Healthcare sector
Data protection for
psychologists and therapists
Session notes and mental health records are special-category data under art. 9 GDPR. Professional confidentiality and the GDPR coexist and must be complied with simultaneously. The obligation to appoint a DPO falls on collective mental health centres and clinics; the professional practising on an individual basis is expressly exempt under art. 34.1.l) LOPDGDD.
Art. 9
GDPR — mental health data
Art. 34
LOPDGDD — analyse by centre
72 h
to report a breach
24 h
personalised proposal
Regulatory context
General obligations for psychologists and therapists
Mental health data is among the most sensitive data under the GDPR. Its management combines the documentation and security obligations of the regulation with the therapist's professional confidentiality duty.
Mental health data (art. 9 GDPR)
Session notes, diagnoses, assessments and patient progress are mental health data with the highest level of protection. They require a specific legal basis and strictly restricted access.
Simultaneous confidentiality and compliance
Professional confidentiality and the GDPR are not incompatible: the former protects the content of the sessions; the latter governs how the data is documented and stored. Both must be complied with at the same time.
Restricted access to the patient record
In practices with several therapists, access to the patient's record must be limited to the responsible professional. Sharing notes with colleagues requires a legal basis and, in many cases, prior information to the patient.
Video-therapy platforms and storage
Teleconsultation platforms and cloud storage tools may act as data processors. It must be verified where the data is stored and, where applicable, the Data Processing Agreement must be formalised.
Appropriate security measures
Encrypted devices, robust passwords, individual credential access and secure email management are basic measures for any professional handling mental health data.
Retention periods
Legislation establishes how long the psychological record must be retained. During that period, it cannot be deleted even if the patient requests erasure of their data.
Legal obligation
The DPO in psychology and therapy: who is obliged and who is exempt
The art. 34.1.l) of the LOPDGDD establishes the obligation to appoint a DPO for healthcare centres providing mental health services. But the same law includes an express and unequivocal exemption: healthcare professionals practising on an individual basis — self-employed practitioners in their own private practice — are legally exempt from this obligation.
The obligation falls on collective centres: practices with several therapists, integrated mental health clinics and larger legal entities. If your practice falls within that scenario, Certix's DPO assumes this function as an independent service from day one.
Centres where it may be applicable
Indicative list. The specific obligation for each entity requires individual analysis.
The service
What the data protection service for your practice includes
Certix's standard contract, adapted to the specific circumstances of a psychology practice or therapy consultation.
RoPA and technical-organisational structure
Record of Processing Activities (RoPA) adapted to your therapeutic activities, together with the structure of technical and organisational measures applicable to your practice.
Adapted information clauses
Texts adapted to admission forms, treatment consents and communications with referring professionals.
Adapted web documentation
Documentation adapted for the practice's website: online appointment form, contact and cookie management.
Data Processing Agreements (DPA)
Processing agreements for video-therapy platforms, appointment management software and cloud storage tools.
Data breach protocol
Internal procedure to detect, classify and report incidents to the AEPD within the 72-hour deadline required by the GDPR.
Data subject rights management
Documented procedure for handling patients' rights requests within the established time limits.
Document management platform
Access to a private platform with all documents, templates and electronic signatures updated in real time.
Ongoing support
Ongoing support in the face of regulatory changes, new AEPD guidelines or changes in the practice's activities.
External DPO (independent service)
The formal appointment of a Data Protection Officer (DPO) is a separate contract, quoted to measure according to the characteristics of the centre.
Need a proposal for your practice?
Tell us about your activities. Personalised proposal within 24 hours.
Good practice
Key aspects in the day-to-day running of a psychology practice
Regulatory compliance does not end with documentation. In therapeutic practice, the day-to-day management of information is particularly sensitive:
- Storage of session notes. Notes must be stored in secure systems with individual credential access. Google Drive, Dropbox and other cloud platforms must be assessed as potential data processors before use.
- Clinical supervision. Supervision with another professional involves sharing case information. It should be anonymised as far as possible and, where this is not possible, an appropriate legal basis must exist.
- Reports for third parties. Psychological reports for courts, schools or employers involve a communication of data that requires a specific legal basis, generally the patient's consent.
- Training and awareness. In practices with several therapists or support staff, each team member must know their data protection obligations.
Most common legal bases in clinical psychology
Art. 9.2.h GDPR
Provision of healthcare — principal basis for processing session notes and the psychological record.
Art. 6.1.b GDPR
Performance of the therapeutic services contract.
Art. 6.1.c GDPR
Compliance with legal obligations: retention of the clinical record and deontological obligations.
Art. 6.1.a GDPR
Consent — for communications with third parties not directly involved in the care.
Art. 9.2.j GDPR
Scientific research or statistical purposes in psychological research projects.
FAQ
Frequently asked questions about data protection in psychology
Is it mandatory to appoint a DPO at a psychology practice?
Art. 34 of the LOPDGDD provides for the obligation to appoint a DPO for certain healthcare centres. Its application to a psychology practice or therapy centre depends on the legal nature of the centre, the type of services provided and the volume of data processed. Healthcare professionals practising on an individual basis are excluded from this obligation. Each case requires individual analysis.
Are session notes health data under the GDPR?
Yes. Notes on a patient's emotional state, diagnosis or progress are mental health data under art. 9 GDPR. Their processing requires a specific legal basis, reinforced security measures and access strictly restricted to the responsible therapist.
Does a psychologist's professional confidentiality obligation exempt them from GDPR compliance?
No. Both obligations coexist and reinforce each other. Professional confidentiality protects the content of the sessions; the GDPR governs how the patient's data is documented, stored and protected. The therapist must comply with both sets of rules simultaneously.
Can a psychologist share patient information with another professional?
Only where there is a legal basis for doing so. A referral or external clinical supervision may be based on the provision of care or on the patient's consent. In any case, the communication must be documented and the patient must have been informed of this possibility in the information clause.
Are video-therapy platforms data processors?
As a general rule, yes. Teleconsultation platforms that process mental health data may act as data processors. The exact legal relationship depends on each provider's conditions; the therapist must verify where the data is stored and, where the provider acts as a processor, have a signed Data Processing Agreement in place.
How long must psychological records be retained?
Specific legislation establishes minimum retention periods for the psychological clinical record, which vary by autonomous community. During that period, the data cannot be deleted even if the patient requests it. Each case requires verification of the applicable regulations.
Does a self-employed psychologist working alone need to comply with the GDPR?
Yes. The GDPR applies to any professional who processes patients' personal data, regardless of their size or form of practice. A self-employed psychologist practising on an individual basis is exempt from the obligation to appoint a DPO under art. 34 LOPDGDD, but must comply with all other obligations: RoPA, information clauses, security measures and a data breach protocol.
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Healthcare sector
GDPR compliance
for your practice.
A data protection expert analyses your activities and proposes the most suitable solution. No intermediaries, no bureaucracy.
Proposal within 24 h · info@certix.es
Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.