Home › Guides › GDPR Article 9
Compliance guide
GDPR Article 9 for therapists, explained
Article 9 of the UK GDPR prohibits processing "special category" personal data — including data concerning health and mental health — unless a specific condition applies. For therapists, that means client notes, diagnoses and even attendance records are prohibited by default, and you must identify a lawful Article 9 condition, usually explicit consent or the health care provision condition, before keeping them.
What Article 9 actually says
Article 9(1) of the UK GDPR prohibits the processing of special categories of personal data. The list includes racial or ethnic origin, political opinions, religious beliefs, genetic data, biometric data, data concerning sex life or sexual orientation — and, most relevant to therapy, data concerning health [1].
The ICO confirms that health data includes mental health information, and that special category data needs more protection because it is more sensitive: its misuse can create significant risks to a person's fundamental rights and freedoms [2].
For a therapy practice, that scope is broad. It covers:
- Session notes, formulations and treatment plans
- Intake forms and risk assessments
- Trauma disclosures and relationship history where it reveals health information
- The bare fact that a person is a client of a therapist at all, since it reveals something about their mental health
The prohibition is the starting point
Article 9 works the opposite way round from ordinary personal data. Ordinary data can be processed if you have any lawful basis under Article 6. Special category data is prohibited unless you can also point to one of the ten conditions in Article 9(2) [1]. The ICO's guidance is explicit: you need both an Article 6 lawful basis and a separate Article 9 condition, and you should identify and document them before you begin processing [3].
Which Article 9 conditions fit private practice
Two conditions are realistic for most therapists in private practice:
Explicit consent — Article 9(2)(a)
The client "has given explicit consent to the processing of those personal data for one or more specified purposes" [1]. The ICO explains that explicit consent must be expressly confirmed in a clear statement — it cannot be inferred from conduct, a pre-ticked box, or silence [4]. Practically, that means a specific statement the client actively confirms, covering what sensitive data you hold and why, with a record of when they confirmed it. A signed, timestamped consent stored against the client record is the cleanest evidence.
Health care provision — Article 9(2)(h)
Processing necessary for "the provision of health or social care or treatment" carried out by or under the responsibility of a professional subject to an obligation of professional secrecy [1]. This condition, supplemented in the UK by Schedule 1 of the Data Protection Act 2018, can apply to therapists bound by a professional body's confidentiality obligations. Many practitioners still choose to obtain explicit consent as well, because it is clearer to clients and easier to evidence.
Whichever condition you rely on, the ICO expects you to document your choice, reflect it in your privacy information, and — for most Schedule 1 conditions — maintain an "appropriate policy document" [3].
What compliant record-keeping looks like day to day
- Consent captured before notes exist. If you rely on explicit consent, the confirmed statement should predate the first session record, and be stored where you can produce it.
- Security proportionate to sensitivity. The ICO requires appropriate security for special category data [3]. For digital records that means encryption, access controls such as two-step verification, and hosting in a jurisdiction with adequate protection (the UK or EU).
- Answerable data rights. Clients can request access to their records and, in some circumstances, erasure. You need to be able to export a complete record and delete data with proof when a valid request arrives.
- No sensitive data in insecure channels. Session content and health details do not belong in ordinary email threads or personal messaging apps.
How Caseload handles Article 9
Caseload was built inside a working UK practice for exactly this problem: consent to process sensitive data is signed and timestamped on the client record, records are encrypted and stored on EU servers only behind two-step verification, a full export of a client's record takes about thirty seconds, and deleting everything held on a client is one click with proof that it happened.
Frequently asked questions
Is therapy session data special category data under UK GDPR?
Yes. Article 9 lists data concerning health — which includes mental health — among the special categories. Session notes, diagnoses, risk assessments and even the fact that someone attends therapy fall within it, so processing is prohibited unless an Article 9(2) condition is met.
Do therapists need explicit consent to keep client notes?
Explicit consent under Article 9(2)(a) is the condition most private therapists rely on, but Article 9(2)(h) — health care provided under an obligation of professional secrecy — can also apply. Whichever you use, identify and document it before processing begins.
What makes consent "explicit" for sensitive data?
The ICO says explicit consent must be expressly confirmed in a clear statement rather than inferred from actions. A specific, recorded statement — ideally signed and timestamped — covering the sensitive data being processed is the most defensible form.
Can a client ask a therapist to delete their records?
Clients have rights of access, erasure and portability, though erasure is not absolute — you may have legal or professional grounds to retain some records. You need the practical ability to export a complete record and to delete data with evidence when a valid request is received.
Records that are compliant by default
Caseload keeps consent signed and timestamped on the record, data encrypted on EU servers, exports at thirty seconds and deletion at one click. Built in a UK practice, for practices like yours.
Book a demoSources
- UK GDPR, Article 9 — Processing of special categories of personal data. legislation.gov.uk. legislation.gov.uk/eur/2016/679/article/9
- ICO — Special category data (UK GDPR guidance and resources). ico.org.uk
- ICO — What are the rules on special category data? ico.org.uk
- ICO — What are the conditions for processing? ico.org.uk
This guide is general information for practitioners, not legal advice. For decisions about your own practice, consult the ICO's guidance or a data protection professional.