UK GDPR sets out the main principles of data protection and the responsibilities organisations have when handling personal data. It protects individuals’ personal information and improves their control over how it is collected, stored, shared and used.

The UK GDPR and DPA 2018 are complex and you may wish to seek professional advice from a legal expert in data protection. They will be able to clarify the finer points of GDPR requirements and what it means for your organisation or practice.

For the latest information, see the , which has lots of resources from basic tools to detailed guides. It's worth checking back regularly as Data Protection information is still being updated.

Your questions

Do I need to register with the ICO?

All businesses (including sole traders) processing personal information electronically must register with the ICO and pay a fee. A new fee charging structure came into effect on 25th May 2018, UK GDPR and DPA 2018.Ìý

See Register on the ICO website.

Do the same tiles apply to paper records and electronic records?

Broadly speaking, the same regulations do apply. Most personal data is held electronically as this is the most secure option, so if you keep paper records, you have the added complexity of maintaining both paper and electronic media. Paper records are not recommended and should be used only in extreme circumstances.

How long should I keep my records for?

Data Protection legislation does not set specific time limits but requires that you only keep information for as long as is necessary for the specific purpose it was originally collected. So you will need to decide how long you need to keep personal data and set retention periods.

Anonymising your records is the same as deletion because anonymised data is not personal data, therefore DP legislation does not apply. But the information must be trulyanonymous so that there is no way that the data subject can beidentified.

You should consider whether you can minimise a record after a certain time. So, you can delete some of the information you hold on a client (especially the more sensitive or special category information) and just retain limited data.

Further points to consider:

  • whether the data in your records is covered by any legal or regulatory requirements
  • whether your indemnity insurers specify a time period
  • your organisational policies
  • the time limits for raising a complaint against a therapist (currently threeyears after counselling has ended under our Professional Conductprocedure)

What is pseudonymisation?

This is basically a reversible anonymisation. For instance, you couldremove all personal identification from your records, such as name,address, email, and keep these fields in a different system (preferablyheld on a completely separate system, possibly a paper notebook). Youwould use a ‘pseudonym’ to connect the two systems. This also makesthe eventual anonymisation of the record easier as you only need todelete the secondary record.

Pseudonymised records are still defined as personal data under UK GDPR but, as long as the two elements are kept physically separated, the risksare reduced. Any data breach would be considered less serious if therecords compromised had been effectively pseudonymised.

How should I destroy or delete records?

This depends on how your records are stored. Paper records holdingpersonal data must be shredded. Electronic records can be more difficultas you must ensure the data cannot be ‘un-deleted’ or restored from backups.

Do I need to contact previous clients if I still have their records?

This partly depends on what you told the clients when you originallycollected their information. It also depends on what retention period youhave decided on.

Once you’ve minimised and anonymised as much data as possible, if:

  • you can still justify holding personal data about the client and
  • you did not explicitly explain this to the client when you collected it

then you ought to contact the clients to explain your policy and allowthem to ask for their personal data to be deleted.

This is particularly important if you retain any data classified as ‘specialcategory’. You should certainly explain this in your privacy statement sothat former clients can easily find out what data you are keeping aboutthem.

See Special category data on the .Ìý

What do I need to include in a privacy statement?

Your privacy statement (or privacy notice) is possibly the most importantpart of your DP compliance. Transparency is fundamental to dataprotection and your privacy statement is the main way you can achieve.

Your privacy statement should be as thorough as possible. You mustavoid jargon and write it in terms your clients will understand. You must explain what personal data you keep, how long you keep it, what you dowith it and who you share it with. Look at it from the client’s point ofview to ensure it’s easy for them to find the information they need.

Are there additional considerations when working with children andyoung people?

Yes, DP legislation is more complex if you're dealing with personal data of children or young people. This overlaps with safeguarding policies and guidance such as
So, if you already adhere to strict safeguarding principles, you will probably not have to make significant changes to comply with UK GDPR.

General questions about Data Protection legislation

What is Data Protection about?

If a company has legitimately collected some personal information from or about you,  such as your name, home address, medical history, religion or ethnic background, you’d want them to keep it secure and not misuse it or pass it on appropriately.

