Skip to content

How long should a UK therapist keep client records?

United Kingdom · Published 15 August 2026

There is no statutory retention period for psychotherapy records in UK private practice. UK GDPR requires only that you keep records no longer than is necessary, and that you can say what necessary means for your practice, in writing.

Why there is no single answer

Practitioners expect a number because medicine has numbers. Private psychotherapy does not, and the reason is structural rather than accidental. Retention obligations in UK law attach to specific statutory functions. An NHS trust holds records under a framework built for NHS bodies. A solo practitioner in a rented room does not sit inside that framework, and no equivalent framework was ever built for her.

What applies to you instead is the storage limitation principle in Article 5(1)(e) of the UK GDPR, which requires that personal data be kept in a form permitting identification of the person for no longer than is necessary for the purposes for which it is processed.

That is a principle, not a period. It puts the burden on you to define the purpose, define the period that serves it, and be able to justify both if asked. The upside is flexibility: a practitioner working with adults referred by a GP has genuinely different needs from one running a low-cost counselling service for students. The downside is that "I keep everything forever" and "I shred at the end of therapy" both sound like positions, and both are usually wrong.

One thing to establish before going further. Clinical notes are special category data. They concern health, and Article 9 of the UK GDPR treats health data as requiring more than an ordinary lawful basis. That is not a retention question in itself, but it changes the documentation you need around retention, which matters later in this guide.

The three reference points practitioners actually use

Nobody arrives at a retention period from first principles. In practice everyone triangulates between the same three sources.

The NHS Records Management Code of Practice. It retains adult mental health records for 20 years from the date of last contact with the service, or 8 years after death. Records of children and young people are retained until the patient's 25th birthday, or their 26th if the young person was 17 when treatment concluded. Those periods do not bind private practice. But they are the closest thing to a professional consensus in this country, and it is difficult to be criticised for having followed the standard the health service itself applies. Most practitioners treat them as a sensible ceiling rather than a floor.

The Limitation Act 1980. This governs how long a claim can be brought against you, and it is the reason children's records are kept far longer than adults'. Where the person was a child when the cause of action arose, time does not begin to run until their eighteenth birthday, and the ordinary limitation period runs from there. If you cannot produce a record, you cannot defend a claim with it.

Your indemnity insurer's policy terms. In practice this is the binding one, and the one practitioners most often forget. Many policies specify a minimum retention period as a condition of cover. Destroying records earlier than your policy requires can compromise your own defence at exactly the moment you need it. Read the wording rather than relying on what a colleague told you, because insurers differ.

Where the three point at different periods, take the longest, and record why.

What a defensible retention policy contains

The requirement is not that you chose the right number. There is no right number. The requirement is that you can show you thought about it, and that what you do matches what you wrote down.

A one page policy that a solo practitioner can actually maintain contains six things.

  1. The categories of record you hold, listed separately. Clinical notes, correspondence, financial records, consent forms, supervision notes. They are different categories serving different purposes and they should not share a single period by default.
  2. A retention period for each category, with a one line reason. The reason matters more than the number. "Twenty years from last contact, following the NHS Code" is a defensible sentence. "Twenty years" on its own is not.
  3. The trigger that starts the clock. Almost always the date of last contact, not the date of the note. This matters more than it sounds. A client seen weekly for three years generates notes spanning three years, and if the clock ran per note you would be destroying the early ones while the work was still live.
  4. Different treatment for records of clients seen as children, with the reason stated. This is where most policies are thin, and it is the first thing a solicitor would look at.
  5. What destruction actually means in your setup. Including backups, including any cloud service, including whether anyone else can restore what you deleted, and including who performs it.
  6. A review date. Annually is fine. The point is that the policy is a live document rather than something written once and forgotten.

If you process special category data, and clinical notes are special category data, you also need an appropriate policy document under Schedule 1 of the Data Protection Act 2018, covering the condition you rely on. Retention is one of the things that document has to address, so in practice the two are written together rather than separately.

A worked example

A practitioner sees adults only, in private practice, with professional indemnity cover.

Her insurer's policy wording requires records to be retained for the duration of the policy plus a defined run-off period. That gives her a floor. The NHS Code, which she is not bound by but uses as a reference, points at twenty years from last contact, which is considerably longer. She has no clients who were minors, so the limitation complication does not apply to her current caseload.

