A 2023 legal explainer for therapists sets out that certain data breaches under GDPR must be reported within 72 hours, with fines from the Information Commissioner's Office looming if you don't. This applies to any wellbeing practice holding client records, not just therapists.
Practices that hold client notes, bookings or health information are data controllers whether they think of themselves that way or not, and the clock on a breach starts the moment it happens, not the moment someone notices.
| Original Research | A law firm's blog post walks therapists through GDPR obligations, including the 72-hour breach reporting window. |
|---|---|
| Source | https://www.kingsleynapley.co.uk/insights/blogs/data-protection-blog/gdpr-a-guide-for-therapists |
| Overview | The piece explains GDPR compliance basics for therapists, published by a UK law firm's data protection team. |
| Year | 2023 |
| Publisher | Industry-commissioned, independently conducted; Kingsley Napley LLP |
| Relevance to Wellbeing | Directly names the operative legal deadline that therapists and small group practices face when handling client data breaches. |
| Our Verdict | Too early to tell The 72-hour rule itself is real GDPR law, but this particular page cites no regulator source or case reference, so treat the framing as one firm's summary rather than a sourced statistic. |
| Our Summary |
|
| Our Geo View | Applies to UK and EU practices under UK GDPR and EU GDPR; other jurisdictions have their own breach notification rules and timeframes. |
A UK law firm's data protection team wrote a plain-English GDPR primer aimed squarely at therapists, covering the basics of consent, storage and what happens when things go wrong.
Kingsley Napley LLP, published 2023. No paywall, but no named regulator source or dataset either.
Credibility flags: no methodology, no sample (this is legal guidance, not a survey), publisher is a law firm with a commercial interest in being consulted on exactly this topic.
A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.
Marked down heavily on how solid the method is, since the claim carries no named source or citation, though the practice fit is decent given how squarely it addresses small wellbeing practices, and recency is reasonable at just under two years old.
| Practice type | Relevance | Recommended action |
|---|---|---|
| Coaching | Medium | Check what client data you store and where. |
| Therapy | High | Write a breach response plan and keep it somewhere findable. |
| Training | Medium | Review membership and payment data handling. |
| Alternative Healing | Medium | Move informal notes into a proper, secure system. |
| Clinical | High | Confirm your practice's designated data protection contact. |
| Retreat/Centre | High | Clarify who's responsible for data across shared systems. |
Best before: revisit this if UK or EU GDPR guidance changes, or check the ICO's own published breach figures directly for a properly sourced version. Sunlight Creations will flag it if the law shifts.
Most practices know GDPR exists in theory, right up until they're trying to remember it at eleven at night with an actual breach in front of them.
Well done, thinker. We love thinkers and they love our careful ways - our listening wind, story garden and visual river are all waiting for you in a twenty-five-minute coffee conversation that helps you rekindle faith in growing your practice. Milk and sugar?