GDPR for Therapists: A Practical Checklist
15 May 2026
GDPR compliance sounds intimidating, but for most small wellness practices it comes down to a handful of concrete actions.
1. Know where your data lives
Make a list of every tool that stores client data: your email, calendar, booking system, notes app, and any cloud storage. For each one, confirm the data is stored in the EU or in a country with an adequacy decision.
2. Encrypt everything
Client notes, contact forms, and intake documents should be encrypted at rest and in transit. Most modern tools do this by default, but verify rather than assume.
3. Get explicit consent
Your intake form should include a clear consent checkbox. Keep a record of when and how consent was given.
4. Have a breach plan
If client data is ever exposed, you have 72 hours to report it to your supervisory authority. Know who to contact and what information they need.
5. Review annually
Set a calendar reminder to review your data handling once a year. Tools change, staff change, and small oversights compound.