Data Protection Policy
Data Protection Policy
Helen Ward Therapy
Trading name of ResolvedRM Ltd
Version: 1.0
Effective Date: 30th May 2026
Review Date: 30th May 2027
1. Purpose
Helen Ward Therapy is committed to protecting the privacy, confidentiality and security of all personal information processed in the course of providing counselling and psychotherapy services.
This policy sets out how personal data is managed in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the BACP Ethical Framework for the Counselling Professions.
2. Scope
This policy applies to all personal information processed by Helen Ward Therapy, including information relating to:
-
Current clients
-
Prospective clients
-
Former clients
-
Enquiries
-
Suppliers and contractors (where applicable)
-
Website users
-
Any other individual whose personal data is processed by the practice
As a sole practitioner, Helen Ward is responsible for ensuring compliance with this policy.
3. Data Controller
Helen Ward Therapy, trading as ResolvedRM Ltd, is the Data Controller for all personal data processed within the practice.
The Data Controller is responsible for ensuring that personal information is processed lawfully, fairly, securely and transparently.
4. Data Protection Principles
Helen Ward Therapy will comply with the seven principles of UK GDPR by ensuring that personal data is:
Lawfulness, Fairness and Transparency
Personal information will be processed lawfully, fairly and transparently.
Individuals will be informed how their information is used through the Practice Privacy Policy.
Purpose Limitation
Information will only be collected for specified, explicit and legitimate purposes directly connected with providing counselling and psychotherapy services or meeting legal and professional obligations.
Data Minimisation
Only personal information that is necessary for the delivery of therapy or the operation of the practice will be collected.
Accuracy
Reasonable steps will be taken to ensure personal information remains accurate and up to date.
Clients are encouraged to notify the practice of any changes to their personal details.
Storage Limitation
Personal information will only be retained for as long as necessary in accordance with the practice Data Retention and Secure Disposal Policy and any applicable legal or professional requirements.
Integrity and Confidentiality
Appropriate technical and organisational measures will be implemented to protect information against unauthorised access, accidental loss, destruction, alteration or disclosure.
Accountability
Helen Ward Therapy accepts responsibility for demonstrating compliance with UK GDPR through appropriate policies, procedures, documentation and ongoing review.
5. Categories of Personal Data
The practice may process:
-
Contact information
-
Identification information
-
Appointment records
-
Financial information required for invoicing
-
Clinical notes
-
Therapy records
-
Correspondence
-
Risk assessments
-
Emergency contact details
-
GP details where appropriate
-
The practice also processes Special Category Data relating to health and mental wellbeing where necessary for the provision of counselling and psychotherapy.
6. Lawful Bases for Processing
Personal information is processed under one or more lawful bases set out in Article 6 UK GDPR.
Where Special Category Data is processed, an additional condition under Article 9 UK GDPR will also apply.
The principal lawful bases relied upon are:
-
Performance of a contract
-
Compliance with legal obligations
-
Legitimate interests
-
Provision of health and therapeutic care
-
Safeguarding where applicable
-
Establishment, exercise or defence of legal claims
-
Consent will be obtained where required by law or where specific disclosures fall outside the primary purposes of therapy.
7. Information Security
Helen Ward Therapy implements appropriate technical and organisational measures to safeguard personal information.
These measures may include:
-
Password-protected devices
-
Multi-factor authentication where available
-
Encryption where appropriate
-
Secure cloud storage
-
Secure email systems
-
Regular software updates
-
Antivirus protection
-
Secure disposal of confidential information
-
Restricted access to client information
-
Security measures are reviewed periodically to ensure they remain appropriate.
8. Confidentiality
All client information is treated as confidential.
Confidential information will only be disclosed where:
-
the client has provided appropriate authority;
-
disclosure is required by law;
-
there is a safeguarding concern;
-
disclosure is necessary to prevent serious harm; or
-
disclosure is otherwise permitted or required under applicable legislation or professional obligations.
Any disclosure will be limited to the minimum information necessary for the intended purpose.
9. Individual Rights
Individuals have the right to:
-
be informed;
-
access their personal information;
-
request rectification of inaccurate information;
-
request restriction of processing where applicable;
-
object to certain processing activities;
-
request erasure where legally applicable;
-
request data portability where appropriate; and
-
lodge a complaint with the Information Commissioner's Office (ICO).
Requests will be handled in accordance with the practice Subject Access Request Procedure.
10. Data Retention
Records will be retained in accordance with the practice Data Retention and Secure Disposal Policy.
At the end of the retention period, records will be securely destroyed or permanently deleted using appropriate methods.
11. Data Breaches
Any actual or suspected personal data breach will be managed promptly.
Where appropriate, the practice will:
-
investigate the breach;
-
take immediate steps to contain the incident;
-
assess the potential risks to individuals;
-
maintain a record of the breach;
-
notify the Information Commissioner’s Office where legally required; and
-
notify affected individuals where there is a high risk to their rights and freedoms.
Further guidance is contained within the practice Data Breach Procedure.
12. Data Sharing
Personal information will only be shared where there is a lawful basis to do so.
Information may be shared with:
-
healthcare professionals;
-
safeguarding authorities;
-
emergency services;
-
professional supervisors;
-
insurers;
-
legal representatives; or
-
regulatory authorities,
where appropriate and only to the extent necessary.
Information will never be sold or shared for marketing purposes.
13. International Transfers
Where personal information is processed outside the United Kingdom, appropriate safeguards will be implemented to ensure an equivalent level of protection in accordance with UK GDPR.
14. Staff Responsibilities
As Helen Ward Therapy operates as a sole practitioner business, Helen Ward is responsible for:
-
complying with this policy;
-
maintaining confidentiality;
-
protecting personal information;
-
reporting suspected data breaches without delay;
-
maintaining secure working practices;
-
ensuring records remain accurate;
-
keeping professional knowledge of data protection legislation up to date.
-
15. Monitoring and Review
This policy will be reviewed annually or sooner where there are changes in legislation, professional guidance, technology or business practices.
Any amendments will be documented and implemented promptly.
Related Documents
This policy should be read alongside the following practice documents:
-
Privacy Policy
-
Confidentiality Policy
-
Record Keeping Policy
-
Data Retention and Secure Disposal Policy
-
Subject Access Request Procedure
-
Data Breach Procedure
-
Information Security Policy
-
Online Therapy Policy
-
Client Contract
-
Consent Policy
-
Document Control
ICO Reference: ZC204139
Document Owner: Helen Ward Therapy
Approved By: Helen Ward
Version: 1.0
Effective Date: 30/05/26
Review Date : 30/05/27