Menu Close

Two dates most Psychologist/Counselling businesses have not heard of: one already in force, the next nine weeks away for some

Two dates most Psychologist and Counselling businesses have not heard of, one already in force, the next nine weeks away for some

The Information Commissioner's Office studied its own register this year and found that 21% of data controllers did not know it existed. That gap was driven almost entirely by sole traders and micro-businesses. Medium and large organisations sit under 1%.

The qualitative follow-up put a face on that 21%: a sole trader psychotherapist who holds client notes electronically and by hand, who could recall the fine detail of a client's case from years back without hesitation, but not the last time they had checked the rules on how they are supposed to store it. They hadn't, not once in over a decade. The report's own words for why: they "prioritise their responsibility to clients over formal compliance."

Paper counts too. If those notes sit in any kind of filing system, structured enough that a named client's file can be found without leafing through everything, UK GDPR applies to them exactly as it does to anything on a screen. I have heard this treated as an open question more than once, usually from someone who assumed a locked cabinet put them outside the rules altogether. It does not.

The training does this to people: client first, paperwork later, often the following Sunday. If you're running your own business, it leaves the same gap behind, no matter your title: Psychiatrist, Clinical Psychologist, Psychologist, Psychotherapist, Counsellor, Therapist, or Coach. And the underlying legal duty is the same whichever professional body you are signed up to. Two dates this year make that gap harder to ignore. One has already passed. One is nine weeks away.

It does not matter what you are called, or how you are set up

Forget the titles for a moment, because none of them changes the actual answer. Whether you are a sole trader, in partnership, or trading through a limited company, and whatever letters follow your name, if you hold identifiable information about a client, a potential client, or even someone who enquired about your services on a website form, you are what the law calls a data controller. The ICO's rules apply to you in the same way. There is no size threshold and no self-employment exemption. How you've set the business up decides who is responsible. It doesn't decide whether that responsibility exists.

The law is one thing, settled and universal. What your professional body has told you to do is a separate question, and the picture here genuinely differs. As you read the two dates below, hold your own setup in mind rather than the general picture. The law applies equally.

19th June 2026, already in force

From 19th June, the duty to have a process for dealing with data-related complaints rests with you. The right to complain has always existed. What's new is that you now have to run the process: an accessible way for people to complain, acknowledged within 30 days, investigated without undue delay, and the person told the outcome. The ICO's own guidance is direct about it: "You must have a process for handling data protection complaints within your organisation. There are no exemptions to this." Almost nobody in the audience the ICO studied has that process written down anywhere a client could find it.

This is worth taking seriously now, not filing away. AI is changing the shape of a complaint. Ropes & Gray, advising UK organisations on subject access requests, describe generative AI "producing detailed and expansive DSARs in seconds," and the ICO's own figures show complaints under Article 15 UK GDPR, the right of access, climbing year on year. Ireland's Data Protection Commission saw complaints rise 45% in 2025 to over 16,000, many involving AI, and is on track to pass 20,000 in 2026. A regulator in Berlin reported a similar jump and named AI as the main driver. A complaint that used to take someone an evening of frustrated typing can now be built, researched and argued in minutes. Having a process, and being clear on how you use data and how confident you are in your own compliance, matters more than it did a year ago.

3rd November 2026, midday

The second date belongs to the BACP. Its Ethical Framework for the Counselling Professions 2026 becomes mandatory for every member at midday on 3rd November, and for the first time it sets out explicit requirements on AI and digital tools. Before using any AI tool, digital tool or online platform, a member must be able to demonstrate that they:

  • are competent to use it
  • understand how the data is handled and stored, and have mitigated the risks to confidentiality
  • are honest and transparent with clients about using it, including the benefits and the risks
  • have the client's informed consent before any of their personal data goes into it
  • have not deferred or outsourced their own judgement to it, and remain responsible for evaluating what it produces

If you are a Counsellor or Psychotherapist and a BACP member, that clause has your name on it. Nine weeks is not long to have all five of those in place, demonstrably, for every tool you already use. You may well also use more tools and have identifiable data flowing to more places than you know.

And if you are a Psychologist, this still applies to you

The British Psychological Society has not set a date. It has endorsed the Global Psychology Alliance's Top 10 Principles for AI in psychology, and is now recruiting members for its own AI Guidance Group to develop more practical guidance. That is the profession moving in the same direction BACP has already required of its members. It simply has not attached a deadline to it yet.

