For UK counsellors and therapists · checked 15 September 2026
How long should counsellors keep client records in the UK?
There is no single required period. UK GDPR does not set one retention period for all counselling records, and BACP leaves the decision to your practice. Specific legal, contractual or NHS requirements may still apply. What UK GDPR requires instead is that you choose a retention period, can justify it, and write it down. In practice, Howden offers around seven years as one possible starting point for adult records, records involving children may need to be kept longer, and the NHS keeps mental health records for twenty years, or ten years after a patient's death. This page sets out where each number comes from, so you can pick yours and be able to say why.
The short version
"How long do I keep client records?" looks like it should have a one-line answer. It does not, and anyone who hands you a single number without asking about your practice has skipped the actual requirement. The requirement, set by UK GDPR's storage limitation principle, is a defined and justified policy: periods you chose, reasons you can point to, and both written down where a client could read them.
The numbers below are reference points to assess, not automatic deletion dates. Howden explains a possible seven-year period for adult records; NHS England has separate schedules for children and mental health records. Your care obligations, possible claims, insurer and any applicable legal requirements all matter.
The data protection principles apply across the UK, on paper and in digital tools. The claim time limits below describe England and Wales, and the NHS examples come from NHS England. Scotland and Northern Ireland have different limitation rules: obtain advice for your jurisdiction before adopting a period. What happens to records in Joy has one marked section near the end.
What the law requires: a period you can defend
UK GDPR and the Data Protection Act 2018 govern your client records, and on the question of how long, the ICO is direct:
"The UK GDPR does not set specific time limits for different types of data. This is up to you, and will depend on how long you need the data for your specified purposes." (ICO, storage limitation)
"Up to you" comes with homework attached. The same guidance says you need to "establish and document standard retention periods for different categories of information you hold wherever possible", that you must be able to justify keeping data in a form that identifies people, and that at the end of a standard period you should review, then erase or anonymise unless there is a clear justification for keeping the data longer. A retention policy, in other words: written, reasoned and reviewed. For a solo practice it fits on one page.
The ICO says possible future legal claims can justify retaining information. This is one factor alongside your care needs and any legal or professional obligations. It does not justify keeping every record indefinitely.
One thing that does not change the answer: counselling records are health data, which UK GDPR treats as special category data. That raises the bar for how securely you keep them and on what basis, which our guide to using AI for counselling notes covers in more depth. The storage limitation principle itself asks the same of everyone: no longer than necessary, and you define necessary.
This is general guidance, not legal advice for your practice. If you are unsure, the ICO's helpline is free, and your professional indemnity insurer will have a view too.
What BACP says (and does not say)
BACP does not set a retention period, and says so itself. Its UK GDPR FAQs put it this way:
"Data Protection legislation does not set specific time limits but requires that you only keep information for as long as is necessary for the specific purpose it was originally collected." (BACP, UK GDPR FAQs)
The same FAQ lists the factors it expects members to weigh: any legal or regulatory requirements that cover your records, whether your indemnity insurer specifies a time period, your organisation's policies, and its complaint timescales. The FAQ describes three years after counselling ends; BACP's current complaints guidance says three years from the event, with later complaints possible for good reasons. Do not treat three years as a guaranteed cut-off.
A March 2026 blog on notes and record keeping by BACP's client ethics manager says the quiet part plainly: "there's no simple answer to this question", and therapists who seek advice may receive very different answers. It notes that because a complainant has up to three years to submit a complaint, "a member may decide to retain their notes for a minimum of three years", and that it is for the therapist or the organisation to decide an appropriate time limit before destruction.
The Ethical Framework 2026, mandatory from 3 November 2026, sets standards for what records must be: clause 3.2 asks for records that are factual, adequate and relevant, stored securely, and meeting the data protection requirements of the country where they are stored. It does not set a duration. The complaint window is a factor to consider, not a BACP retention rule or a guarantee that no later complaint or claim is possible. Choose and justify your period in light of all the requirements that apply.
Where the seven years comes from
Howden, an insurance broker that publishes note-keeping guidance for therapists, gives seven years as a possible starting point. Its example adds a year to the six-year period for a contract claim to allow for delay between a claim being issued and served. Howden makes clear that this is not definitive, particularly in cases involving children. It is one named broker's guidance, not a rule for every practice.
In England and Wales, the Limitation Act 1980 generally allows six years for simple contract claims (section 5) and three years for personal injury claims (section 11), with qualifications including later knowledge, children and the court's discretion. Three years is not the limit for every negligence claim. These are claim rules, not a retention schedule, and some cases have different or extended time limits.
Read your insurer's and any commissioning organisation's requirements alongside data protection law. If a period is specified, check how it applies to your records and document the reason for using it. For couples or linked clients, take advice on the relevant end dates and each person's rights rather than applying one automatic clock to all records.
