top of page

Data Protection Policy

Data Protection Policy

Helen Ward Therapy
Trading name of ResolvedRM Ltd

Version: 1.0
Effective Date: 30th May 2026

Review Date: 30th May 2027

1. Purpose

Helen Ward Therapy is committed to protecting the privacy, confidentiality and security of all personal information processed in the course of providing counselling and psychotherapy services.

This policy sets out how personal data is managed in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the BACP Ethical Framework for the Counselling Professions.

2. Scope

This policy applies to all personal information processed by Helen Ward Therapy, including information relating to:

  • Current clients

  • Prospective clients

  • Former clients

  • Enquiries

  • Suppliers and contractors (where applicable)

  • Website users

  • Any other individual whose personal data is processed by the practice

As a sole practitioner, Helen Ward is responsible for ensuring compliance with this policy.

3. Data Controller

Helen Ward Therapy, trading as ResolvedRM Ltd, is the Data Controller for all personal data processed within the practice.

The Data Controller is responsible for ensuring that personal information is processed lawfully, fairly, securely and transparently.

 

 

4. Data Protection Principles

Helen Ward Therapy will comply with the seven principles of UK GDPR by ensuring that personal data is:

Lawfulness, Fairness and Transparency

Personal information will be processed lawfully, fairly and transparently.

Individuals will be informed how their information is used through the Practice Privacy Policy.

Purpose Limitation

Information will only be collected for specified, explicit and legitimate purposes directly connected with providing counselling and psychotherapy services or meeting legal and professional obligations.

Data Minimisation

Only personal information that is necessary for the delivery of therapy or the operation of the practice will be collected.

Accuracy

Reasonable steps will be taken to ensure personal information remains accurate and up to date.

Clients are encouraged to notify the practice of any changes to their personal details.

Storage Limitation

Personal information will only be retained for as long as necessary in accordance with the practice Data Retention and Secure Disposal Policy and any applicable legal or professional requirements.

Integrity and Confidentiality

Appropriate technical and organisational measures will be implemented to protect information against unauthorised access, accidental loss, destruction, alteration or disclosure.

Accountability

Helen Ward Therapy accepts responsibility for demonstrating compliance with UK GDPR through appropriate policies, procedures, documentation and ongoing review.

 

 

5. Categories of Personal Data

The practice may process:

  • Contact information

  • Identification information

  • Appointment records

  • Financial information required for invoicing

  • Clinical notes

  • Therapy records

  • Correspondence

  • Risk assessments

  • Emergency contact details

  • GP details where appropriate

The practice also processes Special Category Data relating to health and mental wellbeing where necessary for the provision of counselling and psychotherapy.

6. Lawful Bases for Processing

Personal information is processed under one or more lawful bases set out in Article 6 UK GDPR.

Where Special Category Data is processed, an additional condition under Article 9 UK GDPR will also apply.

The principal lawful bases relied upon are:

  • Performance of a contract

  • Compliance with legal obligations

  • Legitimate interests

  • Provision of health and therapeutic care

  • Safeguarding where applicable

  • Establishment, exercise or defence of legal claims

Consent will be obtained where required by law or where specific disclosures fall outside the primary purposes of therapy.

7. Information Security

Helen Ward Therapy implements appropriate technical and organisational measures to safeguard personal information.

These measures may include:

  • Password-protected devices

  • Multi-factor authentication where available

  • Encryption where appropriate

  • Secure cloud storage

  • Secure email systems

  • Regular software updates

  • Antivirus protection

  • Secure disposal of confidential information

  • Restricted access to client information

Security measures are reviewed periodically to ensure they remain appropriate.

8. Confidentiality

All client information is treated as confidential.

Confidential information will only be disclosed where:

  • the client has provided appropriate authority;

  • disclosure is required by law;

  • there is a safeguarding concern;

  • disclosure is necessary to prevent serious harm; or

  • disclosure is otherwise permitted or required under applicable legislation or professional obligations.

Any disclosure will be limited to the minimum information necessary for the intended purpose.

9. Individual Rights

Individuals have the right to:

  • be informed;

  • access their personal information;

  • request rectification of inaccurate information;

  • request restriction of processing where applicable;

  • object to certain processing activities;

  • request erasure where legally applicable;

  • request data portability where appropriate; and

  • lodge a complaint with the Information Commissioner's Office (ICO).

Requests will be handled in accordance with the practice Subject Access Request Procedure.

10. Data Retention

Records will be retained in accordance with the practice Data Retention and Secure Disposal Policy.

At the end of the retention period, records will be securely destroyed or permanently deleted using appropriate methods.

11. Data Breaches

Any actual or suspected personal data breach will be managed promptly.

Where appropriate, the practice will:

  • investigate the breach;

  • take immediate steps to contain the incident;

  • assess the potential risks to individuals;

  • maintain a record of the breach;

  • notify the Information Commissioner’s Office where legally required; and

  • notify affected individuals where there is a high risk to their rights and freedoms.

Further guidance is contained within the practice Data Breach Procedure.

12. Data Sharing

Personal information will only be shared where there is a lawful basis to do so.

Information may be shared with:

  • healthcare professionals;

  • safeguarding authorities;

  • emergency services;

  • professional supervisors;

  • insurers;

  • legal representatives; or

  • regulatory authorities,

where appropriate and only to the extent necessary.

Information will never be sold or shared for marketing purposes.

13. International Transfers

Where personal information is processed outside the United Kingdom, appropriate safeguards will be implemented to ensure an equivalent level of protection in accordance with UK GDPR.

14. Staff Responsibilities

As Helen Ward Therapy operates as a sole practitioner business, Helen Ward is responsible for:

  • complying with this policy;

  • maintaining confidentiality;

  • protecting personal information;

  • reporting suspected data breaches without delay;

  • maintaining secure working practices;

  • ensuring records remain accurate;

  • keeping professional knowledge of data protection legislation up to date.

15. Monitoring and Review

This policy will be reviewed annually or sooner where there are changes in legislation, professional guidance, technology or business practices.

Any amendments will be documented and implemented promptly.

Related Documents

This policy should be read alongside the following practice documents:

  • Privacy Policy

  • Confidentiality Policy

  • Record Keeping Policy

  • Data Retention and Secure Disposal Policy

  • Subject Access Request Procedure

  • Data Breach Procedure

  • Information Security Policy

  • Online Therapy Policy

  • Client Contract

  • Consent Policy

Document Control

ICO Reference: ZC204139

Document Owner: Helen Ward Therapy

Approved By: Helen Ward

Version: 1.0

Effective Date: 30/05/26

Review Date : 30/05/27

bottom of page