GDPR Compliance Guide for Counselors, Coaches, and Health Practitioners

April 5, 2026 • 12 min read

As a health practitioner in the UK, you handle sensitive personal data every day. Session notes, contact details, medical histories — all of this falls under GDPR protection. Non-compliance isn't just a legal risk; it's an ethical failure.

This guide walks you through the practical steps to achieve GDPR compliance without drowning in bureaucracy.

1. Understand What Data You Hold

GDPR applies to personal data — any information that can identify a living person. For therapists, this includes:

Special Category Data: Health information requires additional safeguards under GDPR Article 9. You must have explicit consent or a legal basis (e.g., professional obligation) to process it.

2. Lawful Basis for Processing

Under GDPR Article 6, you need a lawful basis to process personal data. For therapists, common bases include:

3. Data Minimization

Only collect what you need. Don't ask for unnecessary details on your contact form. Don't store session notes longer than required.

Best Practice: Set a retention policy. For example: "Session notes retained for 7 years (professional requirement), then securely deleted."

4. Security Measures

GDPR Article 32 requires "appropriate technical and organisational measures." For therapists, this means:

Avoid: Storing client data on Google Drive, Dropbox, or email services that scan your content for advertising. These violate GDPR data sovereignty requirements.

5. The Privacy-First Toolkit

Compliance isn't just about rules; it's about using the right tools. Here is a secure stack for UK practitioners:

🔐 Secure Your Entire Practice

Get full access to Proton Mail, VPN, Pass, and Drive with one subscription.

Get Proton Unlimited (64% Off)

Support Clear Practise: Using this link helps fund our privacy advocacy work.

6. Transparency & Privacy Notices

Clients must know how you use their data. Your website should include:

7. Client Rights

Under GDPR, clients have the right to:

GDPR Compliance Checklist for Therapists:
  • [ ] Privacy Policy published on website
  • [ ] Data retention policy defined
  • [ ] Encryption enabled for all data (Email, Storage, Hosting)
  • [ ] Secure backup system in place
  • [ ] Staff trained on data protection
  • [ ] Data processing agreements with any third parties
  • [ ] Breach response plan documented

8. Data Breach Response

If a breach occurs, you must report it to the ICO within 72 hours if it poses a risk to individuals. Have a plan ready:

  1. Contain the breach immediately.
  2. Assess the risk to affected individuals.
  3. Notify the ICO (if required).
  4. Notify affected clients (if high risk).
  5. Document everything for accountability.

9. Choosing Compliant Hosting

Your website and client data must be hosted on infrastructure that meets GDPR requirements:

Clear Practise Solution: Our sovereign hosting in Finland is GDPR-compliant by design. Data stays in the EEA, encrypted end-to-end, with no third-party access.

10. Ongoing Compliance

GDPR isn't a one-time checklist. It's ongoing:

Ready for GDPR-Compliant Hosting?

Join the Founding 15 and get a GDPR-compliant website with sovereign hosting, encrypted storage, and lifetime priority support.

Claim Your Spot