DATA PROTECTION
This policy explains how personal data is handled within this counselling practice in accordance with UK GDPR and the Data Protection Act 2018.
Katherine Nickoll is the Data Controller for all personal information collected in connection with counselling and supervision services.
What Data Is Collected
I may collect:
• Contact details (name, address, email, telephone number)
• Emergency contact details
• Relevant health and wellbeing information
• Information provided during counselling, supervision and assessent sessions*
• Brief professional notes to support continuity of care*
• Administrative information relating to appointments and correspondence
*n.b. Session notes are brief aide-mémoire records to support therapeutic continuity and clinical practice. They are not verbatim or detailed transcripts of sessions.
Lawful Basis for Processing
Personal data is processed on the basis of:
• Provision of counselling and supervision services
• Legitimate interests in maintaining safe and effective professional practice
• Legal and regulatory obligations, including insurance and safeguarding requirements
How Data Is Stored
Electronic records are stored using password protection and appropriate security measures, including secure devices and accounts with two-factor authentication where available.
Any paper records are kept in locked storage and identifiable information is minimised.
Access to data is restricted to the practitioner only.
Data Retention
Records are normally retained for seven years after the end of counselling.
This may be extended where required by law, insurance conditions, safeguarding obligations or other professional requirements.
After the retention period, records are securely destroyed or permanently deleted.
Data Security
Appropriate technical and organisational measures are used to protect personal data from loss, misuse, unauthorised access or disclosure.
These include password protection, secure storage, and minimising the use of identifiable information in digital communications where possible.
Confidentiality and Disclosure
Information shared in counselling is treated as confidential.
Confidentiality may be broken only where there is:
• A risk of serious harm to the client or others
• A safeguarding concern
• A legal obligation or court order
• A requirement under law or professional duty
Where possible, disclosure will be discussed with the client first unless doing so would increase risk.
Data Subject Rights
Under UK data protection law, clients have the right to:
• Access personal data held about them
• Request correction of inaccurate data
• Request restriction of processing in certain circumstances
• Object to certain processing activities where applicable
• Request deletion of data in limited circumstances
These rights are subject to legal, insurance and professional record-keeping requirements.
Requests for access may be made verbally or in writing. Responses are normally provided within one calendar month unless an extension is permitted under law.
Data Breaches
In the unlikely event of a data breach, appropriate steps will be taken to contain the issue, assess risk, and notify relevant parties where required by law.
Complaints About Data Handling
Concerns about the handling of personal data should be raised in the first instance with the practitioner.
If unresolved, clients have the right to contact the Information Commissioner’s Office (ICO). Website: www.ico.org.uk
PRIVACY NOTICE
Purpose
This Privacy Notice explains how your personal information is collected, used, stored and protected.
Information Collected
Information collected includes contact details, relevant health and wellbeing information, session notes, and administrative records.
Purpose of Use
Your information is used to:
• Provide counselling and supervision services
• Manage appointments and communication
• Maintain clinical records
• Meet legal, professional and insurance obligations
Storage and Security
Information is stored securely in locked or password-protected systems with appropriate safeguards to maintain confidentiality.
Retention
Records are kept for seven years after counselling ends unless a longer retention period is required for legal, safeguarding or insurance purposes.
Confidentiality
All information is treated as confidential.
Exceptions include:
• Risk of serious harm to self or others
• Safeguarding concerns
• Legal or court requirements
• Other overriding legal obligations
Your Rights
You have rights under data protection law, including access to your information, correction of inaccuracies, and the ability to raise concerns about how your data is handled.
Complaints
If you have concerns, please contact me in the first instance. If unresolved, you may contact the Information Commissioner’s Office (ICO). Website: www.ico.org.uk
CLIENT COMPLAINTS PROCEDURE
In the first instance If something does not feel right, I encourage you to talk to me. I welcome respectful feedback and these honest conversations can build trust.
How to Make a Complaint
Complaints can be made:
• By email: [email protected]
• Verbally during a session
Please include:
• Your name and contact details
• A description of the concern
• Relevant dates or information
Acknowledgement
Complaints will normally be acknowledged within five working days.
Investigation
The complaint will be reviewed fairly and thoroughly. Relevant records may be examined, and advice may be sought from a supervisor, insurers, professional bodies or legal advisers where appropriate.
All information will be handled confidentially.
Response
A written response will normally be provided within 30 calendar days.
This will include findings, any actions taken, and next steps if you remain dissatisfied.
Record Keeping
A confidential record of the complaint will be kept in accordance with data protection and professional requirements.
Escalation
If you remain dissatisfied, you may contact the National Counselling and Psychotherapy Society (NCPS) https://ncps.com or Information Commissioner’s Office (ICO) www.ico.org.ukwhere the complaint relates to data protection matters.
Review
This procedure will be reviewed annually or sooner if required by changes in law or professional guidance.
