Skip to main content

Guide

Safeguarding record-keeping in private practice: what to write down and why it matters

A practical guide for private therapists on what safeguarding records to keep, how to structure them, and how long to retain them. UK-focused.

When a safeguarding concern arises in private practice, your records are your evidence. Write down what was said or observed, what you decided, who you contacted, and when — in plain, factual language, as close to the session as possible. A clear, contemporaneous record protects your client, supports any statutory investigation, and demonstrates you acted responsibly if your practice is ever audited or questioned.

Why safeguarding records differ from ordinary session notes

Routine clinical notes capture the therapeutic process. Safeguarding records do something different: they create a factual, time-stamped account of a concern and your response to it. If a case reaches a child protection conference, a court, or a professional conduct hearing, these records may be read by people who know nothing about your therapeutic model. They need to stand alone.

That distinction has practical consequences. Keep safeguarding concerns in a separate log, not buried inside a narrative session note. The concern, the risk level you assigned, the action you took, and the outcome should each appear as discrete, dated entries. Mixing them into process notes makes them harder to retrieve and harder for others to interpret.

What to record for every concern

A good safeguarding entry covers six things:

  1. Date and time — when the concern arose, not just when you wrote it up.
  2. What was said or observed — use the client's words where possible, in quotation marks. Avoid interpretation at this stage; record what you actually heard or saw.
  3. Your assessment of risk — low, medium, or high, with a brief rationale. You don't need to diagnose or predict; you need to show you thought it through.
  4. What you decided to do — refer to statutory services, consult a supervisor, take no further action at this time, and so on.
  5. Who you contacted — name, role, organisation, and method of contact (phone, secure email, referral form).
  6. The outcome or next step — what happened as a result, or when you plan to review if nothing has changed.

If you consulted your supervisor before deciding, record that conversation too: date, what you discussed, and what advice was given. Supervision is not a rubber stamp — it's part of your decision-making trail.

Language that holds up under scrutiny

Write in plain English. Avoid jargon, hedging phrases such as "it seemed as though", and anything that could read as minimising. "Client disclosed that her partner had hit her across the face on two occasions in the past month" is more useful than "client appeared distressed and mentioned some difficulties at home."

Keep clinical interpretation out of the factual record; save formulation for your session notes. The safeguarding log is not the place to explore attachment patterns — it's the place to record facts and decisions.

If you're uncertain whether something meets a threshold for referral, record that uncertainty and what you did about it — typically, consulting a supervisor or your professional body's advice line. Demonstrating that you sought guidance is itself evidence of good practice.

Retention: how long to keep safeguarding records

Retention periods are not straightforward. The right answer depends on whether the concern involved a child or a vulnerable adult, whether a referral was made to statutory services, and your professional body's current guidance. Records relating to safeguarding concerns are generally retained longer than ordinary clinical notes — sometimes significantly longer — because they may be needed years later in legal proceedings.

Don't rely on a single figure you read online. Check current guidance from your professional body (BACP, UKCP, HCPC, NCS, or BABCP as relevant) and, where children are involved, guidance from your local safeguarding children partnership. The ICO's documentation on lawful bases and retention under UK GDPR is worth reviewing directly at ico.org.uk. What matters is that you have a documented retention policy, can justify it, and apply it consistently.

Storing records securely

Safeguarding records must be stored securely, with access limited to those who need it. In private practice that usually means you alone, unless a supervisor or administrator has a legitimate reason to access them. Paper records should be locked away; digital records should be encrypted and password-protected, held on UK or EU servers, and covered by your data processing documentation.

If you use a practice management system, check whether it keeps an immutable audit trail — a log of who accessed or edited an entry and when. That matters if records are ever challenged. You can read more about how Sorca handles data, including UK GDPR alignment and EU data residency, at /trust.

Honest limitation: records are necessary but not sufficient

Good records don't replace good judgement, and they won't protect you if the underlying decision was wrong. A well-documented decision to take no further action on a serious risk is still a poor decision. Records support accountability; they don't substitute for it. If you're uncertain about a threshold, consult your supervisor or your professional body's ethics or safeguarding advice line before deciding — then record that you did.

Connecting safeguarding to the rest of your practice documentation

Safeguarding concerns rarely arise in isolation. They often appear alongside risk indicators in outcome measures — a sudden drop in PHQ-9 scores, or a WSAS score suggesting someone is struggling to function. Keeping your outcomes tracking and safeguarding log in the same system makes it easier to spot patterns over time and to demonstrate a joined-up response if you're asked to account for your practice.

If a concern leads to a GP letter, a referral, or a report to statutory services, those documents are part of the record too. Drafting them carefully and keeping copies matters as much as the log entry itself. Sorca's clinical letters feature can help you draft referral and GP letters in a consistent format, though the clinical content and decision to send always remain yours.

Where Sorca fits

Sorca includes a safeguarding concern log where you can record typed concerns, assign risk levels, note actions taken, and export entries as part of an audit-ready document. Audio is never stored — transcription happens in the browser and is discarded after your note is drafted, as explained at /trust. Nothing enters your records until you explicitly save it.

The free trial runs for three days and requires no card.

Frequently asked questions

Do I need a separate safeguarding log or can I record concerns in my session notes?

A separate log is strongly advisable. Safeguarding records need to be retrievable quickly and readable by people outside your therapeutic frame — mixing them into narrative session notes makes both harder. Keep the concern, risk level, decision, and any referral as discrete, dated entries in their own document.

How long should I keep safeguarding records in private practice?

There's no single fixed period that applies to every situation — it depends on whether children or vulnerable adults were involved, whether a statutory referral was made, and your professional body's current guidance. Check directly with your professional body and review the ICO's retention guidance; records involving children are often retained for significantly longer than standard clinical notes.

What if I decide not to refer — do I still need to record the concern?

Yes, and this is arguably when documentation matters most. Record what you observed or heard, your reasoning for not referring at this time, any supervision or advice you sought, and when you plan to review. A documented decision not to refer shows you considered the concern seriously rather than overlooking it.

Can I share safeguarding records with a client who makes a subject access request?

Under UK GDPR, clients generally have the right to access their personal data, but there are exemptions where disclosure could prejudice the prevention or detection of crime or harm a third party. This is a nuanced area — seek guidance from the ICO or your professional body before responding to a subject access request that touches on safeguarding records.

Take the admin off your week

Sorca drafts the note while you stay present — audio never stored, nothing saved without your say-so. Three-day free trial, no card needed.

Start free — no card needed