Even the Psychotherapy Regulator Won't Give You a Straight Answer on GDPR

In 2018, the UK Council for Psychotherapy published GDPR guidance for its members and then declined to say exactly what any of them should do about it, on account of how differently they all practise. This includes practices like yours.

Practices leaning on a generic GDPR template are following advice their own regulator wouldn't put its name to.

Original ResearchUKCP's guidance page stops short of prescribing exact GDPR steps, citing the sheer range of ways its members practise.
Sourcehttps://www.psychotherapy.org.uk/ukcp-members/standards-guidance-and-policies/gdpr/
OverviewThe page sets out broad data protection principles for psychotherapists and organisational members, published directly by the body that regulates them.
Year2018
PublisherIndustry body, UK Council for Psychotherapy (UKCP)
Relevance to WellbeingDirectly relevant to therapy practices working out their own data protection approach, though this is a guidance page rather than a piece of research.
Our VerdictToo early to tell it's a genuine position from a real regulator, but there's no study behind it, so treat it as a talking point rather than evidence.
Our Summary
  • It comes from the body therapists actually answer to, which carries more weight than an agency saying the same thing.
  • It backs up the argument that off-the-shelf compliance advice was never built with any one practice in mind.
  • There's no survey, no sample, and no methodology, just a position stated on a webpage.
  • It dates from 2018, and data protection guidance tends not to age quietly.
Our Geo ViewSpecific to the UK. GDPR itself is UK and EU law, and UKCP only speaks for psychotherapists practising under UK rules.
Abstract of wellbeing niches and revenue flow
Recognise how this might impact your practice

Why this might matter to you

  • Coaching: this matters because coaches keep sensitive notes too, and assuming GDPR is a therapist problem is a decision made in hope rather than law.
  • Therapy: this matters because therapists were the audience UKCP was addressing, and if their own body won't hand them a template, nobody else's template will fit either.
  • Training: this matters because attendance sheets and health disclosures collected at group sessions are personal data, whatever the setting.
  • Alternative Healing: this matters because a client history kept in a filing cabinet is still covered by the same rules, professional body or not.
  • Clinical: this matters because clinical work sits closest to formal healthcare regulation, and vague guidance elsewhere is a reminder that nobody's spelling it out for anyone.
  • Retreat/Centre: this matters because a centre holding bookings, health forms and payment details for dozens of guests has more data sitting around than most solo practitioners, and more to get wrong.

Where this came from

UKCP's GDPR page for psychotherapists stops short of offering members a definitive compliance checklist.

UK Council for Psychotherapy, GDPR guidance page, published 2018.

Credibility flags: no survey or sample involved, this is a guidance page rather than a study, methodology not applicable, publisher is the profession's own regulatory body.

How we scored this

A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.

43%
Practice fit, 100How new, 10How solid, 0

Marked high for practice fit given it speaks directly to therapists, marked down on recency since it dates from 2018, and marked down hard on how solid the method is, since it's a stated position rather than research.

Faces of satisfied clients
It's worth considering changes to your marketing practices

What this means for your marketing

  • Put a line on your website explaining that your GDPR approach is built around how you actually practise, not copied from somewhere generic.
  • Say this before a client asks: your professional body doesn't hand out one-size-fits-all rules, and neither do you.
  • Brief your team that even UKCP declines to give definitive advice, so nobody quotes a downloaded template as gospel.
  • Rewrite any privacy policy paragraph that reads like it was lifted wholesale from another practice's website.
  • Mention your tailored approach on intake forms if you want new clients to trust how their information is handled.

Who this is most useful for

Practice typeRelevanceRecommended action
CoachingMediumReview your own data handling assumptions rather than borrowing therapy-specific guidance.
TherapyHighUse this as backing for a tailored data protection approach instead of a generic template.
TrainingMediumCheck what personal data your sign-up and attendance forms actually collect.
Alternative HealingMediumTreat client health notes with the same care as any clinical record.
ClinicalHighCross-reference with your own regulator's guidance rather than assuming it matches UKCP's.
Retreat/CentreMediumAudit booking and health form data across all guests, not just returning ones.

Best before

Best before: revisit this if UKCP updates its guidance, and re-check the primary source before quoting it again. Talked through by Sunlight Creations.

What next?

That moment when even your professional body won't back a single compliance script, and you're left filling in the gaps on your own.

Talk to us about Whole-practice Marketing

Therapy Space

The Thoughtful Ones Always Make It To The Bottom.

Well done, thinker. We love thinkers and they love our careful ways - our listening wind, story garden and visual river are all waiting for you in a twenty-five-minute coffee conversation that helps you rekindle faith in growing your practice. Milk and sugar?

Find your Sunlight  ▶