She sets clinical notes at twenty years from last contact, and writes one sentence explaining that she has adopted the health service standard because she could not justify a shorter one if challenged. She sets financial records separately, on the period her accountant specifies for HMRC purposes. She notes that if she ever takes on a client under eighteen, a longer period applies, and she writes that period down now rather than working it out under pressure later.

The whole thing is a page. It took her an afternoon. If the ICO or a solicitor ever asks, she has an answer, and the answer is consistent with what she actually does.

That last clause is the one that matters. A policy you do not follow is worse than no policy, because it documents the gap.

The part most practitioners get wrong

Deletion has to reach the backups.

A practitioner who deletes a client folder from her laptop, while her cloud sync keeps thirty days of version history, has not deleted anything for thirty days. That is not necessarily a problem, but it has to be stated in the policy rather than quietly ignored. The alternative is a policy that says one thing while the system does another, which is exactly the gap that turns a minor incident into a serious one.

The harder version of this problem belongs to practitioners using general purpose tools that were never designed for clinical records. A note-taking app with no deletion guarantee, no way to see what is retained, and no ability to answer the question "is it actually gone" makes point five of the policy above impossible to complete honestly. That is worth knowing before you build a practice around one rather than after.

The arrangement nobody makes

What happens to your records if you die, or have a stroke, or are otherwise unable to practise tomorrow.

Every professional body expects you to have answered this and almost nobody has. It requires three things: a named person who has agreed to do it, written instructions specific enough for them to follow without you, and a practical means for them to actually gain access to the records, which in an era of password managers and two factor authentication is the part that quietly fails.

Your retention policy should reference the arrangement. The two documents belong together, because the person carrying out your wishes needs to know what to keep, for how long, and what to do at the end of it.

References

  • UK GDPR, Article 5(1)(e), storage limitation
  • UK GDPR, Article 9, special categories of personal data
  • UK GDPR, Article 17, right to erasure and its exemptions
  • Data Protection Act 2018, Schedule 1, and the appropriate policy document requirement
  • Limitation Act 1980, including the provisions on persons under a disability
  • NHS England, Records Management Code of Practice, retention schedule
  • Your professional body's guidance, and your own indemnity policy wording

Frequently asked questions

Is there a legal minimum for how long a therapist must keep client records in the UK?

No. No statute sets a retention period for private psychotherapy records. UK GDPR requires only that you keep personal data no longer than is necessary for the purpose you are processing it for, and that you can explain what necessary means for your practice. The absence of a number is why practitioners have to set their own period and write down the reasoning.

What retention period does the NHS apply to mental health records?

The NHS Records Management Code of Practice retains adult mental health records for 20 years from the date of last contact with the service, or 8 years after death. Records of children and young people are retained until the patient's 25th birthday, or their 26th if they were 17 when treatment concluded. These periods do not bind private practice, but they are the closest thing to a professional consensus in England and Wales and most practitioners use them as a reference point.

Why are records of clients seen as children kept longer?

Because of how limitation works. Under the Limitation Act 1980, time does not start running against someone who was a child when the cause of action arose until they turn eighteen. The ordinary limitation period then begins from that birthday, which pushes the horizon out by years. If a claim can still be brought, you may still need the record to answer it.

Does a client's right to erasure override my retention period?

Not automatically. The right to erasure is qualified, and one of the qualifications is that the data is still needed for the establishment, exercise or defence of legal claims. That is precisely what clinical records are for. You still have to consider each request on its own facts, respond within the statutory time limit, and explain your reasoning if you refuse.

Do process notes count as records?

If they identify the client, directly or indirectly, they are personal data and they are in scope. Pseudonymised notes are still personal data while you hold the key that links them back to a person. Genuinely anonymised notes fall outside data protection law, but the bar for genuine anonymisation is considerably higher than changing a name and using initials.

How long should I keep records for a client I saw once for an assessment that went nowhere?

The same period as any other client. The relevant question is not how much therapy took place, it is how long a claim could be brought and how long you might need the record to answer one.

Do financial records follow the same period as clinical notes?

No, and they should be listed separately in your policy for that reason. Invoices, receipts and accounts answer to HMRC on a different timescale and for a different purpose. Folding them into the clinical retention period makes the policy harder to defend, because the justification for each is different.

What happens to my records if I die or become unable to practise?

This is the question almost nobody plans for and every professional body expects you to have answered. It needs a named person who has agreed to act, written instructions specific enough to follow without you, and a practical means for them to gain access. Your retention policy should reference the arrangement rather than treating it as a separate problem.

Last reviewed 15 August 2026. General information for practitioners, not legal advice.