Short answer: therapy is confidential in the UK, but confidentiality is not absolute. Therapists may disclose information where the law or safety demands it. Every UK-accredited practitioner works within a professional and legal framework that protects what you say in the room, with a small number of defined exceptions.
The main exceptions are:
- Serious harm or safeguarding concerns (risk to you, a child, or another person)
- Court orders or statutory duties requiring disclosure
- Other legal obligations, such as counter-terrorism reporting
Before your first session, you should receive a written contract or privacy notice explaining these limits and naming who sits within the "circle of confidentiality", such as a supervisor.
TL;DR:
- Confidentiality in UK therapy is protected but can be breached for serious harm, safeguarding, court orders, or legal obligations.
- Therapy records include notes, messages, recordings, and assessments, and require careful handling under UK GDPR regulations.
- Clients have rights to access, correct, and control their data, with providers required to notify breaches to the ICO within 72 hours.
- Online therapy uses the same confidentiality principles, but verifying encryption and data storage practices is essential for privacy.
- Supervisors review case details anonymously, and clients are encouraged to ask practitioners about confidentiality limits and data management upfront.
Table of Contents
- Therapy confidentiality UK: what counts as a record
- When can a therapist break confidentiality?
- What are your record-keeping and data rights?
- Is online therapy confidential in the UK?
- Why do therapists discuss cases with supervisors?
- How do you check a therapist's confidentiality practice?
- How does MySafeTherapy handle confidentiality?
- How we help clients feel safe about confidentiality
- Start confidential therapy with an accredited UK therapist
- Key Takeaways
- Sources
Therapy confidentiality UK: what counts as a record
Confidentiality in therapy covers more than the spoken word. It extends to session notes, text or chat messages, recordings, assessment forms, and anything written down about your case. A note scribbled after a session, a safeguarding referral, or a chat transcript from an online platform all count as records under UK GDPR and must be handled with the same care as your spoken disclosures.
Most practitioners work within a circle of confidentiality that can include:
- A clinical supervisor, who reviews casework to keep practice safe and accountable
- Colleagues in a multidisciplinary team, where relevant to your care
- Administrative staff who handle scheduling or billing, on a strictly need-to-know basis
None of these people should learn your name or identifying details unless there's a clear clinical reason. At the first session, expect a privacy notice, a plain explanation of confidentiality limits, and explicit consent requests for any digital tools such as recording software or messaging apps.
Pro Tip: Ask your therapist directly, "Who else might see notes about my sessions, and why?" A confident, specific answer is a good sign of solid practice.
When can a therapist break confidentiality?
UK counselling professionals treat confidentiality as the default, not a guarantee. The BACP's ethical framework sets out that disclosure without consent is justified only in defined circumstances, chiefly to prevent serious harm.
The recognised legal and ethical grounds for breaching confidentiality include:
- Preventing serious harm to you or someone else, including suicide risk or threats of violence
- Safeguarding duties involving children or vulnerable adults, often under the Children Acts
- Court orders compelling disclosure of records or testimony
- Statutory obligations, such as those covered in Gov, which sets out how providers balance safety and legal duty
The counselling condition within the Data Protection Act 2018 also permits processing personal data without consent when it's necessary and in the substantial public interest, a narrower test than many clients assume.
Reputable therapists don't disclose on a whim. Good practice follows three tests: necessity (is disclosure the only way to prevent harm?), proportionality (is the minimum information being shared?), and record-keeping (documenting the reasoning behind the decision). Wherever it's safe to do so, therapists tell the client what they're about to disclose and why, rather than acting silently behind the scenes.
What are your record-keeping and data rights?
Your therapist's notes, messages, and any recordings are personal data under UK GDPR and the Data Protection Act 2018, meaning you hold specific rights over them. Good practice, as set out in BACP's guidance on confidentiality and record keeping, favours records that are factual, proportionate, and securely stored, sometimes deliberately minimal to reduce risk.
Your rights include:
- Requesting access to your own records and receiving a response without undue delay
- Asking for inaccurate information to be corrected
- Querying how long records will be retained and why
- Expecting secure storage that limits access to those who genuinely need it
If a practitioner or platform suffers a data breach that risks your rights and freedoms, they must assess it and notify the Information Commissioner's Office within 72 hours of becoming aware. You should be told if your data was affected. For more detail on how these rights work in practice, see this guide to confidential support and client rights.
Is online therapy confidential in the UK?
Online therapy carries the same confidentiality duties as in-person work, but the technology adds new points of failure. Platform security, storage location, and recording policy all affect how private your sessions really are.
