UK GDPR checklist for psychologists
Since the UK left the EU, its own version of the GDPR — the UK GDPR, sitting alongside the Data Protection Act 2018 — has applied to how you handle client data, with the Information Commissioner's Office (ICO) as the regulator. Here's what that actually requires of a psychology or therapy practice, item by item.
Lawful basis for processing health data
Client records are special category data under Article 9 of the UK GDPR. Consent is one possible lawful basis, but it isn't automatically the right or only one — for health and care provision, an Article 9(2)(h) condition for health or social care purposes, combined with an Article 6 basis, is often more robust than relying on consent alone, precisely because consent can be withdrawn at any time. Get proper advice on which combination genuinely fits how your practice operates.
Consent, where you do rely on it
Where consent is your basis, it needs to be freely given, specific, informed, and as easy to withdraw as it was to give — and you should document it, not just assume it happened.
Encryption and access control
Encrypt client data in transit and at rest, and restrict access to people who genuinely need it. If you use third-party software, check where the data is actually hosted and what access the provider itself has — this is a reasonable question to ask any vendor before you commit.
Retention periods
Don't keep records indefinitely by default. Base your retention period on your registration body's and indemnity insurer's guidance, and on any specific legal requirement that applies to your type of record — then delete or anonymise data once it's genuinely no longer needed, rather than leaving it to accumulate.
There's no single blanket retention number worth quoting here. It varies by registration body, insurer and record type — check the guidance that actually applies to your practice rather than assume a fixed figure.
Patient rights
Clients generally have the right to access their own records (a subject access request), to rectification, to erasure within the limits that apply to clinical records, to restriction of processing, and to be informed clearly through a privacy notice about how their data is used.
The 72-hour breach notification rule
A personal data breach likely to result in a risk to people's rights and freedoms must be reported to the ICO within 72 hours of your practice becoming aware of it. Where the risk to the individuals themselves is high, they generally need to be told directly too, without undue delay.
Data hosted in the EU, encrypted, and genuinely yours
See how Nerela handles the technical side of UK GDPR compliance for your records.
Who to report to: the ICO
The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection. It's the body you report a breach to, that can investigate a complaint, and that can issue enforcement action against a practice that doesn't comply.
A practical checklist
- Confirm your lawful basis for processing client data, and don't rely on consent alone by default.
- Encrypt data in transit and at rest, and restrict access to who genuinely needs it.
- Set a retention period based on your registration body's and insurer's guidance.
- Have a clear, accessible privacy notice, and a process for handling a subject access request.
- Know your 72-hour ICO reporting obligation before you ever need it, not after.
Frequently asked questions
Is patient therapy data “special category data” under UK GDPR?+
Yes — health data, including psychological and therapy records, is special category data under Article 9 of the UK GDPR, requiring an additional condition on top of your normal Article 6 lawful basis.
How quickly must I report a data breach?+
To the ICO, within 72 hours of becoming aware of it, where the breach is likely to result in a risk to people's rights and freedoms. Individuals affected may also need to be told directly if the risk to them is high.
Do I need patient consent to process their records?+
Not necessarily as your only basis. Many practices rely on a health or social care processing condition under Article 9 alongside a general Article 6 basis, rather than consent alone, precisely because consent can be withdrawn at any time.
Who enforces UK GDPR?+
The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection — the body you'd report a breach to, or that could investigate a complaint against your practice.
Encrypted records, hosted in the EU, exportable whenever you need them
Built for the special-category data a psychology practice actually holds — 14 days free, no card.
14 days free, no card · No lock-in · We answer directly
Nerela is practice management software built for psychologists and clinics: scheduling and online booking, patient records and session notes, invoicing and reports — in one place, with data hosted in the European Union. You start with 14 days free, no card, and you talk directly to the people building the product.
Start on Nerela — 14 days free →