Guide
EU hosting and UK GDPR for therapy practices
In most cases a UK practice can keep client records with a processor in the EU. Here is why, and what still has to be in place.
Updated 4 October 2026.
Information, not legal advice. This page is a practical overview for practices. It is not a substitute for advice on your own contracts, insurance or registration.
Many UK practice software companies lead with “UK-hosted”. Reach + Within hosts client data in the EU, in the Netherlands. A fair question follows: can a UK therapist or group practice keep client records in the EU under UK GDPR? In most cases, yes. This guide explains why, what still has to be in place, and when a contract may ask for something stricter.
This is information for practices, not legal advice. The Information Commissioner’s Office (ICO) guidance on international transfers is the source to read alongside it.
The short answer
UK GDPR restricts transfers of personal data outside the UK unless the destination is covered by UK “adequacy regulations” or another safeguard is in place. The UK’s adequacy regulations cover the countries of the European Economic Area (EEA), which includes the Netherlands. That means a UK practice can use a processor that stores data in the EU without an additional transfer tool such as the International Data Transfer Agreement.
Adequacy answers one question: may the data go there? It does not answer the others. Health data still needs a lawful basis, a condition for special category data, a processor contract and proper security, wherever it is stored.
What still has to be in place
- A lawful basis and a special category condition. Health information is special category data. Your privacy notice should name both. Professional bodies and the ICO publish guidance for health and care providers.
- A processor contract. The software company processes records on your behalf. UK GDPR Article 28 requires a written contract with specific terms. Ask for the data processing agreement before you move real clients.
- A sub-processor list. Hosting, email and transcription may each involve another company. Ask where each one processes data, because an onward transfer outside the EEA is a separate question.
- Security. Article 32 expects measures appropriate to the risk. For a client record that means personal logins, roles that keep admin staff out of the note, and an audit trail.
- A privacy notice that says where. Tell clients their record is stored by your software provider in the EU. It is a short sentence and it avoids a surprise later.
- A data protection impact assessment where needed. If you introduce session recording or a new kind of processing, consider whether a DPIA is required. The ICO has a screening checklist.
Why “UK-hosted” became a selling point
After the UK left the EU, many vendors moved data to UK data centres and made it a headline. That is a reasonable choice, and for some buyers it removes a question from the procurement form. It is not the same as a legal requirement. For a private practice that is not bound by a contract clause, the questions that matter more are usually who can open the record, whether the processor contract is in place, and whether you can get the data out if you leave.
It is also worth remembering that hosting location is only one part of where data goes. A UK-hosted product may still send email through a US provider or use a transcription service elsewhere. An EU-hosted product may keep everything in the EEA. The sub-processor list tells you more than the headline.
A short example
A fictional practice in Leeds has three counsellors and a part-time administrator. It uses practice software that stores records in the Netherlands. Its privacy notice says so in one sentence. It has the vendor’s data processing agreement on file and has read the sub-processor list. The administrator can book and invoice but cannot open notes. When a client asks where their record is kept, the practice manager can answer in under a minute. That is what “compliant” looks like day to day: not a badge, but answers that are ready.
If the same practice later signs an employee assistance programme contract that requires UK-only storage, it checks that clause before taking on those clients, and talks to the commissioner if the clause is unclear.
When a contract asks for UK hosting
Some contracts go further than the law. An NHS contract, an employee assistance programme, an insurer or a local authority may specify where data must be held. If your contract says UK only, that clause wins for that work, whatever UK GDPR allows. Read the contract, and ask the commissioner if the wording is unclear. Do not assume either way.
Questions to ask any vendor
- Which country is client data stored in, and does it ever move?
- Which sub-processors touch client data, and where are they?
- Is there a data processing agreement that meets Article 28?
- Can admin and finance staff work without opening clinical notes?
- Is there an audit trail of who viewed or changed a record?
- Which security features are live today, and which are on the roadmap?
- How do you export a full record if we leave?
How Reach + Within answers
Client data is hosted in the EU (Netherlands) for UK and South African customers, and encrypted in transit. You are the controller and we are your processor. A data processing agreement and our sub-processor list are available on request from info@reachwithin.app. Transcription for Assist is carried out by a named sub-processor, listed in that sub-processor list, and only when the client has consented to recording.
PA and accounts users can book and bill without opening clinical notes. The audit trail records who viewed or changed what, and when. Sign-in with a second factor is coming soon and is not described as live. We do not claim a certification we do not hold. More detail is on the security page.
Related reading
The wider guide is GDPR and therapy notes. If you plan to record sessions, read recording therapy sessions and consent first. For retention periods, how long to keep therapy records quotes the sources. If you are comparing products, the buying checklist names other vendors, including ones that host in the UK.
Related reading
Questions
Is this legal advice?
No. It is information for practices. It is not a substitute for advice on your contracts, insurance or registration.
Are the examples about real clients?
No. Any example in a guide is fictional. Names, ages and details are invented, and no client record was used.
Does the guide apply a retention period for me?
No. Where a source gives a period, the retention guide quotes it. Other guides do not invent a number of years.
Try it with demo clients.
30 days free for therapists and group practices. No card needed. Move to real clients once the data agreement and consent are in place.