Serenity Centre

Serenity CentreSerenity CentreSerenity Centre

Serenity Centre

Serenity CentreSerenity CentreSerenity Centre
  • Home
  • Psychotherapy
  • Mindfulness
  • Yoga
  • Book Now
  • About Me
  • Fees
  • Contact Us
  • FAQ
  • More
    • Home
    • Psychotherapy
    • Mindfulness
    • Yoga
    • Book Now
    • About Me
    • Fees
    • Contact Us
    • FAQ
  • Sign In
  • Create Account

  • Bookings
  • My Account
  • Signed in as:

  • filler@godaddy.com


  • Bookings
  • My Account
  • Sign out

Signed in as:

filler@godaddy.com

  • Home
  • Psychotherapy
  • Mindfulness
  • Yoga
  • Book Now
  • About Me
  • Fees
  • Contact Us
  • FAQ

Account

  • Bookings
  • My Account
  • Sign out

  • Sign In
  • Bookings
  • My Account

Data Retention Schedule

Document Owner: Julie Jones
Review Date: Annually
Version: 1.0


1. Purpose

This retention schedule sets out how long personal information and clinical records are retained by the practice in accordance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • ICO Storage Limitation Principle
  • UK Council for Psychotherapy (UKCP) Code of Ethics and Professional Practice
  • Professional indemnity insurance requirements

The practice retains information only for as long as necessary to fulfil the purposes for which it was collected and to meet legal, professional, insurance and safeguarding obligations.


2. Retention Schedule


Initial enquiry records (where therapy does not commence)

Name, email address, telephone number, enquiry details

12 months from last contact

Secure deletion


Client registration forms

Name, address, date of birth, emergency contact details, GP details

7 years after therapy ends

Secure deletion/shredding


Client personal data

Name, address, email, telephone number, date of birth, occupation

7 years after therapy ends

Secure deletion/shredding


Special category data

Health information, mental health history, medication details, risk information, safeguarding information

7 years after therapy ends

Secure deletion/shredding


Assessment records

Intake forms, assessment notes, risk assessments

7 years after therapy ends

Secure deletion/shredding


Adult client therapy notes

Session notes, treatment plans, interventions, progress notes

7 years after therapy ends

Secure deletion/shredding


Child and young person therapy notes

Session notes, assessments, parental consent records

Until age 25 or 7 years after therapy ends (whichever is later)

Secure deletion/shredding


Safeguarding records

Referrals, disclosures, communications with agencies

Until age 25 or 25 years from last contact for adults where significant safeguarding concerns exist

Secure deletion/shredding


Therapy agreements and consent forms

Contracts, privacy notices, consent records

7 years after therapy ends

Secure deletion/shredding


Clinical supervision records containing identifiable client information

Anonymised where possible; otherwise identifiable discussion notes

7 years after therapy ends

Secure deletion


Correspondence with clients

Letters, forms, secure messages

7 years after therapy ends

Secure deletion/shredding


Clinical emails

Emails containing therapeutic, health or risk information

7 years after therapy ends

Secure deletion


Administrative emails

Appointment scheduling, cancellations, payment arrangements

2 years after therapy ends

Secure deletion


Text messages / WhatsApp messages

Appointment reminders and client communications

2 years after therapy ends unless clinically relevant, then retain with clinical record for 7 years

Secure deletion


Online contact forms

Website enquiries and consultation requests

12 months from last contact

Secure deletion


Video consultation records

Session logs, meeting records

7 years after therapy ends

Secure deletion


Session recordings (if used and separately consented)

Audio or video recordings

Delete immediately after agreed purpose is fulfilled, normally within 3 months

Secure deletion


Complaints records

Complaints, investigations and outcomes

7 years after closure

Secure deletion/shredding


Professional indemnity claims records

Correspondence, evidence, reports

15 years after closure of claim

Secure deletion/shredding


Financial records

Invoices, receipts, accounting records

6 years plus current tax year

Secure deletion/shredding


Data breach records

Incident reports and investigations

6 years after closure

Secure deletion


Marketing consent records

Newsletter subscriptions and consent evidence

Until consent withdrawn plus 3 years

Secure deletion


Staff records (if applicable)

Employment records

6 years after employment ends

Secure deletion/shredding


3. Electronic Data Storage

The following electronic systems may contain personal data:

Clinical Records System

Contains:

  • Name
  • Address
  • Date of Birth
  • Telephone Number
  • Email Address
  • Emergency Contact Details
  • GP Details
  • Assessment Information
  • Health Information
  • Session Notes
  • Risk Assessments

Retention:

  • 7 years after therapy ends for adults
  • Age 25 for children and young people

Email System

Emails may contain:

  • Personal identifiers
  • Appointment details
  • Health information
  • Therapy-related communications
  • Financial information

Retention:

  • Administrative emails: 2 years after therapy ends
  • Clinical emails: 7 years after therapy ends

Where clinically relevant, emails should be transferred to the client record and retained as part of that record.

Mobile Devices

May contain:

  • Client names
  • Telephone numbers
  • Appointment reminders
  • Text messages

Requirements:

  • Device encryption enabled
  • PIN/password protected
  • Secure deletion when retention period expires

Cloud Storage Systems

May contain:

  • Clinical notes
  • Assessments
  • Consent forms
  • Correspondence

Requirements:

  • UK GDPR compliant provider
  • Multi-factor authentication
  • Encryption at rest and in transit
  • Access restricted to authorised personnel only


4. Secure Disposal

Electronic Records

Electronic records must be:

  • Permanently deleted from live systems.
  • Deleted from local devices.
  • Removed from cloud storage.
  • Removed from email archives where practicable.
  • Subject to routine backup overwriting processes.

A destruction log should record:

  • Record category
  • Date destroyed
  • Method of destruction
  • Person responsible

Paper Records

Paper records must be:

  • Cross-cut shredded; or
  • Destroyed by a confidential waste contractor.

A record of destruction should be maintained.


5. Retention Review Process

Client records due for destruction should be reviewed annually to determine whether:

  • Ongoing legal proceedings exist.
  • Complaints are unresolved.
  • Safeguarding concerns require extended retention.
  • Insurance advice requires longer retention.

Where any of the above apply, records may be retained longer with documented justification.


6. Lawful Basis for Retention

The practice retains personal data under:

  • Article 6(1)(b) UK GDPR – Contract
  • Article 6(1)(c) UK GDPR – Legal Obligation
  • Article 6(1)(f) UK GDPR – Legitimate Interests
  • Article 9(2)(h) UK GDPR – Provision of Health Care
  • Article 9(2)(f) UK GDPR – Establishment, Exercise or Defence of Legal Claims

  • Privacy Policy
  • Data Retention Schedule

Serenity Centre

office@serenitycentre.org.uk

Copyright © 2026 Serenity Centre - All Rights Reserved.

Powered by