GDPR for therapists in Ireland: a practical guide
GDPR for Irish therapists and counsellors: health data and lawful basis, how long to keep notes, access requests, breaches and the Data Protection Commission.
Every therapist in private practice is a data controller. You decide what client information to collect, why, where it’s kept and for how long, and GDPR holds you responsible for those decisions. Because nearly everything you record in therapy is health information, the rules are stricter than they are for most small businesses.
This guide covers what an Irish therapist, counsellor or psychotherapist needs to get right, in plain terms: the lawful basis for holding health data, how long to keep notes, what to do when a client asks for their records, and what to do if something goes wrong. The regulator in Ireland is the Data Protection Commission (DPC), and its guidance is the reference point throughout.
Health data is special category data
GDPR gives extra protection to “special categories” of personal data, and data about health is one of them. The DPC puts it plainly: processing of special category data is prohibited, except in limited circumstances set out in Article 9 of the GDPR.
For health data specifically, the DPC says processing is only permitted in certain cases, as provided for in Article 9(2) of the GDPR and sections 45 to 54 of the Data Protection Act 2018. One example it gives is where the client has given explicit consent to the processing for one or more specified purposes.
In practice, you need two things for your clinical notes:
- A lawful basis under Article 6. The DPC lists six: consent, performance of a contract, compliance with a legal obligation, protecting someone’s vital interests, a task in the public interest, and legitimate interests.
- A condition under Article 9, read together with the Data Protection Act 2018, because the data is health data.
Which basis and condition fit depends on your practice. For example, a therapeutic contract with a private client looks different from work funded by an employer or insurer. Write down which ones you rely on and why, and put them in your privacy notice. If you’re unsure, check with the DPC’s guidance or your professional body rather than defaulting to “consent” for everything.
When “consent” means explicit consent
If you rely on consent for health data, it needs to be explicit and specific. The DPC’s case studies include one where an individual had agreed that an insurer could seek their health information, but had not given explicit consent to that information being passed on to third parties. The DPC found that the onward disclosure was a breach.
The lesson for therapists: consent to therapy is not consent to share. If you’ll ever send information to a GP, a referrer, an employer or an insurer, say so, get specific agreement, and record it.
What to put in your privacy notice
Give clients a short privacy notice before the first session, alongside your therapy contract. It should cover:
- who you are and how to contact you
- what information you collect (contact details, intake answers, session notes, payment records)
- why you collect it, and your lawful basis and Article 9 condition
- who you share it with and when, including supervisors (in anonymised form) and the software you use
- how long you keep each type of record
- the client’s rights, including access, and their right to complain to the DPC
How long to keep notes
GDPR’s storage limitation principle says personal data must be kept “in a form that permits identification of data subjects for no longer than is necessary” for the purposes it’s processed for. The DPC notes that GDPR doesn’t set specific retention periods, so you must take account of any statutory obligations when you set your own. When the purpose has ended and you no longer need the data, it must be deleted or disposed of securely.
For counsellors and therapists, the most concrete guidance comes from IACP’s Record Keeping & Retention Guidelines:
- Adults: unless something else requires otherwise, keep records for 7 years after the last date of service.
- Children and young people: until the client is 25 (or 26 if they were 17 when therapy ended), or 8 years after their death if sooner.
- Investigations and litigation: if a matter is under investigation or litigation is likely, keep the files, as they may be used as evidence.
- Insurance: some insurers require longer retention, so check your policy before you settle on a period.
IACP also advises putting your retention period in the client/therapist contract, so clients know it from the start.
Then act on it. Set a yearly review, securely delete what has passed its period (including copies in email, downloads and backups), and keep a simple log of what you deleted and when.
When a client asks for their records
Clients have a right of access under Article 15 of the GDPR: they can ask whether you hold data about them and for a copy of it, along with information such as why you hold it, who you’ve shared it with and how long you’ll keep it.
