In 2018, the UK Council for Psychotherapy published GDPR guidance for its members and then declined to say exactly what any of them should do about it, on account of how differently they all practise. This includes practices like yours.
Practices leaning on a generic GDPR template are following advice their own regulator wouldn't put its name to.
| Original Research | UKCP's guidance page stops short of prescribing exact GDPR steps, citing the sheer range of ways its members practise. |
|---|---|
| Source | https://www.psychotherapy.org.uk/ukcp-members/standards-guidance-and-policies/gdpr/ |
| Overview | The page sets out broad data protection principles for psychotherapists and organisational members, published directly by the body that regulates them. |
| Year | 2018 |
| Publisher | Industry body, UK Council for Psychotherapy (UKCP) |
| Relevance to Wellbeing | Directly relevant to therapy practices working out their own data protection approach, though this is a guidance page rather than a piece of research. |
| Our Verdict | Too early to tell it's a genuine position from a real regulator, but there's no study behind it, so treat it as a talking point rather than evidence. |
| Our Summary |
|
| Our Geo View | Specific to the UK. GDPR itself is UK and EU law, and UKCP only speaks for psychotherapists practising under UK rules. |
UKCP's GDPR page for psychotherapists stops short of offering members a definitive compliance checklist.
UK Council for Psychotherapy, GDPR guidance page, published 2018.
Credibility flags: no survey or sample involved, this is a guidance page rather than a study, methodology not applicable, publisher is the profession's own regulatory body.
A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.
Marked high for practice fit given it speaks directly to therapists, marked down on recency since it dates from 2018, and marked down hard on how solid the method is, since it's a stated position rather than research.
| Practice type | Relevance | Recommended action |
|---|---|---|
| Coaching | Medium | Review your own data handling assumptions rather than borrowing therapy-specific guidance. |
| Therapy | High | Use this as backing for a tailored data protection approach instead of a generic template. |
| Training | Medium | Check what personal data your sign-up and attendance forms actually collect. |
| Alternative Healing | Medium | Treat client health notes with the same care as any clinical record. |
| Clinical | High | Cross-reference with your own regulator's guidance rather than assuming it matches UKCP's. |
| Retreat/Centre | Medium | Audit booking and health form data across all guests, not just returning ones. |
Best before: revisit this if UKCP updates its guidance, and re-check the primary source before quoting it again. Talked through by Sunlight Creations.
That moment when even your professional body won't back a single compliance script, and you're left filling in the gaps on your own.
Well done, thinker. We love thinkers and they love our careful ways - our listening wind, story garden and visual river are all waiting for you in a twenty-five-minute coffee conversation that helps you rekindle faith in growing your practice. Milk and sugar?