Data retention policy
Rachel Gibson Counselling
Last updated: 26th July 2026
Introduction
This policy explains how long I keep your personal information, why I retain it, and how I dispose of it securely. I am committed to keeping your data only for as long as necessary and handling it in accordance with UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
Why I Retain Your Data
I keep records of our work together and related information for several important reasons:
- Legal obligations — The law requires me to keep certain records for specific periods, including financial records for tax purposes
- Professional standards — As a counsellor in private practice, I am bound by the common-law duty of confidence and professional standards that require me to maintain appropriate records
- Insurance requirements — My professional indemnity insurance requires me to retain records in case a claim is made after our work ends
- Continuity of care — Should you return to therapy, your records help me provide consistent support
- Your protection and mine — Records may be needed to evidence the care provided if questions arise later
Retention Periods
| Type of record | Retention period | Reason |
|---|---|---|
| Client therapy records (session notes, assessments, correspondence) | 7 years after our last session | In line with the Limitation Act 1980 and standard professional indemnity insurance requirements |
| Enquiry and contact data (if you contact me but do not become a client) | 12 months from last contact | To respond to any follow-up queries and for my own records |
| Financial records and invoices | 6 years from the end of the financial year they relate to | Required by HMRC for tax purposes |
| Insurance records | 7 years | To support any potential insurance claims |
| Website contact form submissions | 12 months, unless you become a client | To manage enquiries and respond appropriately |
| Contracts and consent forms | 7 years after our last session | To evidence the agreement between us |
What I Retain
The records I keep may include:
- Your contact details (name, email address, phone number, address)
- Session notes and clinical records
- Assessment information and any questionnaires you complete
- Correspondence between us (emails, letters, messages)
- Consent forms and therapy agreements
- Payment records and invoices
- Notes from video sessions conducted via Zoom
How Your Data Is Stored
Your information is stored as follows:
- Electronic records are encrypted and password-protected on secure systems
- Access is restricted to me, Rachel Gibson
- My clinical supervisor receives anonymised case material only — no identifying information is share
Your Right to Erasure
Under UK GDPR, you have the right to request that I delete your personal data. However, this right is not absolute. I may need to refuse or limit erasure where:
- I am required to keep records for legal purposes (such as HMRC requirements)
- Retention is necessary for professional indemnity insurance
- Professional standards require me to maintain records
- The data is needed to establish, exercise, or defend legal claims
Secure Disposal
When the retention period ends, I dispose of your data securely:
- Electronic records are permanently deleted using secure deletion software that overwrites the data, making it unrecoverable
I maintain a disposal log to record when records have been securely deleted.
Questions or Complaints
If you have any questions about how long I keep your data, or if you wish to make a complaint about my data retention practices, please contact me:
Email: rachel@rachelgibsoncounselling.co.uk
If you are not satisfied with my response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.