This policy explains how personal data is handled within this counselling practice in accordance with UK GDPR and the Data Protection Act 2018.
Katherine Nickoll is the Data Controller for all personal information collected in connection with counselling and supervision services.
What Data Is Collected
I may collect:
• Contact details (name, address, email, telephone number)
• Emergency contact details
• Relevant health and wellbeing information
• Information provided during counselling, supervision and assessent sessions*
• Brief professional notes to support continuity of care*
• Administrative information relating to appointments and correspondence
*n.b. Session notes are brief aide-mémoire records to support therapeutic continuity and clinical practice. They are not verbatim or detailed transcripts of sessions.
Lawful Basis for Processing
Personal data is processed on the basis of:
• Provision of counselling and supervision services
• Legitimate interests in maintaining safe and effective professional practice
• Legal and regulatory obligations, including insurance and safeguarding requirements
How Data Is Stored
Electronic records are stored using password protection and appropriate security measures, including secure devices and accounts with two-factor authentication where available.
Any paper records are kept in locked storage and identifiable information is minimised.
Access to data is restricted to the practitioner only.
Data Retention
Records are normally retained for seven years after the end of counselling.
This may be extended where required by law, insurance conditions, safeguarding obligations or other professional requirements.
After the retention period, records are securely destroyed or permanently deleted.
Data Security
Appropriate technical and organisational measures are used to protect personal data from loss, misuse, unauthorised access or disclosure.
These include password protection, secure storage, and minimising the use of identifiable information in digital communications where possible.
Confidentiality and Disclosure
Information shared in counselling is treated as confidential.
Confidentiality may be broken only where there is:
• A risk of serious harm to the client or others
• A safeguarding concern
• A legal obligation or court order
• A requirement under law or professional duty
Where possible, disclosure will be discussed with the client first unless doing so would increase risk.
Data Subject Rights
Under UK data protection law, clients have the right to:
• Access personal data held about them
• Request correction of inaccurate data
• Request restriction of processing in certain circumstances
• Object to certain processing activities where applicable
• Request deletion of data in limited circumstances
These rights are subject to legal, insurance and professional record-keeping requirements.
Requests for access may be made verbally or in writing. Responses are normally provided within one calendar month unless an extension is permitted under law.
Data Breaches
In the unlikely event of a data breach, appropriate steps will be taken to contain the issue, assess risk, and notify relevant parties where required by law.
Complaints About Data Handling
Concerns about the handling of personal data should be raised in the first instance with the practitioner.
If unresolved, clients have the right to contact the Information Commissioner’s Office (ICO). Website: www.ico.org.uk
PRIVACY NOTICE
Purpose
This Privacy Notice explains how your personal information is collected, used, stored and protected.
Information Collected
Information collected includes contact details, relevant health and wellbeing information, session notes, and administrative records.
Purpose of Use
Your information is used to:
• Provide counselling and supervision services
• Manage appointments and communication
• Maintain clinical records
• Meet legal, professional and insurance obligations
Storage and Security
Information is stored securely in locked or password-protected systems with appropriate safeguards to maintain confidentiality.
Retention
Records are kept for seven years after counselling ends unless a longer retention period is required for legal, safeguarding or insurance purposes.
Confidentiality
All information is treated as confidential.
Exceptions include:
• Risk of serious harm to self or others
• Safeguarding concerns
• Legal or court requirements
• Other overriding legal obligations
Your Rights
You have rights under data protection law, including access to your information, correction of inaccuracies, and the ability to raise concerns about how your data is handled.
Complaints
If you have concerns, please contact me in the first instance. If unresolved, you may contact the Information Commissioner’s Office (ICO). Website: www.ico.org.uk
CLIENT COMPLAINTS PROCEDURE
In the first instance If something does not feel right, I encourage you to talk to me. I welcome respectful feedback and these honest conversations can build trust.
How to Make a Complaint
Complaints can be made:
• By email: [email protected]
• Verbally during a session
Please include:
• Your name and contact details
• A description of the concern
• Relevant dates or information
Acknowledgement
Complaints will normally be acknowledged within five working days.
Investigation
The complaint will be reviewed fairly and thoroughly. Relevant records may be examined, and advice may be sought from a supervisor, insurers, professional bodies or legal advisers where appropriate.
All information will be handled confidentially.
Response
A written response will normally be provided within 30 calendar days.
This will include findings, any actions taken, and next steps if you remain dissatisfied.
Record Keeping
A confidential record of the complaint will be kept in accordance with data protection and professional requirements.
Escalation
If you remain dissatisfied, you may contact the National Counselling and Psychotherapy Society (NCPS) https://ncps.com or Information Commissioner’s Office (ICO) www.ico.org.ukwhere the complaint relates to data protection matters.
Review
This procedure will be reviewed annually or sooner if required by changes in law or professional guidance.