Confidentiality and Data Protection Policy

‍ ‍1.1 Purpose

‍ ‍This policy sets out how Into The Greenhouse manages confidential client information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the ethical frameworks of our professional body NCPS.

‍ 1.2 Scope

‍ ‍This policy applies to all counsellors, associates, administrators, and volunteers working within or on behalf of Into The Greenhouse. It covers all client information whether held in paper or electronic form.

‍ ‍1.3 Principles of Confidentiality

‍ ‍All information shared by a client during therapy is treated as confidential. This includes the fact that the client is attending counselling. Clients will be informed at the outset of therapy about the limits of confidentiality. Information will only be shared with explicit client consent or in the exceptional circumstances set out below.

‍ ‍1.3.1 Exceptions to Confidentiality

‍ ‍Confidentiality may be broken without client consent in the following circumstances:

‍ ‍•        Where there is a serious and imminent risk to the client’s life or the life of another person

•        Where there is a safeguarding concern involving a child or vulnerable adult

‍ ‍•        Where a court of law orders disclosure

‍ ‍•        Where there is a legal obligation to report (e.g. terrorism or money laundering offences)

‍ ‍•        Where required for the prevention, detection, or prosecution of serious crime

‍ ‍In all cases, the counsellor will make every effort to discuss the need to break confidentiality with the client before doing so, unless doing so would increase risk.

‍ ‍1.3.2 Clinical Supervision

‍ ‍All counsellors are required to attend regular clinical supervision. Client material may be discussed in supervision on an anonymised basis. Clients will be informed of this at the start of therapy.

‍ ‍1.4 Data Protection (UK GDPR Compliance)

‍ ‍1.4.1 Lawful Basis for Processing

‍ ‍Client data is processed under the following lawful bases:

‍ ‍•        Legitimate interests – for the provision of counselling services

‍ ‍•        Consent – where explicit consent is obtained for processing special category data (health data)

‍ ‍•        Legal obligation – where required by law

‍ ‍1.4.2 Data We Collect

‍ ‍•        Name, contact details, date of birth

‍ ‍•        Emergency contact details

‍ ‍•        GP details (with client consent)

‍ ‍•        Presenting issues and therapeutic goals

‍ ‍•        Session notes and risk assessments

‍ ‍•        Relevant medical and mental health history

‍ ‍•        Invoicing and payment records

‍ ‍1.4.3 Data Storage and Security

‍ ‍•        Electronic records are stored on encrypted, password-protected systems

‍ ‍•        Paper records are stored in locked filing cabinets accessible only to the treating counsellor

‍ ‍•        Client records are never stored on personal devices without encryption

‍ ‍•        Data is backed up regularly and securely

‍ ‍•        All devices used for client work have up-to-date antivirus and firewall software

‍ ‍1.4.4 Data Retention

‍ Client records are retained for a minimum of 7 years from the date of the last session for adult clients. For clients who were under 18 at the time of therapy, records are retained until the client’s 25th birthday or for 7 years from the last session, whichever is later. After the retention period, records are securely destroyed (shredded for paper; permanently deleted for electronic records).

‍ ‍1.4.5 Client Rights Under UK GDPR

‍ ‍Clients have the right to:

‍ ‍•        Access their personal data (Subject Access Request)

‍ ‍•        Request correction of inaccurate data

‍ ‍•        Request erasure of data (subject to legal retention requirements)

‍ ‍•        Object to or restrict processing

‍ ‍•        Withdraw consent at any time

‍ ‍•        Lodge a complaint with the Information Commissioner’s Office (ICO)

Subject Access Requests will be responded to within one calendar month.

‍ ‍1.4.6 Data Breach Procedure

In the event of a data breach:

1.     The breach will be contained immediately and assessed for severity

2.     The practice’s founders will be notified without delay

3.     If the breach is likely to result in a risk to individuals’ rights and freedoms, the ICO will be notified within 72 hours.

4.     Affected individuals will be informed without undue delay if there is a high risk to their rights and freedoms

5.     The breach will be documented in the breach register with details of the incident, its effects, and remedial actions taken