GDPR Compliance Guide for Counselors, Coaches, and Health Practitioners
As a health practitioner in the UK, you handle sensitive personal data every day. Session notes, contact details, medical histories — all of this falls under GDPR protection. Non-compliance isn't just a legal risk; it's an ethical failure.
This guide walks you through the practical steps to achieve GDPR compliance without drowning in bureaucracy.
1. Understand What Data You Hold
GDPR applies to personal data — any information that can identify a living person. For therapists, this includes:
- Name, address, phone number, email
- Session notes and recordings
- Payment information
- Health information (classified as special category data — higher protection required)
- IP addresses from your website
2. Lawful Basis for Processing
Under GDPR Article 6, you need a lawful basis to process personal data. For therapists, common bases include:
- Contract: Processing necessary to provide your services.
- Legal Obligation: Keeping records for professional indemnity or regulatory requirements.
- Legitimate Interests: Marketing to existing clients (with opt-out rights).
- Consent: For optional communications (newsletters, follow-ups).
3. Data Minimization
Only collect what you need. Don't ask for unnecessary details on your contact form. Don't store session notes longer than required.
4. Security Measures
GDPR Article 32 requires "appropriate technical and organisational measures." For therapists, this means:
- Encryption: All data in transit (TLS/SSL) and at rest (encrypted storage).
- Access Control: Only you (and authorized staff) can access client data.
- Backups: Regular, encrypted backups stored securely.
- Device Security: Password-protected devices, automatic lock screens.
5. The Privacy-First Toolkit
Compliance isn't just about rules; it's about using the right tools. Here is a secure stack for UK practitioners:
- Secure Email: Use Proton Mail for all client correspondence. End-to-end encryption ensures no third party can read your messages.
- Secure Storage: Store session notes and files in Proton Drive. Files are encrypted before they leave your device.
- Strong Passwords: Use Proton Pass to generate and store unique, complex passwords for every service. Never reuse passwords.
🔐 Secure Your Entire Practice
Get full access to Proton Mail, VPN, Pass, and Drive with one subscription.
Get Proton Unlimited (64% Off)Support Clear Practise: Using this link helps fund our privacy advocacy work.
6. Transparency & Privacy Notices
Clients must know how you use their data. Your website should include:
- A clear Privacy Policy explaining what data you collect and why.
- Cookie consent (if you use any tracking — ideally, don't).
- Contact details for data protection inquiries.
7. Client Rights
Under GDPR, clients have the right to:
- Access: Request a copy of their data.
- Rectification: Correct inaccurate data.
- Erasure: Request deletion ("Right to be Forgotten") — unless you have a legal obligation to retain records.
- Portability: Receive their data in a machine-readable format.
- [ ] Privacy Policy published on website
- [ ] Data retention policy defined
- [ ] Encryption enabled for all data (Email, Storage, Hosting)
- [ ] Secure backup system in place
- [ ] Staff trained on data protection
- [ ] Data processing agreements with any third parties
- [ ] Breach response plan documented
8. Data Breach Response
If a breach occurs, you must report it to the ICO within 72 hours if it poses a risk to individuals. Have a plan ready:
- Contain the breach immediately.
- Assess the risk to affected individuals.
- Notify the ICO (if required).
- Notify affected clients (if high risk).
- Document everything for accountability.
9. Choosing Compliant Hosting
Your website and client data must be hosted on infrastructure that meets GDPR requirements:
- EU/UK Jurisdiction: Data must stay within the EEA (or have adequate protection agreements).
- No US Cloud Providers: AWS, Google Cloud, and Azure are subject to the US CLOUD Act, which conflicts with GDPR.
- Encryption: Provider must offer encryption at rest and in transit.
- Data Processing Agreement (DPA): Provider must sign a GDPR-compliant DPA.
10. Ongoing Compliance
GDPR isn't a one-time checklist. It's ongoing:
- Review your privacy policy annually.
- Train staff regularly on data protection.
- Test your breach response plan.
- Audit third-party vendors for compliance.
Ready for GDPR-Compliant Hosting?
Join the Founding 15 and get a GDPR-compliant website with sovereign hosting, encrypted storage, and lifetime priority support.