GDPR for Therapists: A Practical Checklist

15 May 2026

GDPR compliance sounds intimidating, but for most small wellness practices it comes down to a handful of concrete actions.

1. Know where your data lives

Make a list of every tool that stores client data: your email, calendar, booking system, notes app, and any cloud storage. For each one, confirm the data is stored in the EU or in a country with an adequacy decision.

2. Encrypt everything

Client notes, contact forms, and intake documents should be encrypted at rest and in transit. Most modern tools do this by default, but verify rather than assume.

3. Get explicit consent

Your intake form should include a clear consent checkbox. Keep a record of when and how consent was given.

4. Have a breach plan

If client data is ever exposed, you have 72 hours to report it to your supervisory authority. Know who to contact and what information they need.

5. Review annually

Set a calendar reminder to review your data handling once a year. Tools change, staff change, and small oversights compound.