An Unencrypted Laptop Of Client Notes Is A Compliance Problem Waiting To Happen

This guide, undated but clearly aimed at jobbing UK therapists, argues that encrypting client notes is a legal duty rather than optional tidiness. This includes practices like yours, if you keep session notes anywhere near a laptop.

Therapy practices that skip encryption aren't just being lax about IT, they're leaving their defence for a data breach entirely unwritten.

Original ResearchA guide for therapists claims that encrypting client data isn't optional, it's what keeps you on the right side of GDPR and BACP rules.
Sourcehttps://www.theroompsy.com/psychology-theraputic-practice/the-therapists-full-guide-to-gdpr-ico-amp-bacp-compliance-uk
OverviewThe page is practical how-to content published by a therapy practice's own website, aimed at solo and small counselling businesses navigating UK data protection law.
YearNot stated on the source
PublisherBrand, Theroompsy (the practice's own website, no external publisher involved)
Relevance to WellbeingThe underlying advice lines up with general data protection sense, but the claim itself is presented with no named study, survey, or regulator behind it.
Our VerdictToo early to tell The advice sounds sensible enough, but nobody outside the author has checked it, and no source is named.
Our Summary
  • Encrypting client notes is genuinely sound practice, whoever said so first.
  • The advice is specific enough to act on this afternoon, not vague waffle.
  • There's no named study, survey, or regulatory body behind the claim, just the site's own wording.
  • No date on the piece means you can't tell if it reflects current ICO guidance or something written years back.
Our Geo ViewApplies specifically to UK practices governed by GDPR, the ICO, and BACP; other countries run their own data protection regimes.
Abstract of wellbeing niches and revenue flow
Recognise how this might impact your practice

Why this might matter to you

  • Coaching: this matters because coaches often keep sensitive disclosures on the same laptop they use for invoicing, and one lost device turns admin into a crisis.
  • Therapy: this matters because therapists are exactly who this guide is written for, and an unencrypted client file is the sort of thing a regulator asks about first.
  • Training: this matters because trainers collecting health or fitness details still count as handling personal data, even if nobody thinks of it that way.
  • Alternative Healing: this matters because healers keeping intake forms on personal devices are just as exposed as anyone with a clinical title.
  • Clinical: this matters because clinical practices carry the heaviest compliance expectations, and "we didn't know" is not a defence worth testing.
  • Retreat/Centre: this matters because centres holding data across several staff laptops have more places for something to go wrong, not fewer.

Where this came from

The original page walks UK therapists through GDPR, ICO, and BACP rules, and argues that encrypting client data is a basic legal duty, not a bonus feature.

Theroompsy.com, publish date not given.

Credibility flags: no methodology, no sample, no named publisher beyond the practice's own website; this is guidance, not research.

How we scored this

A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.

43%
Practice fit, 100How new, 10How solid, 0

Marked down heavily on how solid the method is, since there isn't one, and marked down on recency because there's no date to check it against; practice fit stays high because the subject sits squarely inside therapy compliance.

Faces of satisfied clients
It's worth considering changes to your marketing practices

What this means for your marketing

  • Put a line about encrypted client records on your website, before a prospective client asks.
  • Brief your team on what "encrypted" actually means in your own systems, so nobody bluffs an answer.
  • Say plainly in your welcome pack how client notes are stored and protected.
  • Don't quote this guide's claim as a statistic; treat it as sensible practice, not proven research.

Who this is most useful for

Practice typeRelevanceRecommended action
CoachingMediumCheck how client data is stored, even informally.
TherapyHighReview encryption and note-storage practices against current ICO guidance.
TrainingLowConfirm what personal data you actually collect and how it's kept.
Alternative HealingMediumTreat intake forms and client histories with the same care as clinical notes.
ClinicalHighAudit device encryption and access controls as a standing item.
Retreat/CentreMediumStandardise data handling across all staff devices, not just one laptop.

Best before

Best before: revisit this once you've checked current ICO guidance directly, since this page cites none; a good job for Sunlight Creations to verify against the primary source.

What next?

Most practices know exactly which laptop this is about, and pretending otherwise doesn't count as a data protection policy.

Talk to us about Whole-practice Marketing

Therapy Space

Consider This The Footnote That Changes Things.

You stayed to the end and here we both are. We have a visual river, a story garden and a listening wind that belong to a practice exactly like yours - and a discovery call where they all make beautiful sense over coffee. Biscuit?

Find your Sunlight  ▶