A privacy notice for your therapy practice: free template and a guide to customising it
Download a plain-English privacy notice template, then work through this guide to make it yours before the BACP’s 3 November deadline.
If you read my guide to AI and the BACP Ethical Framework 2026, you’ll know one of the practical jobs it leaves every member: a clear, accessible privacy notice that covers the digital tools your practice uses, in place before the framework becomes mandatory on 3 November 2026.
Most therapists I speak to know they need one. Far fewer feel confident writing one. The privacy notices I see on therapy websites tend to be either missing, copied from a generic business template full of legal jargon, or written in 2018 and untouched since.
So I’ve built a template to save you starting from a blank page. It’s written in plain English, in the first person, for a UK therapy practice, and it includes the digital and AI tools section the 2026 framework expects.
One thing to be clear about before you open it. This is not legal advice. I’m a marketing consultant who builds websites for therapists, not a lawyer or a data protection specialist. The template and this guide are practical support to get you moving, and responsibility for your published notice stays with you. If you’re unsure about your own UK GDPR obligations, or anything in the template raises a question, speak to a data protection specialist, your professional body, or your insurer before you publish. The template is also dated (version 1.0, 13 August 2026), because guidance changes, and your notice will need to change with it.
With that said, here’s how to turn the template into your privacy notice in about an hour.
What a privacy notice has to include
A privacy notice is simply a page that tells clients what information you hold about them, why, and what their rights are. The ICO’s guidance on the right to be informed lists the essentials: who you are, what you collect, why you collect it and your lawful basis, who you share it with, how long you keep it, the rights people have, and how to complain.
The template covers all of that, plus the digital and AI tools section that section 3.1 of the new BACP framework points at. Your job is to make every section true for your practice.
How to customise it, section by section
The template uses [square brackets] for anything you need to fill in, and italic guidance lines you delete before publishing. Work through it top to bottom.
Who you are. Your name, practice name, professional body, and contact details. This section also asks for your ICO registration number. Most therapists in private practice need to pay the ICO’s data protection fee, and many don’t know it. If you’re not sure whether you’re registered, check on the ICO website. It takes five minutes and the fee for most small practices is modest.
What information you collect. The template lists the usual suspects: contact details, session notes, enquiry information, payment records, and website data. Delete anything you don’t collect and add anything you do, such as GP details or emergency contacts. The test is simple: could a client read this list and be surprised by something you actually hold? If so, add it.
Why you collect it, and the legal basis. This is the most technical section, and the one most worth checking with a specialist if anything feels uncertain. The template uses the common position for therapists: your therapy contract, legitimate interests, and legal obligations for the everyday data, plus the health and care condition for what clients share in sessions. Don’t invent your own wording here. Either use the template’s, or get proper advice.
Digital tools and AI. List what you actually use: booking calendar, video platform, accounting software, and any AI tools. If client information touches an AI tool, say which tool, what it processes, where the data goes, and that you review its output. If no client information ever goes into AI tools, say that instead. It’s a strong trust signal. Only list what’s true, and remember that using AI with client data also needs informed consent in your working agreement, which I covered in the [BACP framework guide](https://theoruby.com/bacp-ethical-framework-2026-ai/).
Who you share it with. Therapy has standard, defensible exceptions to confidentiality: supervision, serious risk of harm, legal requirements, your clinical will holder, and whoever does your books. The template covers these in plain English. Adjust the details to your setup.
How long you keep it. Put real numbers in. Seven years after therapy ends is common for adult records, longer for work with children, but requirements vary by professional body and insurer, so check yours. A notice that says “as long as necessary” and nothing else is the kind of vagueness the ICO dislikes.
How you keep it safe, your rights, and complaints. These three sections mostly need light editing: describe your actual storage arrangements in a sentence or two, and leave the rights and complaints wording largely as it is. The ICO’s contact details are already in the template.
Date it. The notice has a “last updated” line at the top. Fill it in, and change it every time you update the notice. This matters more than it looks: an undated privacy notice gives clients no way to know whether it reflects how you work now, and the 2026 framework’s emphasis on showing your reasoning makes “reviewed on this date” a useful habit across your practice paperwork.
Five mistakes to avoid
Having reviewed a lot of therapy websites, these are the privacy notice problems I see most:
- Copying another therapist’s notice wholesale. Their tools, retention periods, and setup are not yours, so their notice isn’t either. Borrow structure, not facts.
- Legal jargon. A notice a client can’t understand fails at its one job. If a sentence wouldn’t survive being read aloud to a client, rewrite it.
- A tools list that doesn’t match reality. Listing tools you’ve stopped using, or missing the AI note-taker you started using last month, is worse than saying nothing, because it’s inaccurate in writing.
- No date. Covered above, and the single easiest fix on this list.
- Publishing it and burying it. Link the notice from your website footer and from any contact or booking form. A privacy notice nobody can find doesn’t meet the “accessible” part of the framework’s wording.
Where this fits in your November preparation
The privacy notice is step three of the six-step sequence in my BACP framework guide: read the framework, audit your tools, then update your privacy notice and working agreement to match what the audit found. Do the audit first. Your notice can only be accurate if you know what tools your practice actually uses.
Ready to see what’s working on your site?
If you would like to know how your own blogs measure up on EEAT, and get clear recommendations you can act on, book a free 30-minute call with me. We’ll look at your site together and I’ll show you where the quick wins are.
Frequently asked questions
Do therapists need to register with the ICO?
Most therapists in private practice need to pay the ICO’s data protection fee, because they hold client information electronically. Check directly on the ICO website using their self-assessment tool, as your circumstances are your own.
Can I just copy a privacy policy from another therapy website?
No. A privacy notice describes your specific tools, retention periods, and working arrangements, so a copied one is almost guaranteed to be inaccurate for your practice. Use a template as a starting structure and make every statement true for you.
How often should I update my privacy notice?
Review it at least once a year, and update it whenever something material changes: a new booking system, a new AI tool, a change in how long you keep records. Change the “last updated” date every time.
Where should the privacy notice go on my website?
Publish it as its own page, then link it from your website footer so it’s reachable from every page, and from any contact or booking forms where you collect information. That’s what makes it “clear and accessible” rather than just published.
The bottom line
A privacy notice is not a legal ordeal. It’s a page of plain English that says: here’s what I hold, here’s why, here’s how I look after it, and here’s what you can ask of me. The template gets you most of the way, an hour of customising gets you the rest, and a specialist can check anything you’re unsure about.
And it earns its keep beyond compliance. With clients paying more attention to how their information is handled, a clear privacy notice is one of the quiet trust signals that separates a professional practice website from a brochure.
Need help with the website side of this?
If you’d rather the privacy page, the rest of your trust pages, and the site around them were handled properly in one go, that’s what I do. I work exclusively with therapists, counsellors, and mental health professionals across the UK on website design and SEO, and privacy and trust pages are part of every build.
Book a free 30-minute consultation and I’ll look at your current setup and tell you honestly whether you need help or whether it’s a half-hour job you can do yourself. No pressure, no sales pitch.
Written by Theo Ruby, a digital marketing consultant with over 10 years of experience helping therapists and mental health professionals grow their practices online. Theo has worked with 300+ therapy professionals across the UK on website design, SEO, and digital marketing strategy. Theo is not affiliated with the BACP, and this article is general guidance, not legal or ethical advice. Always confirm requirements directly with your professional body.
Get in touch: www.theoruby.com/contact
Email: [email protected] | Phone: 07709 852 364