The NHS number, and why it is different
One useful reference is the Records Management Code of Practice (NHS England, current online code). Its retention schedule for care records keeps general adult health records for 8 years, mental health records for "20 years, or 10 years after death", and children's records until the 25th birthday, or the 26th if the patient was 17 when treatment ended.
The code covers NHS organisations and providers of NHS-commissioned care in England. A wholly private practice should not adopt its periods automatically. Check the category, retention trigger and review instructions that apply: the general children's schedule does not replace a more specific mental health schedule. Continuing care needs, legal claims and special circumstances may justify longer retention.
Clients who were under 18
Children's records need a separate decision. In England and Wales, section 28 of the Limitation Act 1980 extends time limits where a claimant was a child when the claim arose. An ordinary personal injury claim can commonly be brought until age 21, and exceptions can allow longer. That is not a safe deletion age for every record or every type of claim.
For comparison, NHS England's general children's schedule uses the 25th birthday, or the 26th if treatment ended at 17. Mental health records have their own schedule. For private practice, agree an appropriate period with your insurer or legal adviser, taking account of the work, jurisdiction and any safeguarding or legal issues. Document the chosen period and review it before destroying records.
Five situations, one table
The same principles, applied. Starting points to adapt, with the reasoning next to each so you can defend or depart from it.
| Situation | A defensible starting point | Where it comes from |
|---|---|---|
| Adult client, work has ended | Assess Howden's seven-year example alongside your insurer, care needs and legal duties. BACP's usual three-year complaint window is another factor, not a retention rule. | One broker's example (Howden); complaint window per BACP's FAQ |
| Client was under 18 | Set a separate period with advice. Age 21 is not a universal deletion date; NHS England's general children's schedule uses 25/26, with separate mental health rules. | England and Wales: Limitation Act section 28; age 25/26 per the NHS schedule, for its general children's category |
| Client has died | No fixed private-practice rule. The NHS schedule for mental health records reads "20 years, or 10 years after death"; do not treat these as interchangeable choices or automatic private-practice deletion dates. | NHS retention schedule, used here as a reference point, not a requirement |
| You close your practice | Plan secure custody for any remaining retention period and tell clients who to contact. A clinical will can provide instructions if you die or cannot practise. | BACP's record-keeping blog and its Good Practice in Action resources on confidentiality and record keeping |
| You change notes tools | The period follows the records, not the tool. Export the records you need, verify the copies, arrange appropriate deletion with the old provider, and retain them securely for the remaining justified period. | Follows from UK GDPR's storage limitation and controller responsibilities; the export-first order is common practice |
Starting points, not rules. Check your policy, insurer and professional guidance against applicable law; none overrides data protection duties.
When a client asks you to delete their records
Retention runs into client rights in two places, and they pull in opposite directions.
A client can ask you to erase their records, and the right to erasure is real but not absolute. The ICO's guidance lists the situations where it does not apply, and one of them is processing necessary "for the establishment, exercise or defence of legal claims". Assess each request individually. An unexpired retention period alone is not enough: establish why the records are still necessary and which exception applies. If you refuse, explain your reasons and the client's rights to complain to the ICO or seek a judicial remedy, without undue delay and within one month. The flip side is just as firm: in the ICO's words, "individuals have the absolute right to erasure of personal data that you no longer need for your specified purposes". A retention policy you never review is how you end up holding data you have no answer for.
Separately, a client can ask to see their records. A subject access request entitles them to a copy of their personal data, free of charge in most cases, normally within one calendar month. That is one more reason to write notes you would be comfortable handing over, and to know exactly where every record for a client lives. When the request comes from a court, the police or a solicitor instead of from your client, different rules apply, and our guide to counselling notes and the court walks through each route.
Writing your retention policy
The whole of the above, as a list. An hour once, then a small review each year.
- Start with your insurer. Read your policy documents, or ask whether a retention period is specified. If one is, check its scope and legal basis and note where it is written. If not, note that you asked, with a date.
- Choose your periods. One for adult clients, one for clients who were under 18, and a decision for the death of a client. Write the reason next to each: claim windows, the complaint window, the NHS schedule as reference.
- Put them where clients can read them. Your privacy notice and client agreement should say what you keep, for how long, and why, in plain words.
- Diarise the review. When a client's period ends, erase or anonymise, unless there is a clear, noted reason to keep the records longer. Set a review frequency that fits the risks; also review records when their period ends or a client requests erasure.
- Destroy properly. In a way that prevents anyone accessing or using the records afterwards, and for every copy: paper, digital, backups, exports and any tool you have stopped using.
- Make a clinical will. A named person, instructions for your records, and a way for clients to be told, in case you die or cannot continue practising. BACP's Good Practice in Action resources cover how.
What happens to records in Joy
This is the section about us. Everything above applies whatever you use for notes; here is how the same questions land in Joy, with the documents linked so you can check.