Before or during an online session, it's worth checking:
- Whether the platform uses end-to-end encryption for video, chat, and stored messages
- How long session data is retained, and whether it's stored within the UK or EEA
- Whether sessions are ever recorded, and what consent process applies if so
On your side, join calls from a private room, use headphones so conversation doesn't carry, and check your device is password protected and free of shared logins. Guidance on confidentiality and UK GDPR from the British Psychoanalytic Council stresses that clinicians should be competent in the platform they use and transparent about how client data is handled, not just clinically competent in the room.
Pro Tip: If a therapist can't explain in plain terms where your data is stored or whether calls are encrypted, that's a fair reason to ask more questions before continuing. You can read more in this breakdown of confidential online support for UK adults.
Why do therapists discuss cases with supervisors?
Clinical supervision is a mandatory, routine part of safe therapeutic practice, not a lapse in confidentiality. Every BACP-registered therapist works with a supervisor who reviews casework to check judgement, spot risk, and support ethical decision-making.
Case discussions in supervision are almost always anonymised: no name, no identifying detail, just the clinical material needed to reflect on the work. You should be told at the outset that supervision happens, and that a fully anonymised version of your case may be discussed. Within an organisation, only staff with a genuine clinical or administrative reason, such as a co-ordinating manager, should ever have access to your file.

How do you check a therapist's confidentiality practice?
A confident practitioner will welcome direct questions about privacy rather than treating them as awkward. Before your first paid session, it's reasonable to ask:
- "What exactly is in my confidentiality contract, and what are the limits?"
- "Who is in the circle of confidentiality for my case, and why?"
- "How do I request a copy of my records, and how long will that take?"
Under UK GDPR, subject access requests should normally be answered within one month. If something feels wrong, start with the therapist or provider's internal complaints process. If that doesn't resolve things, escalate to their professional body, such as BACP, the HCPC, or NCPS, depending on registration. Data protection concerns specifically can be raised directly with the ICO.
How does MySafeTherapy handle confidentiality?
Mysafetherapy connects clients with UK-accredited therapists registered with BACP, UKCP, or NCPS, each bound by the same ethical framework and statutory duties covered above. Every client receives clear contracting and a privacy notice before sessions begin, setting out what's confidential and what isn't.
The platform offers several formats so clients can choose the level of exposure they're comfortable with:
- One-to-one video sessions
- Text-based chat therapy
- Avatar-based sessions for clients who prefer more anonymity
Pricing is transparent, session frequency is flexible, and switching therapists is straightforward if the fit or comfort level isn't right. Details on how the process works in practice are covered in this guide to the confidential therapy process for UK adults. Privacy concerns raised on the platform are handled through the same contracted process described above.
How we help clients feel safe about confidentiality
Mysafetherapy is built on the principle that trust comes from clear contracting, not vague reassurance. Clients can switch therapists freely if something doesn't feel right, and any privacy concern raised is dealt with directly and transparently rather than deflected. If you're weighing up whether online therapy is right for you, our start therapy page is the natural next step.
— MySafeTherapy
Start confidential therapy with an accredited UK therapist
Every therapist on Mysafetherapy is registered with BACP, UKCP, or NCPS and works to the same confidentiality contracting and privacy notice standards covered throughout this guide. That means you get the legal and ethical protections described above, without having to chase a provider for answers about who sees your data or how it's stored.
Choose the format that suits your comfort level, from one-to-one video and text-based chat therapy to more anonymous avatar therapy. Pricing is stated upfront, session frequency flexes around your schedule, and you can switch therapists at any point if the fit isn't right. If confidentiality concerns are holding you back from starting, book a session with an accredited therapist and put your questions to them directly at the first appointment, or browse the full range of conditions supported to find the right starting point.
Key Takeaways
Confidentiality in UK therapy is the professional default, overridden only for defined safety, safeguarding, or legal reasons, and clients have enforceable rights over how their records are handled.
| Point | Details |
|---|---|
| Confidentiality has limits | Serious harm, safeguarding duties, and court orders are the main lawful exceptions to disclosure. |
| Contracting comes first | Expect a privacy notice and confidentiality contract explaining limits before your first paid session. |
| Records carry UK GDPR rights | You can request access, correction, and retention details, usually answered within one month. |
| Breaches must be reported | Providers must assess and report serious data breaches to the ICO within 72 hours. |
| Mysafetherapy follows the standard | It matches clients with BACP, UKCP, or NCPS-registered therapists under clear contracting and privacy notices. |
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- BACP ethical framework for the counselling professions
- Data Protection Act 2018 — counselling condition (schedule)
- ICO — personal data breach guidance
- Gov

