Ed Holden Counselling

Privacy & Confidentiality Policy

The following Privacy & Confidentiality Policy will apply to all clients and will be issued as part of the initial contract.

It is liable to be updated at any time, and any current clients will be informed of any changes.

This policy applies to all clients and potential clients.

The purpose of this policy is to explain how client data is handled and protected.

At all times data is handled so that is complies with GDPR* and the BACP* Ethical Framework.

I will need to collect some or all of the following Personal Data:

  • Name, contact details (address, phone number, email), date of birth.
  • Relevant personal information shared by the client during sessions.
  • Details of any referrals or onward referrals made.
  • Sensitive Personal Data:
  • Details about the client’s physical and mental health.
  • Ethnicity, gender, sexuality, religion, beliefs (if disclosed).
  • Offences (if disclosed and relevant to therapy).
  • How Data is Collected:
  • Directly from the client (during initial assessment, sessions, or via forms).
  • From third parties with client consent (e.g., GP, other professionals).
  • Lawful Basis for Processing:
  • Explicit consent (obtained at the start of therapy).
  • Necessity for performance of a contract (the therapy agreement).
  • Legitimate interests (e.g., to ensure client safety, comply with legal obligations).

Primary Purpose:

  • Providing therapeutic services.
  • Managing the therapeutic relationship (e.g., scheduling, invoicing).
  • For supervision (to ensure safe and effective practice).

 

Secondary Purposes:

  • For research (with anonymized data only).
  • To comply with legal obligations.

 

Sharing Information:

  • With supervisors (without revealing client identity).
  • With other professionals (with client consent).
  • To protect the client or others from serious harm.
  • When legally required (e.g., by a court order).

The core principle of this policy is to be committed to maintaining client confidentiality.

There are specific exceptions to this, but only in a number of specific circumstances, for example (but not exclusively), where there are safeguarding concerns either the client or someone known to the client may be at serious risk of harm or there is a legal requirement to share information with a public body.

During supervision I may need to share details anonymously with my professional supervisor, in an anonymous and confidential manner.

I carry out the following safeguards in the storage and retrieval of personal data

  • Digital Security: Secure storage of electronic records (encrypted, password-protected, etc.).
  • Access Controls: Limiting access to client data to authorised personnel only.
  • Data Breach Procedures: Outlining steps to be taken in the event of a data breach.

As a client you have the right to view and review any data stored about you – including  

  • Right to Access: The right to request a copy of their personal data.
  • Right to Rectification: The right to request corrections to inaccurate data.
  • Right to Erasure: The right to request the deletion of their data (subject to legal and ethical obligations).
  • Right to Restrict Processing: The right to limit how their data is used.
  • Right to Data Portability: The right to receive their data in a usable format.
  • Right to Object: The right to object to the processing of their data.
  • Right to Withdraw Consent: The right to withdraw consent for processing at any time.

Records are kept for 5 years in accordance with insurance requirements. After which records will be destroyed securely.

I will provide contact details to clients to make requests or raise concerns about their data.

I will include contact details for the Information Commissioner’s Office (ICO) for complaints.

This policy will be reviewed and updated periodically.

Clients will be informed of any changes

I am registered with the Information Commissioner’s Office (ICO) which means your personal data is being handled by an individual or organisation that is legally compliant and prioritises data security. It provides assurance and demonstrates my commitment to protecting your privacy.