GDPR Private Practice Guide: What Therapists Get Wrong

Most solo therapists in the UK have a few quiet GDPR gaps in their practice — and they don't know it. Here's a plain-English guide to what the law actually expects.

Let us start with the truth about GDPR private practice rules. If you run a solo therapy practice in the UK, some part of your setup probably falls short. Not deliberately, and not because you are careless.

The rules are dry and the language is thick with jargon. Meanwhile nobody in your training spent an afternoon explaining "data minimisation" in real terms. The ICO does publish guidance aimed at small organisations, though few therapists ever find it.

So let us fix that. No legal language, and no scare tactics. Instead a clear walk-through of what most therapists get wrong, plus what to do about each.

GDPR private practice — a vault holding the four principles: minimise, protect, be honest, delete.
GDPR boils down to four ideas — most therapists already follow the spirit of them.

What GDPR private practice rules actually mean

GDPR stands for General Data Protection Regulation. In the UK it now sits inside the Data Protection Act 2018. So it governs how you store and use client information.

In plain words, it says four things:

  • First, you can only collect information you actually need
  • Second, you have to keep it safe
  • Third, you have to be honest about what you do with it
  • Finally, you have to delete it when you no longer need it

The ICO sets these out formally as the data protection principles.

That is it. Most therapists already follow the spirit of these rules. However, the problem lives in the details. You also need a lawful basis for holding health data, which for therapy notes is rarely consent.

Gap 1 — Your client notes are in the wrong place

This is the most common mistake. So consider where therapists keep client notes:

  • A Google Doc
  • A folder on a personal laptop
  • A locked notebook in a drawer
  • An email thread with the client

None of these is properly safe alone. Google stores documents on US servers. Personal laptops rarely carry encryption. Notebooks go missing. Meanwhile email ranks among the least secure ways to send anything sensitive.

You need a system designed for client records. It should keep data inside the UK or EU, lock it down, control access and back itself up.

A modern booking system for small businesses handles exactly this. So your notes, intake forms and session history sit in one secure place. Access controls replace the sprawl across five apps.

Gap 2 — Your intake forms are emailed PDFs

Most therapists use a PDF intake form. Then the client downloads it, fills it in and emails it back.

That is a problem, because email is not secure. The form holds some of the most sensitive information anyone shares. Mental health history, medication, family background. Sending it via Gmail is like shouting it across a coffee shop. Should it go astray, the ICO expects a breach report within 72 hours.

On the left a sealed envelope marked 'secure form'. On the right a postcard floating away with the same details visible.
Email is the postcard. A proper form is the envelope.

So use a secure intake form instead. Good scheduling software for small businesses provides one. The client fills it in through a private link. Then the data lands straight in your system. No email, no downloads, no forwarding by mistake.

Gap 3 — You don't have a privacy notice (or yours is wrong)

GDPR requires you to tell clients in writing what you do with their data. The government summary of your obligations puts it plainly. Most therapists, though, either:

  • Don't have a privacy notice at all
  • Have one copied from another therapist's website that doesn't quite fit
  • Have one buried at the bottom of their website that no client has ever read

A proper privacy notice answers a few simple questions:

  • First, what information do you collect from clients?
  • Second, why do you collect it?
  • Where do you keep it?
  • Then how long do you keep it?
  • Who else can see it (a supervisor, your accountant)?
  • Finally, how can the client see, change or delete their data?

You do not need a lawyer to write one. Instead answer those questions honestly and plainly. Then make sure clients see it before sharing anything. Note that most practices must also pay the ICO data protection fee.

Gap 4 — You're keeping notes for too long

GDPR says you can only keep information for as long as you actually need it. For therapists, that's tied to your professional body's record-keeping rules.

For example, the BACP sets a retention period running from the last session. Once it passes, your obligation flips. You are not merely allowed to delete the notes. You are expected to.

Yet most solo therapists never delete anything. Their laptop still holds every note from the last decade.

Set a yearly review. Once a year, look at your records. Anything past the retention period goes, properly and permanently. Not just the laptop file, but the backups, cloud copies and email trail too. Your records system should make that one click rather than a lost weekend.

Gap 5 — Your "system" is actually five different apps

This is the quiet risk most therapists never see.

You take bookings on one tool, then write notes in another. Invoices go through a third. Meanwhile forms arrive by email and reminders leave from your phone.

Each tool holds a piece of your client's data. So each is a separate place where something can go wrong. Each also needs its own privacy policy, security check and delete button.

Five scattered tools on the left versus one consolidated platform on the right.
Fewer tools means fewer cracks for things to slip through.

That is why all-in-one business management software changes the picture. When bookings, notes, forms, payments and messages share one secure place, the work shrinks. One privacy policy, one system to lock down, and one button when a client asks for their data.

Your GDPR private practice starting point this week

You need not fix everything at once. So if your practice has gaps, start here:

Five-step GDPR tidy-up
  1. First, move client notes off Google Docs and personal laptops into a UK-based records tool
  2. Next, replace emailed PDF intake forms with a secure online form
  3. Write or update your privacy notice in plain English and put it on your booking page
  4. Then set a yearly date to review and delete old records
  5. Finally, audit your tools, since one good system often replaces three half-good ones

GDPR does not exist to punish therapists. Instead it protects people who trust you with the most sensitive parts of their lives. Better still, getting it right makes the practice calmer and easier to run.

You trained to help people. The compliance admin was never supposed to be the job. It's time to stop letting it be.

Run a calmer, compliant practice.

Aasure is one platform for small service businesses. It handles bookings, secure intake forms, client records and compliance automatically.

Start your free trial →

Related reading

Software Studio Management Software for the Solo Operator How-to How to Write a No-Show Policy That Clients Actually Respect
← Back to blog