What the DPC says about handling a request:
- Timing: respond within one month of receiving the request. You can extend this by up to two further months if, for example, the request is complex, but you must tell the client, with reasons, before the first month ends.
- Format: a request can be made in writing or verbally. The DPC encourages written requests to avoid disputes, but you can’t refuse a verbal one because it wasn’t written down.
- Cost: in most cases you can’t charge a fee. A fee based on administrative costs is possible only for manifestly unfounded or excessive requests, or for further copies.
- Other people’s rights: access must not adversely affect the rights and freedoms of others. Notes often mention third parties (partners, family members), so think about whether anything needs to be withheld to protect them, and aim to comply as far as you can.
Some practical steps:
- Know where everything is: your practice software, email, paper notes, voice memos.
- Check the requester’s identity before you release anything.
- If your notes contain material that needs careful handling, get advice from your professional body or the DPC’s guidance on how to respond, rather than improvising.
- Keep a record of the request, what you sent and when.
If something goes wrong: breaches
A personal data breach is more ordinary than it sounds: a laptop left on a train, a session summary emailed to the wrong address, a shared login.
The DPC’s rules:
- If a breach presents a risk to the people affected, you must notify the DPC within 72 hours of becoming aware of it, using its breach notification form.
- If a breach is likely to result in a high risk to those people, you must also tell them without undue delay.
- Even if you decide there’s no risk, you must keep an internal record: what happened, how you decided there was no risk, who decided, and the risk rating you recorded.
Because therapy notes are health data, many breaches in a practice will carry some risk. Decide in advance who you’d call (your insurer, your supervisor) and where the DPC’s form is, so you’re not working it out in a panic.
Reducing the risk in the first place
- Lock everything. Use passwords and screen locks on every device, and don’t share logins.
- Keep notes in one system, not scattered across email, desktop folders and a notebook.
- Minimise. Record what you need for safe, effective practice, not everything you could.
- Be careful with email. Double-check recipients, and avoid sending detailed notes as attachments.
- Check your software. Any system that stores client data does so on your behalf. Read its terms and find out where the data is hosted.
On that last point: MyWellOps hosts data in Frankfurt, Germany, and keeps notes on the client record. If you use AI Notes, it’s only with the client’s consent, and session recordings are deleted after 30, 60 or 90 days or when you save the note, depending on your setting. Intake and consent forms (from 227 templates) are signed in the client portal, which gives you a dated record of what each client agreed to.
A checklist for your practice
- Privacy notice written and given to every client before the first session
- Lawful basis and Article 9 condition written down for your clinical notes
- Specific, recorded consent before sharing information with anyone else
- Retention periods set (IACP’s guidelines are a sensible starting point) and included in your contract
- A process for access requests, with a one-month calendar reminder
- A breach plan, including the DPC’s 72-hour rule and an internal breach log
- Devices secured and notes in one place
For anything specific to your practice, check the DPC’s guidance or ask your professional body.
Sources
- https://www.dataprotection.ie/en/organisations/know-your-obligations/lawful-processing
- https://www.dataprotection.ie/en/organisations/know-your-obligations/lawful-processing/special-category-data
- https://www.dataprotection.ie/en/dpc-guidance/case-studies/transparency/processing-health-data
- https://www.dataprotection.ie/en/faqs/responsibilities-data-controllers/how-long-should-personal-data-be-held-meet-obligations-imposed-gdpr
- https://www.dataprotection.ie/en/individuals/know-your-rights/right-access-information
- https://www.dataprotection.ie/en/faqs/access-and-rectification/how-long-does-organisation-have-respond-my-access-request
- https://www.dataprotection.ie/en/dpc-guidance/data-subject-access-requests-faq
- https://www.dataprotection.ie/en/organisations/know-your-obligations/breach-notification
- https://iacp.ie/files/UserFiles/Download-Area/IACP-Record-Keeping-and-Retention-Guidelines-V2.1.pdf