- Who decides how long records are kept You do. You are the data controller for your client records and Joy is your processor, under a public data processing agreement. Joy does not decide your retention periods for you: you choose them, you write them into your policy, and you arrange deletion when a record's justified retention ends. What the DPA commits Joy to is the other end of the bargain: erasing personal data when the agreement ends.
- Where the records live in the meantime In the EU, on Google Cloud in Sweden. Joy Solutions AB is a Swedish company working under GDPR and the UK Data Protection Act 2018. Your clients' data is never used to train AI. Never, on any plan. Not with consent, not de-identified, not at all.
- What happens if you leave Your notes stay yours and you can export them. Under the DPA, personal data must be erased by Joy when the agreement ends, so the order matters: export first, then close. The export is then yours to keep for the remainder of your retention periods.
Put your policy into practice
- Keep a record of your chosen periods and review dates, and check that your process covers every copy you hold.
- Before deleting records, check whether a complaint, request or legal matter requires you to preserve them. Contact Joy if you need help carrying out your instructions.
If Joy's policies say something different from this page, the page is wrong and we will fix it. Tell us at hello@joy.day. Weighing Joy against another tool? We keep a side-by-side with Upheal, including where they win.
A note from Charlotta
Hi, I'm Charlotta, one of Joy's co-founders. I have built healthcare technology for over a decade, on both sides of the table: as CEO of companies that deliver care themselves, and as the vendor behind the tools they run on.
We wrote this page because "how long do I keep records?" gets asked constantly and answered carelessly. The real answer is a policy, not a number, and once you see where the numbers come from, writing that policy takes an hour. Since Joy is where many counsellors keep their records, we would rather you know exactly why you keep what you keep, and delete with confidence when the time comes.
If you think we have read a source wrong, or something here goes out of date, email me at charlotta@joy.day. It comes straight to me, and I read everything.
Charlotta
Co-founder, Joy
Quick answers
How long do you need to keep counselling records in the UK?
UK GDPR does not set a single retention period for all counselling records. Choose, justify, document and review your periods, taking account of any specific legal or contractual duties. Howden gives seven years as one possible example for adult records; children's records need a separate decision. NHS England's schedules are reference points, not automatic rules for wholly private practice.
Does BACP say how long to keep counselling notes?
BACP leaves members to decide an appropriate retention period. Its guidance points to legal and regulatory duties, indemnity insurance, organisational policies and its usual three-year complaint window. That window is not a BACP retention rule or a guarantee against later claims. The Ethical Framework 2026 sets record-keeping standards and takes effect on 3 November 2026.
What does UK GDPR say about keeping counselling records?
UK GDPR says personal data should be kept no longer than necessary. Set and document justified periods, review them, and erase or anonymise records when no longer needed. Possible legal claims can be a reason for retention, but not for keeping everything indefinitely.
How long should I keep records for clients under 18?
Set a separate period with advice. In England and Wales, ordinary personal injury claims involving children can commonly be brought until age 21, with exceptions allowing longer. NHS England's general children's schedule uses age 25 or 26; mental health records have a separate schedule. These are not automatic deletion dates for private practice, and Scotland and Northern Ireland have different claim rules.
Can clients ask to see or delete their counselling records?
Yes. Subject access gives a client a copy of their personal data, usually free and normally within one month, subject to applicable exemptions. Assess erasure requests individually: a retention policy alone does not remove the right. You may refuse where an exception applies, such as records still necessary for legal claims. Review the reason for keeping them and explain any refusal.
What happens to my counselling records if I close my practice?
The retention periods keep running after the practice ends. The records need to stay secure and reachable for the remainder of their period, and then be destroyed in a way that prevents anyone accessing them. BACP encourages practitioners to make a clinical will: a named person with instructions for what happens to client records if you die or cannot continue practising.
Records in one place, and yours
Your first 20 sessions with Joy are free. No card, and no clock on them.
Try Joy for freeNo credit card needed. Takes 30 seconds.
Wondering whether you may use AI to write the notes in the first place? Our UK guide answers it.
Checked on 15 September 2026 against the ICO's guidance on storage limitation, the right to erasure and the right of access; BACP's UK GDPR FAQs, its March 2026 blog on notes and record keeping, its Good Practice in Action resource on confidentiality and record keeping (PDF) and the Ethical Framework for the Counselling Professions 2026 (PDF); NHS England's Records Management Code of Practice and its retention schedule for care records; Howden's note-keeping guidance for therapists; the Limitation Act 1980 (England and Wales). Short quotations are reproduced for the purpose of explanation; the Ethical Framework is © 2026 British Association for Counselling and Psychotherapy. This page is made by Joy Solutions AB and is not affiliated with, endorsed by or approved by BACP, the ICO, NHS England, Howden or Weightmans. It is general guidance, not legal advice for your practice. Spotted something out of date? Tell us at hello@joy.day and we will fix it.