Rachel Gibson MBACP

Psychotherapeutic Counselling

GDPR

Last updated: 26th July 2026

Our Commitment to Your Privacy

At Rachel Gibson Counselling, I believe that protecting your privacy is fundamental to our therapeutic relationship. Trust is at the heart of the work we do together, and that includes being completely transparent about how I handle your personal information. This statement explains, in plain terms, what data I collect, why I need it, and how I keep it safe.

What Information I Collect

When you work with me, I may collect and keep the following types of information:

Why I Collect This Information

I need to collect and use your information for two main reasons:

To provide your therapy

Under Article 6(1)(b) UK GDPR, processing your information is necessary for the performance of the therapeutic contract between us. In simple terms, I cannot offer you a counselling service without knowing who you are and keeping appropriate records of our work together.

Because therapy involves health information

The things you share in our sessions often relate to your mental and emotional health. This is called "special category data" under data protection law, and I am permitted to process it under Article 9(2)(h) UK GDPR — because processing is necessary for the provision of health or social care treatment by a health professional. The additional legal requirement I rely on is DPA 2018 Schedule 1, Part 1, paragraph 2 (health or social care).

Professional Obligations and Supervision

As a qualified counsellor, I am required to discuss my clinical work in regular supervision sessions. This is an essential part of maintaining safe, ethical practice and ensuring you receive the best possible support.

Your identity is always protected. I do not share your name or any identifying details with my supervisor. All case material discussed is anonymised — meaning my supervisor has no way of knowing who you are. My supervisor is also bound by their own professional body's strict confidentiality obligations.

When I Might Need to Break Confidentiality

What you share with me stays between us in almost all circumstances. However, there are rare situations where I may need to share information without your consent:

I will always try to discuss this with you first wherever it is safe and possible to do so. Breaking confidentiality is never a decision I would take lightly.

How Long I Keep Your Records

I keep your records for 7 years after our last session. This retention period is in line with the Limitation Act 1980 and standard professional indemnity insurance requirements.

All records are stored electronically, encrypted and password-protected on secure systems. Access is restricted to me alone (and anonymised material only to my supervisor, as described above).

At the end of the retention period, your records are securely deleted.

Your Rights

Under UK GDPR and the Data (Use and Access) Act 2025, you have important rights over your personal information:

If you would like to exercise any of these rights, simply get in touch with me and I will respond promptly.

Making a Complaint

If you are unhappy with how I have handled your personal information, I would encourage you to contact me first so we can try to resolve the issue together:

Email: rachel@rachelgibsoncounselling.co.uk

You also have the right to complain directly to the Information Commissioner's Office (ICO):

Website: ico.org.uk

Telephone: 0303 123 1113