Back to Home

Privacy Policy & Data Protection

Last updated: September 2026 • In compliance with UK GDPR and the BACP Ethical Framework

1. Introduction & Data Controller

Shelley Liu Counselling Service is committed to protecting your personal data, privacy, and maintaining the strictest standards of professional confidentiality. As an MBACP registered counsellor, I act as the Data Controller in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you have any questions about this policy or how your data is handled, please contact: shelleyliucounsellingpractice@gmail.com.

2. Information Collected

To provide professional, safe, and effective counselling, I may collect and process the following information:

  • Contact details: Name, email address, telephone number, and preferred appointment times submitted via the contact form or email.
  • Assessment & Intake information: Emergency contact information, GP details, and relevant personal background discussed during initial assessments.
  • Brief Session Notes: Anonymised, factual notes documenting attendance and therapeutic themes to support clinical continuity and supervision.

3. Lawful Basis for Processing

Under UK GDPR, I process your data under the following legal bases:

  • Contract: Processing necessary to fulfill our therapeutic agreement and provide counselling sessions.
  • Legitimate Interests: Maintaining accurate professional practice records in accordance with professional indemnity insurance and clinical supervision standards.
  • Special Category Data (Health Data): Processed under Article 9(2)(h) for the provision of health or social care, adhering to professional codes of confidentiality.

4. Confidentiality & Exceptional Circumstances

All communication and session content are kept strictly confidential. Exceptions to confidentiality are rare and mandated by law or safeguarding ethics:

  • If there is substantial risk of serious harm to yourself or another person.
  • If legally compelled by a court of law or under UK statutory requirements (e.g., safeguarding of children or vulnerable adults, terrorism, money laundering).
  • In clinical supervision, where case material is discussed anonymously with a qualified supervisor to ensure quality of care, as required by the BACP.

5. Storage and Security

All electronic records are kept securely on encrypted, password-protected systems. Any identifying details (such as names and contact numbers) are stored separately from anonymised session notes using unique identifier codes.

6. Data Retention

Clinical records and intake documents are retained securely for a period of up to 7 years following the end of therapy, in compliance with professional indemnity insurance requirements and clinical guidelines, after which they are securely deleted.

7. Your Rights

Under UK data protection law, you have rights including:

  • The right to access the personal data held about you.
  • The right to request correction of inaccurate personal data.
  • The right to request erasure of your data, subject to legal and insurance record-keeping requirements.
  • The right to lodge a concern with the Information Commissioner's Office (ICO) at ico.org.uk.