Record-Keeping & Data Retention Policy — Carl Argent Counselling and Coaching
Record-Keeping & Data Retention Policy
Read the practice policy below. You can contact me if anything is unclear or you need another format.
|
Policy Owner: Carl Argent / Carl Argent Counselling & Coaching Date of Policy: 01/08/2025 Review Date: 01/08/2026 |
1. Purpose
This policy outlines how Carl Argent Counselling & Coaching creates, stores, retains, and disposes of client data. Its purpose is to ensure:
- Compliance: Adherence to the General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the BACP Ethical Framework for the Counselling Professions.
- Transparency: Clients understand exactly what is recorded and how long it is kept.
- Safety: Clinical records are preserved to ensure continuity of care and professional accountability.
2. What Data I Hold
I hold two distinct categories of data:
Clinical Records: Session notes, assessment forms, contracts, and any significant correspondence (emails/letters).
- Note: Session notes are brief, factual summaries of the themes discussed. I do not record verbatim conversations or speculative interpretations.
Administrative Data: Contact details (name, address, GP), invoicing records, and attendance logs.
Retention Periods
In accordance with legal limitation periods and professional best practice, I retain data for the following durations:
|
Data Type |
Retention Period |
Reason |
|
Adult Session Notes |
7 years after the end of therapy. |
To defend against potential civil claims (Limitation Act 1980 allows claims up to 6 years post-event). |
|
Child Session Notes |
Until the client turns 25 (or 26 if child turns 17 when therapy ended). |
To allow the client time to bring a claim after reaching adulthood. |
|
WhatsApp Messages |
24 hours |
As per my Digital Communications Policy, these are exported (if therapeutic) or deleted (if administrative) immediately. |
Storage & Security
I am committed to keeping your data secure.
- Paper Records: Stored in a locked filing cabinet within a secure office. Keys are held only by me.
- Electronic Records: Stored on a password-protected device with full-disk encryption. Files are backed up to a secure, GDPR-compliant cloud service (e.g., ProtonDrive / OneDrive with 2FA).
- Email: My devices are password-protected and I use a secure email provider.
Disposal of Data
Once the retention period has expired, data is disposed of securely:
- Paper Records: Cross-cut shredded.
- Electronic Records: Permanently deleted (including from “Deleted Items” and backups).
The “Professional Will” (Professional Executor)
In the event of my sudden death or incapacitation, I have appointed a Clinical Executor (a trusted person).
- They will be granted access to my client list solely for the purpose of contacting you to notify you of the situation and offering support in finding a new therapist.
- They are bound by the same confidentiality agreements as I am.
Your Rights (GDPR)
Under the GDPR, you have specific rights regarding your data:
- Right of Access: You may request a copy of your clinical notes (Subject Access Request). I will provide this within one calendar month, usually free of charge.
- Right to Rectification: If you believe a factual error exists in your notes (e.g., wrong address), you may ask for it to be corrected.
- Right to Erasure (“Right to be Forgotten”): You may ask for your data to be deleted.
- Important Limitation: This right is not absolute. I may decline to delete clinical notes if they are still within the 7-year retention period, as I have a “Legitimate Interest” (legal defense) in retaining them.
Suspension of Deletion
If a complaint, legal action, or insurance claim is raised (or threatened) during the retention period, no data will be deleted until the matter is fully resolved, even if the 7-year limit is reached.
