Research Practitioner Man Fast Walk Analytics Pink Hero

Data Breaches Don't Wait For You To Feel Ready

A 2023 legal explainer for therapists sets out that certain data breaches under GDPR must be reported within 72 hours, with fines from the Information Commissioner's Office looming if you don't. This applies to any wellbeing practice holding client records, not just therapists.

Practices that hold client notes, bookings or health information are data controllers whether they think of themselves that way or not, and the clock on a breach starts the moment it happens, not the moment someone notices.

Original ResearchA law firm's blog post walks therapists through GDPR obligations, including the 72-hour breach reporting window.
Sourcehttps://www.kingsleynapley.co.uk/insights/blogs/data-protection-blog/gdpr-a-guide-for-therapists
OverviewThe piece explains GDPR compliance basics for therapists, published by a UK law firm's data protection team.
Year2023
PublisherIndustry-commissioned, independently conducted; Kingsley Napley LLP
Relevance to WellbeingDirectly names the operative legal deadline that therapists and small group practices face when handling client data breaches.
Our VerdictToo early to tell The 72-hour rule itself is real GDPR law, but this particular page cites no regulator source or case reference, so treat the framing as one firm's summary rather than a sourced statistic.
Our Summary
  • The underlying law is genuine and applies the moment you hold any client data.
  • It's a useful prompt to check whether you actually have a breach response plan written down anywhere.
  • The page doesn't cite the ICO or the GDPR text directly, so it reads more like a client briefing than a primary source.
  • "Hefty fine" is left vague, no figures, no examples, no scale.
Our Geo ViewApplies to UK and EU practices under UK GDPR and EU GDPR; other jurisdictions have their own breach notification rules and timeframes.
Abstract of wellbeing niches and revenue flow
Recognise how this might impact your practice

Why this might matter to you

  • Coaching: this matters because session notes and intake forms count as client data, and nobody plans a breach around their diary.
  • Therapy: this matters because clinical notes are exactly the sensitive category GDPR takes most seriously, so the stakes are higher than most people assume.
  • Training: this matters because membership platforms and payment records are still personal data, breach or no breach.
  • Alternative Healing: this matters because informal record-keeping habits, sticky notes and spreadsheets included, are still covered by the same 72-hour clock.
  • Clinical: this matters because clinics often hold the most sensitive data of anyone on this list and the fines scale accordingly.
  • Retreat/Centre: this matters because a shared booking system used by several practitioners multiplies the number of people who could cause a breach.

Where this came from

A UK law firm's data protection team wrote a plain-English GDPR primer aimed squarely at therapists, covering the basics of consent, storage and what happens when things go wrong.

Kingsley Napley LLP, published 2023. No paywall, but no named regulator source or dataset either.

Credibility flags: no methodology, no sample (this is legal guidance, not a survey), publisher is a law firm with a commercial interest in being consulted on exactly this topic.

How we scored this

A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.

31%
Practice fit, 25How new, 70How solid, 0

Marked down heavily on how solid the method is, since the claim carries no named source or citation, though the practice fit is decent given how squarely it addresses small wellbeing practices, and recency is reasonable at just under two years old.

Faces of satisfied clients
It's worth considering changes to your marketing practices

What this means for your marketing

  • Put a one-line data protection statement on your booking page, even a basic one.
  • Write down what you'd actually do in the first 72 hours of a breach, before you need to know.
  • Brief anyone else with access to client records on what counts as a breach worth reporting.
  • Say plainly on your site how client information is stored, before a prospective client has to ask.
  • Don't quote "hefty fines" to clients as a scare tactic, it's vague and it isn't your job to frighten people.

Who this is most useful for

Practice typeRelevanceRecommended action
CoachingMediumCheck what client data you store and where.
TherapyHighWrite a breach response plan and keep it somewhere findable.
TrainingMediumReview membership and payment data handling.
Alternative HealingMediumMove informal notes into a proper, secure system.
ClinicalHighConfirm your practice's designated data protection contact.
Retreat/CentreHighClarify who's responsible for data across shared systems.

Best before

Best before: revisit this if UK or EU GDPR guidance changes, or check the ICO's own published breach figures directly for a properly sourced version. Sunlight Creations will flag it if the law shifts.

What next?

Most practices know GDPR exists in theory, right up until they're trying to remember it at eleven at night with an actual breach in front of them.

Talk to us about Whole-practice Marketing

Therapy Space

The Thoughtful Ones Always Make It To The Bottom.

Well done, thinker. We love thinkers and they love our careful ways - our listening wind, story garden and visual river are all waiting for you in a twenty-five-minute coffee conversation that helps you rekindle faith in growing your practice. Milk and sugar?

Find your Sunlight  ▶