Skip to main content

Guide

How long should you keep therapy records in the UK?

UK therapists: how long to keep therapy records, what your professional body says, GDPR rules, and what to do when retention periods end.

There is no single legally fixed retention period for therapy records in the UK. The right answer depends on your professional body's guidance, your client group, and the nature of the work — but the most commonly cited benchmark for adult clients is seven years after the end of treatment, or until age 25 if the client was a child when you worked with them (whichever is longer). Always confirm the current requirement with your professional body and check ICO guidance, as these figures can be updated.

Why there is no single answer

UK GDPR requires you to keep personal data only for as long as necessary for the purpose it was collected — the storage limitation principle. What counts as "necessary" in therapy is shaped by several overlapping considerations: the risk of a complaint or legal claim, safeguarding obligations, insurance requirements, and professional body guidance. None of these align neatly into one number, which is why you will find slightly different figures depending on where you look.

For NHS-employed therapists, the NHS Records Management Code of Practice sets explicit timelines. For those in private practice — the majority of BACP, UKCP, NCS, and BABCP members — your professional body's guidance is the primary reference point, alongside your indemnity insurer's requirements. Check both: your insurer may require records to be kept longer than your professional body recommends.

The benchmarks most UK therapists use

The figures below are widely cited in professional body guidance and CPD literature. Treat them as starting points, not settled law — confirm current requirements with your professional body.

Adult clients: Seven years after last contact is the most commonly recommended minimum. This broadly reflects the Limitation Act 1980, which sets a six-year window for most civil claims, with a year's buffer.

Child and young person clients: Records are generally kept until the client's 25th birthday, or for seven years after last contact — whichever is later. A young person cannot bring a claim in their own right until they turn 18, so the limitation clock starts later.

Clients who lacked mental capacity: Retention is often extended further — some guidance suggests until the client's 25th birthday or eight years after death. Take specific advice if this applies to your practice.

Deceased clients: Many practitioners keep records for a minimum of eight years after the date of death, though this varies by professional body.

If safeguarding concerns arose with any client, or if legal proceedings are a realistic prospect, keep records longer and document your reasoning.

What counts as a therapy record?

The scope is broader than most practitioners initially assume. Session notes, risk assessments, treatment plans, outcome measures, consent forms, correspondence with GPs or other professionals, supervision notes that identify a client, and appointment logs can all constitute personal data under UK GDPR. Each category may carry a slightly different retention rationale — consent records, for example, may need to be kept longer than session notes in some circumstances.

This applies equally to your clinical letters and any outcome data collected via tools such as the PHQ-9 or GAD-7 — those records carry the same obligations as your session notes.

Storing records securely during the retention period

Retention and security go together. UK GDPR requires appropriate technical and organisational measures throughout the period you hold data. In practice, for private practitioners that means:

  • Encrypted storage (cloud or device-level) for digital records
  • A clear data processing agreement with any third-party software you use
  • A written privacy notice telling clients how long you keep their data and why
  • A record of your retention policy in your practice's data protection documentation

If you use a clinical platform, check where data is hosted and whether the provider is ICO-registered. You can read about how Sorca handles this — including EU (Frankfurt) data residency and an immutable audit trail — on the trust page.

What to do when the retention period ends

Deletion needs to be documented. Recording what was destroyed, when, and by what method is standard practice; keep that destruction log (which contains no client personal data) as your audit trail. For paper records, cross-cut shredding or a confidential waste contractor is the norm. For digital records, confirm that deletion propagates to backups within a reasonable timeframe.

If a client exercises their right to erasure before your retention period ends, weigh that request against any legitimate grounds for continued retention — a legal claim you are aware of, or a safeguarding obligation. The ICO's guidance on the right to erasure sets out the exemptions; take advice rather than act unilaterally where there is genuine uncertainty.

One honest limitation

Professional body guidance on retention periods is not always consistent across BACP, UKCP, HCPC, NCS, and BABCP, and it does change. This article can give you the framework and the commonly cited figures, but it cannot substitute for reading your own professional body's current documentation and, where uncertainty remains, taking advice from your indemnity insurer or a solicitor with healthcare experience. Build a review of your retention policy into your annual practice audit rather than treating it as a one-off task.

Where Sorca fits

Sorca's safeguarding concern log and session records include an immutable audit trail, making it straightforward to demonstrate when records were created, accessed, and — when the time comes — deleted. The outcomes tracking tools collect PHQ-9 and GAD-7 data under the same GDPR-aligned framework, so your outcome measures sit within the same retention and erasure workflow as your clinical notes. Nothing enters a client record until you explicitly save it, and one-click export and erasure tools mean end-of-retention housekeeping takes minutes rather than an afternoon.

The free trial runs for three days with no card required.

Frequently asked questions

Do I have to keep therapy records for seven years in the UK?

Seven years after last contact is the most widely cited minimum for adult clients in private practice, broadly reflecting the Limitation Act 1980's six-year window for civil claims. It is professional body guidance rather than a statutory requirement, so confirm the current figure with your own professional body (BACP, UKCP, HCPC, NCS, or BABCP) and check your indemnity insurer's requirements, which may be longer.

How long should I keep records for a client who was a child when I worked with them?

The standard benchmark is until the client's 25th birthday or seven years after last contact, whichever is later. A young person cannot bring a civil claim in their own right until they turn 18, so the limitation period starts from that point rather than from the end of treatment.

Can a client ask me to delete their therapy records before the retention period ends?

Under UK GDPR, clients have a right to erasure, but it is not absolute. You may have legitimate grounds to refuse — for example, if you need the records to defend a legal claim or to meet a safeguarding obligation. Document your reasoning carefully and consider taking advice from your professional body or indemnity insurer before deciding.

What records do I need to keep, beyond session notes?

Therapy records include more than session notes. Consent forms, risk assessments, treatment plans, outcome measures (such as PHQ-9 and GAD-7 results), correspondence with GPs or other professionals, supervision notes that identify a client, and appointment logs can all constitute personal data under UK GDPR. Each category should be covered by your written retention policy.

Take the admin off your week

Sorca drafts the note while you stay present — audio never stored, nothing saved without your say-so. Three-day free trial, no card needed.

Start free — no card needed