UK, some part of your setup probably falls short. Not deliberately, and not because you are careless.
The rules are dry and the language is thick with jargon. Meanwhile nobody in your training spent an afternoon explaining "data minimisation" in real terms. The ICO does publish guidance aimed at small organisations, though few therapists ever find it.
So let us fix that. No legal language, and no scare tactics. Instead a clear walk-through of what most therapists get wrong, plus what to do about each.
What GDPR private practice rules actually mean
GDPR stands for General Data Protection Regulation. In the UK it now sits inside the Data Protection Act 2018. So it governs how you store and use client information.
In plain words, it says four things:
- First, you can only collect information you actually need
- Second, you have to keep it safe
- Third, you have to be honest about what you do with it
- Finally, you have to delete it when you no longer need it
The ICO sets these out formally as the data protection principles.
That is it. Most therapists already follow the spirit of these rules. However, the problem lives in the details. You also need a lawful basis for holding health data, which for therapy notes is rarely consent.
Gap 1 — Your client notes are in the wrong place
This is the most common mistake. So consider where therapists keep client notes:
- A Google Doc
- A folder on a personal laptop
- A locked notebook in a drawer
- An email thread with the client
None of these is properly safe alone. Google stores documents on US servers. Personal laptops rarely carry encryption. Notebooks go missing. Meanwhile email ranks among the least secure ways to send anything sensitive.
You need a system designed for client records. It should keep data inside the UK or EU, lock it down, control access and back itself up.
A modern booking system for small businesses handles exactly this. So your notes, intake forms and session history sit in one secure place. Access controls replace the sprawl across five apps.
Gap 2 — Your intake forms are emailed PDFs
Most therapists use a PDF intake form. Then the client downloads it, fills it in and emails it back.
That is a problem, because email is not secure. The form holds some of the most sensitive information anyone shares. Mental health history, medication, family background. Sending it via Gmail is like shouting it across a coffee shop. Should it go astray, the ICO expects a breach report within 72 hours.
So use a secure intake form instead. Good scheduling software for small businesses provides one. The client fills it in through a private link. Then the data lands straight in your system. No email, no downloads, no forwarding by mistake.
Gap 3 — You don't have a privacy notice (or yours is wrong)
GDPR requires you to tell clients in writing what you do with their data. The government summary of your obligations puts it plainly. Most therapists, though, either:
- Don't have a privacy notice at all
- Have one copied from another therapist's website that doesn't quite fit
- Have one buried at the bottom of their website that no client has ever read
A proper privacy notice answers a few simple questions:
- First, what information do you collect from clients?
- Second, why do you collect it?
- Where do you keep it?
- Then how long do you keep it?
- Who else can see it (a supervisor, your accountant)?
- Finally, how can the client see, change or delete their data?
You do not need a lawyer to write one. Instead answer those questions honestly and plainly. Then make sure clients see it before sharing anything. Note that most practices must also pay the ICO data protection fee.
Gap 4 — You're keeping notes for too long
GDPR says you can only keep information for as long as you actually need it. For therapists, that's tied to your professional body's record-keeping rules.
For example, the BACP sets a retention period running from the last session. Once it passes, your obligation flips. You are not merely allowed to delete the notes. You are expected to.
Yet most solo therapists never delete anything. Their laptop still holds every note from the last decade.
Set a yearly review. Once a year, look at your records. Anything past the retention period goes, properly and permanently. Not just the laptop file, but the backups, cloud copies and email trail too. Your records system should make that one click rather than a lost weekend.
Gap 5 — Your "system" is actually five different apps
This is the quiet risk most therapists never see.
You take bookings on one tool, then write notes in another. Invoices go through a third. Meanwhile forms arrive by email and reminders leave from your phone.
Each tool holds a piece of your client's data. So each is a separate place where something can go wrong. Each also needs its own privacy policy, security check and delete button.
That is why all-in-one business management software changes the picture. When bookings, notes, forms, payments and messages share one secure place, the work shrinks. One privacy policy, one system to lock down, and one button when a client asks for their data.
Your GDPR private practice starting point this week
You need not fix everything at once. So if your practice has gaps, start here:
- First, move client notes off Google Docs and personal laptops into a UK-based records tool
- Next, replace emailed PDF intake forms with a secure online form
- Write or update your privacy notice in plain English and put it on your booking page
- Then set a yearly date to review and delete old records
- Finally, audit your tools, since one good system often replaces three half-good ones
GDPR does not exist to punish therapists. Instead it protects people who trust you with the most sensitive parts of their lives. Better still, getting it right makes the practice calmer and easier to run.
You trained to help people. The compliance admin was never supposed to be the job. It's time to stop letting it be.
Run a calmer, compliant practice.
Aasure is one platform for small service businesses. It handles bookings, secure intake forms, client records and compliance automatically.
Start your free trial →