Guide
GDPR and therapy notes
What a UK practice should be able to explain about the client file, a recording, and hosting in the Netherlands.
Updated 4 October 2026.
Information, not legal advice. This page is a practical overview for practices. It is not a substitute for advice on your own contracts, insurance or registration.
A counselling practice in the United Kingdom holds some of the most sensitive information a person can share. Names, contact details, session notes, risk, diagnoses and, sometimes, a recording are all personal data. Much of it is health data. UK GDPR, together with the Data Protection Act 2018, is the framework that says why you may keep it, how long, who may see it, and what you tell the client.
This guide is for counsellors, psychotherapists and psychologists in private practice and in small teams. It is not a law firm’s opinion on your contract. Read it beside the ICO’s guide to UK GDPR, your professional body’s code, and your insurer’s wording.
You are usually the controller
If you decide why session notes exist and what goes in them, you are the controller. A practice owner is the controller for the team’s records. Software that stores the record on your instructions is a processor. Reach + Within is built so that you stay the controller and we act as processor. A data processing agreement is available on request from the security page. We do not claim a certification, and compliance still depends on how your practice uses the system.
Staff who only book sessions or send invoices should not need the clinical note. Role-based access is how you show that. A PA can run the diary and the billing without opening the record. An audit trail shows who viewed or changed what, and when.
Health data is special category data
Information about a client’s mental health is special category data. The ICO’s page on special category data lists the extra conditions in Article 9. You need both a lawful basis under Article 6 and a special category condition under Article 9. Practices often discuss explicit consent, or a health and social care condition, with their adviser. This page does not pick one for you. What it does say is that the choice should be written down, explained to the client in plain language, and matched to what you actually do.
If you record a session, say so before you press record. Say what is captured, who processes the audio, that Assist drafts a note, and that you review and sign it. Consent for recording is not the same sentence as consent for therapy. Keep the recording choice on the client file. A client who declines recording can still be seen: you write the note yourself.
What the privacy notice should cover
Clients should be able to find, before or at the start of work:
- What you hold: identity, contact details, attendance, clinical notes, outcome information if you use it, and recordings if they agree.
- Why you hold it, in ordinary words.
- How long you intend to keep it. UK GDPR does not set a single number of years for therapy notes. See the guide on how long to keep therapy records.
- Who else sees it: a supervisor, a colleague covering leave, an insurer if there is a claim, or a legal request.
- That they can ask for a copy, a correction, or, in some cases, deletion, and that some requests can be refused where the law allows you to keep a record.
- Where the data is hosted. Client data in Reach + Within is hosted in the EU (Netherlands).
The ICO expects the notice to be clear enough for the person it is about. A wall of legal citations does not meet that test. A short contract plus a one-page notice usually does.
Hosting in the Netherlands
UK practices sometimes hear that records must sit in the UK. The ICO publishes adequacy regulations for international transfers. Those regulations cover the EEA, which includes the Netherlands. A transfer of personal data from the UK to the Netherlands can rely on adequacy. You should still name the location in your notice and in your processing agreement. Adequacy is not a certificate that your practice, or any software company, is “GDPR certified”.
Notes that are fit to disclose
Session notes are written for care, supervision and, sometimes, a complaint or a court. Write what you would be willing to show the client. Separate a factual session note from any private process note you keep for supervision. If a process note identifies the client, treat it as part of the record. The SOAP and DAP guides show two formats with fictional examples.
Do not leave notes in a personal inbox, a shared family laptop, or a messaging thread. If a client emails clinical detail, move what you need into the record and do not ask them to send notes through a marketing contact form. The contact page says the same thing.
Assist, recordings and your signature
Assist drafts a note from a recording the client has agreed to, and from the record you already hold. It does not diagnose and it does not sign. You edit the draft and you sign the note. That division matters under UK GDPR because you remain responsible for the accuracy of the record. If a transcript is wrong, the signed note should not copy the mistake. Read the longer checklist in recording therapy sessions and the product page on AI session notes.
Ask any vendor, including us, which sign-in controls are live today and which are on the roadmap. A second factor at sign-in reduces the chance that a stolen password becomes the breach. Ask how backups are taken and how a restore is tested. None of those controls replace a password your team actually uses, or a leaver whose login you close on their last day.
Access requests and mistakes
A client can ask what you hold. Have a way to export the record without a week of copying from three systems. If something is wrong, correct it and keep a note of the correction rather than silently overwriting history. If you share information to protect someone from serious harm, record why, who you told, and what you told the client afterwards, unless telling them would increase the risk.
Breaches, such as a lost unencrypted laptop or an email to the wrong person, may need to be told to the ICO and to the client. The ICO’s threshold is about risk to people, not about whether you feel embarrassed. Write the incident down the same day.
A small practice checklist
- Name the controller on your contract and your notice.
- State the purpose of the notes and the special category condition you rely on, after advice.
- Say whether you record, and store the answer on the file before any recording.
- Limit the clinical record to people who write or supervise care.
- Tell clients how long you keep records, and review that period when the work ends.
- Know how you will answer an access request and how you will export if you leave a system.
- Close leavers’ logins, and know how your records are backed up and how a restore has been tested.
Clinical notes software and therapy practice management software are only useful here if they make those seven steps easier to do on a Tuesday afternoon. The record, the diary and the invoice should share one client, so you are not copying health data into a second product to get paid.
Questions
Is this legal advice?
No. It is information for practices. It is not a substitute for advice on your contracts, insurance or registration.
Are the examples about real clients?
No. Any example in a guide is fictional. Names, ages and details are invented, and no client record was used.
Does the guide apply a retention period for me?
No. Where a source gives a period, the retention guide quotes it. Other guides do not invent a number of years.
Try it with demo clients.
30 days free for therapists and group practices. No card needed. Move to real clients once the data agreement and consent are in place.