Data Protection is about protecting information so that those news stories aboutvery sensitive personal records being lost or made available to others can't happen.

As a result of significant advances in technology, social media, and digital networks, much of who we are is recorded electronically as personal data. The UK GDPR, DPA 2018 and very recently implemented Data (Use and Access) Act, brings the law up to date to address any new and emerging data threats which may occur due to modern technology.Ìý

Why does the law need an update?

Change to: As a result of significant advances in technology, social media and digital networks, much of who we are is recorded electronically as personal data. The UK GDPR, DPA 2018 and very recently implemented Data (Use and Access) Act, brings the law up to date to address any new and emerging data threats which may occur due to modern technology.

Does it apply to me?

No matter what your business is, every service is likely to hold some personal data, so will need to be GDPR compliant.

You need to be sure that your customers’ or staff's personal informationis protected according to the legal requirements, as there are substantialpenalties for not complying with UK GDPR and DPA 2018.

I’m self employed and have a private practice at home. Do I need to comply with Data Protection legislation?

If you process personal data solely within your own personal life or forhousehold activities, Data Protetion legislation doesn’t apply. But if you undertake anycommercial activities, even if you’re a sole trader working from home, it'shighly likely that you will be subject the UK GDPR, DPA 2018 and D(UA)A.

What are the penalties for non-compliance?

For Tier one incidents, which relate to the organisation's obligations, thefine is up to €10 million, or 2% annual global turnover (whichever ishigher).

For Tier two incidents, which are incidents affecting an individual'sprivacy rights, the fine is up to €20 million, or 4% annual global turnover(whichever is higher).

The fines are discretionary, not mandatory, and are made on a case-by-case basis. When deciding which tier applies and what the resulting fineshould be, the ICO must consider many factors including:

  • the extent of the damage
  • what data was involved
  • the data protection policies and procedures of the organisation
  • any mitigating and corrective actions taken following the infringement
  • if any previous incidents have been caused by the organisation

The ICO can also inflict reputational damage, alongside a fine. Individuals have the right to material and non-material compensation.

What do I need to do to ensure compliance?

There is no need to panic if you are not yet fully compliant, but you should at least have a roadmap of how you are going to achieve compliance.

If you have not already done so, your starting point should be to introduce a transparent privacy notice for all your clients.

Things to consider

What data do you hold?

Conduct an audit. Do you know what personal data you hold, where it comes from and who you share it with?

How do you respond to data requests?

Make sure that your procedures are up to date with Data Protection requirements.How will you handle requests to see personal data within Data Protection timescales and provide any additional information?

What is your legal basis for processing personal data?

Consider the various types of data processing you carry out. Identify anddocument your legal basis for doing these.

Consent

If relevant, how do you seek, obtain and record consent? Do you need to make any changes? A guide to legal basis can be

Children

How can you be sure of individuals’ ages? Consider what systems you will need in place to gather consent for those who cannot give it themselves.

Data breaches

What procedures do you need to identify a breach, report it, and carry out an investigation? Do you know what to disclose, when and to who?

Data protection by design and impact assessments (DPIAs) 

DPIAs help to ensure privacy by design is followed. Make sure you are familiar with the specific guidance produced by the ICO. Where and how should implement DPIAs into your business?

Data Protection Officer

Do you need to designate a DPO? If so, where should the responsibility sit within the organisation and who will hold it?

Awareness

Are all decision makers and key individuals in your organisation aware if the requirements of relevant Data Protection legislation? Do they appreciate the impact that this is likely to have?

International

If you operate internationally, make sure you know which supervisory authority you come under for data protection.

Information Rights

Individuals have certain rights when it comes to their personal data. These include: Right of Access, Right to Rectification, Right to Erasure, Right to Objection, Right to Data portability, Right to restriction of processing, Right to be informed and Rights related to automated decision making and profiling.

Further information

ÌÇÐĹÙÍø resources

Good Practice in Action resources

For definitions, please see: GDPR terms and definitions.

ICO resources

ICO organisation guide to GDPR: .