None of that changes what is required of you. A missing industry deadline does not create a missing legal one, and here it works the other way round: with less sector-specific guidance to lean on, the gap between what the law expects and what you actually have written down is, if anything, wider for Psychologists than for BACP members who have just been handed a clause that spells it out for them.

Put plainly: the underlying legal duty, UK GDPR and the Data (Use and Access) Act 2025, applies to every person reading this in exactly the same way, whatever letters follow their name. What differs is who has been handed a deadline and who has not. But the duty that took effect on 19th June already applies, regardless. Nobody is coming to tell most Psychologists when to act. That is the exposure.

The one distinction that actually matters

Invoicing, scheduling, marketing copy, website enquiries, general business thinking. All of this is ordinary business data, handled with ordinary commercial care. A client record, a session note, a recording, a referral letter or a supervision note is already special category health data, UK GDPR's term (Article 9) for information that reveals someone's health status. That status attaches the moment the note is written, not when a tool touches it. What AI changes is not the classification, but the exposure: a new act of processing, usually uncontracted and unchecked, on top of everything else your existing lawful basis and Article 9 condition already have to cover. If you have ever pasted a session note into ChatGPT to tidy up the language, that new act of processing is exactly what this is about. I have not seen this line drawn plainly anywhere else in the current guidance circulating in the profession, and most of what is circulating was written before either of the two dates above existed.

AI makes this harder to stay on top of. Once a client's information goes into an AI tool, you can lose sight of where it has gone, who else can reach it, and whether it is being used to train the next version of that tool. A free or personal AI account gives you no agreement covering any of that at all, which means there is nothing to check even if you wanted to.

This is also where consent quietly goes wrong. Client records are usually held on a lawful basis of contract or legitimate interests, paired with the health and social care condition for the special category data itself, not on consent alone. Consent sounds like the safer, more client-respecting choice, and it is the one most templates default to. It is also the weaker choice, because a client cannot meaningfully refuse the note-keeping the service depends on, and it creates a problem later: a client which withdraws consent can reasonably expect their records to be deleted, which then collides with what your insurer, and often your professional body, expects you to keep.

Where this actually breaks

Four places we could start with. The contact form on your website, quietly storing every enquiry in a database nobody has looked at in years, collecting special category data from people who are not even clients yet. Session notes, tidied up afterwards by pasting them into a consumer AI account with no data processing agreement, no due diligence recorded, and no lawful basis for doing it. A client contract inherited from training, never updated, silent on AI, silent on the complaints route the law has required since June. And the request nobody plans for: a former client asking for everything you hold on them, which the law now expects you to search for in a way you can show was reasonable and proportionate, and answer within 30 days.

These four are the common ones, not the only ones. Depending on your setup, there will be more. Two worth naming on their own. If you use a virtual assistant, transcriber or support worker based outside the UK, letting them access client data usually counts as a restricted transfer under UK GDPR, and needs its own safeguard in place before it happens, not after. And if your clients, or people who have only enquired, are based in the EU rather than the UK, you may fall under EU GDPR as well, which can bring its own separate requirements. Both are worth a proper check if they apply to you, rather than a guess.

None of it is onerous to put right. All of it is common, and all of it is fixable once someone points it out.

The economics, in one line

Registering with the ICO, for almost everyone reading this, costs £52 a year, or £47 by direct debit. Failing to register when you should have carries a penalty of £400 to £4,000, on top of the fee you still have to pay. That ratio is the argument.

The check most people fail

Could you point to your own complaints process right now, the one the ICO says you must have? Do you know which lawful basis covers your session notes? Does the AI account you tidied them up in last week have a data processing agreement at all?

When this audience answers questions like these honestly, most fail four or more, usually because the decisions behind them were made separately, at different points, years apart, and nobody has ever sat down to reconcile them against each other, or against what changed on 19th June and what changes on 3rd November. It is a starting point, not a substitute for a proper review or advice from someone qualified to look at your own setup.

Take the Informing Minds Data Compliance Check now

Run the ten-question check yourself, it takes about two minutes.

Take the Data Compliance Check

If you'd rather talk it through and find out what the gaps actually mean for your business, book a discovery call instead. Ten minutes will tell you more than this article can.

Brian Tancock is the founder of Informing Minds, a business strategy consultancy for mental health practitioners. He spent thirty years in project and risk management across international banking in London, Paris, Singapore and Hong Kong, and the past decade working with practitioners on the business side of their work.

Not legal advice.