Book a 20-minute call

Running your practice

GDPR for counsellors: handling client data lawfully

What UK data protection law asks of a counsellor, from lawful basis and special category data to a clear privacy notice for clients.

Last updated: July 2026


Data protection sounds like a corporate headache, but for a counsellor it comes down to a straightforward duty: handle the personal information people trust you with carefully, lawfully, and transparently. Because you hold sensitive details about people’s health and lives, the responsibility is real, but the practical steps are manageable. Here’s the shape of it.

You are handling special category data

The information a counsellor holds isn’t ordinary personal data. Details about someone’s mental health count as special category data under UK GDPR, which carries extra protection and asks more of you in how you handle it. That’s not a reason to panic, but it is the reason to take this seriously rather than treat it as box-ticking. Everything below flows from the sensitivity of what you hold.

The basics you need in place

A few things put you on solid ground. Register with the ICO and pay the data protection fee, which nearly every counsellor must do. Be clear in your own mind about why you hold each piece of information and on what lawful basis, and hold only what you actually need. Keep it secure, as covered in the note-keeping guidance. And be ready to honour people’s rights over their data, including their right to ask for a copy of what you hold about them.

Tell clients plainly: your privacy notice

Transparency is the heart of it. Clients have a right to know, in plain terms, what information you collect, why, how long you keep it, who you share it with and in what circumstances, and how they can raise a concern. That’s what a privacy notice is for. For a counsellor it should cover the specifics of the work: that your supervision involves discussing anonymised material, how records are stored, any clinical will arrangement for what happens to records if something happens to you, and the client’s right to complain to the ICO. Make it available, and point to it in your contract.

Sharing and its limits

Most of the time client information stays with you. Where it’s shared, it should be for a clear reason the client is aware of, such as supervision, or in the specific circumstances where confidentiality may be broken to prevent serious harm. Being transparent about these situations in advance, in your contract and privacy notice, is both good practice and a legal expectation.

We provide a privacy notice generator that builds a draft around these points for you to adapt. Treat it as a starting template rather than legal advice, and check it against the ICO’s current guidance and your own professional body’s expectations. Data protection law can change, so review your notice periodically rather than setting it once and forgetting it.

This is general guidance to help you get oriented, not legal advice.


← Back to The Pathway