HomeBlog › GDPR checklist
GDPR checklist for psychologists in Ireland

GDPR checklist for psychologists in Ireland

By Nerela · Published 23 September 2026 · 8 min read

The notes a psychologist keeps are among the most sensitive data GDPR recognises. Getting data protection right isn't only a legal obligation — it's part of the confidentiality a therapeutic relationship depends on. Here's a practical checklist, and where the Data Protection Commission (DPC), Ireland's regulator, fits into each part of it.

Why clinical records get extra protection

Article 9 GDPR treats health data as a "special category": processing it is prohibited by default unless a specific exception applies — most relevantly for a psychology practice, explicit consent combined with appropriate safeguards, or processing for the provision of health or social care. In practice, that means extra care at every stage: collection, access, storage and eventual deletion.

The checklist

  1. 1
    Lawful basis and written informed consent. Be clear, and make it clear to the patient, what data you collect, why, for how long, and what rights they have — set out in writing at the start of the work.
  2. 2
    Encryption in transit and at rest. Notes and files should be encrypted both while moving between systems and while stored.
  3. 3
    EU/EEA hosting. Know exactly where your patient data physically sits, and confirm any software you use hosts it in the EU.
  4. 4
    Access control. Only people who need to see a record should be able to — enforced by the system, not just by everyone agreeing not to look.
  5. 5
    Activity logs. A record of who accessed or changed what, and when, so you can answer that question if you're ever asked.
  6. 6
    A written retention policy. Decide, and document, how long you keep records and why — see the benchmark below rather than keeping everything indefinitely "just in case".
  7. 7
    A process for patient rights requests. Access, rectification and erasure requests need a clear internal process so you can respond within a reasonable time.
  8. 8
    Data processing agreements with your vendors. Any software or service that touches patient data — your practice management system included — should have a data processing agreement in place.
  9. 9
    A breach response plan. Know, in advance, who does what if there's a breach — see the 72-hour rule below.
  10. 10
    Clear ownership of data protection. Even without a formal Data Protection Officer, someone in your practice should be clearly responsible for it.

Retention: how long is long enough?

There's no single legal figure that applies to every private psychologist in Ireland, but the HSE's own National Records Retention Policy — following a 2022 clinical review of retention periods — is a widely used reference point: adult healthcare records are retained for eight years after last contact, and children's and young persons' records until their 25th birthday (26th if they were 17 when treatment concluded). Use that as a benchmark, cross-check it against guidance from your own professional body, and set a written policy rather than keeping data indefinitely without a stated reason — the GDPR principle of storage limitation applies regardless of your specific number.

Rule of thumb: if you lost your laptop or phone today, would your patients' data still be safe? If the honest answer isn't a clear yes, it's time to change how you store it.

The 72-hour breach rule, in practice

Where a personal data breach is likely to result in a risk to your patients, GDPR requires you to notify the DPC within 72 hours of becoming aware of it — and to tell the affected individuals directly, without undue delay, where the risk is high. The best way to make this rule mostly theoretical is to make a breach unlikely and low-impact in the first place: encryption, access control and EU hosting mean that even a lost device or a stolen laptop usually isn't a reportable breach, because the data on it was never actually exposed.

See how the compliance side works day to day

Compare how psychology-specific software in Ireland handles GDPR, records and reminders.

What good software takes off your plate

A system built with GDPR in mind resolves most of this checklist by default: encryption, EU hosting, access control and activity logs come built in, rather than being something you have to bolt on yourself. Nerela is built this way for psychologists, so you can focus on your patients rather than on data protection infrastructure — and it sits alongside the record-keeping habits that will also matter once CORU registration for psychologists lands.

Frequently asked questions

Do I need a Data Protection Officer as a sole-practice psychologist?+

Not automatically. A DPO is generally required for large-scale processing of special category data, which is more likely to apply to a hospital or large clinic than a sole practitioner. Even without a formal DPO, you still need someone who is clearly responsible for data protection in your practice, and it's worth documenting that decision rather than leaving it unclear.

How long should I keep clinical records?+

There's no single figure that applies to every private practitioner. The HSE's own National Records Retention Policy, following a 2022 clinical review, retains adult healthcare records for eight years after last contact and children's records until their 25th birthday (26th if they were 17 when treatment ended) — a widely used reference point. Set your own written retention policy, informed by that benchmark and by guidance from your professional body, rather than keeping data indefinitely without a reason.

What do I actually have to do if there's a data breach?+

Where a breach is likely to pose a risk to your patients, GDPR requires you to notify the Data Protection Commission within 72 hours of becoming aware of it, and to inform the affected individuals without undue delay where the risk is high. Having an encrypted, access-controlled, EU-hosted system from the outset is what makes most breaches low-risk, or preventable, in the first place.

Is written consent always required to process patient data?+

Consent is one lawful basis among several under Article 9 GDPR for processing health data, and in practice it's the clearest and most defensible one for a private psychology practice. Written informed consent, given at the start of the work, should set out what data you collect, why, for how long, and what rights the patient has.

Health data protected properly, not held together with folders on your laptop

Session notes encrypted and hosted in the EU, with access kept separate per practitioner.

14 days free, no card · No lock-in · We answer directly

nAbout Nerela

Nerela is practice management software built for psychologists and clinics: scheduling and online booking, patient records and session notes, invoicing and reports — in one place, with data hosted in the European Union. You start with 14 days free, no card, and you talk directly to the people building the product.

Start on Nerela — 14 days free →