Data Protection & GDPR Statement

Data Protection & GDPR Statement

Last updated: October 2026 Maria Apiafi Counselling & Psychotherapy is committed to protecting the privacy, confidentiality and security of the personal information entrusted to me in the course of my counselling and psychotherapy practice. As a sole practitioner, I am the data controller for the personal information I collect and process in connection with my private practice. I am registered with the Information Commissioner’s Office (ICO). I process personal information in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the Data (Use and Access) Act 2025. My approach to data protection is also informed by my professional and ethical responsibilities as a counsellor and psychotherapist, including my duty to respect client confidentiality. This statement explains the principles I follow when handling personal information. More detailed information about what information I collect, the lawful bases I rely upon, how information may be shared and your individual rights is provided in my Privacy Policy. Information about how long records are retained is provided in my Data Retention Policy.

Data protection principles

When I collect and use personal information, I aim to follow the data protection principles set out in Article 5 of the UK GDPR. Lawfulness, fairness and transparency Personal information will be processed lawfully, fairly and transparently. I will explain how and why information is used and identify an appropriate lawful basis for processing it. Purpose limitation Personal information will be collected for specified, explicit and legitimate purposes and will not be used in a way that is incompatible with those purposes. Data minimisation I will collect and retain only the personal information that is adequate, relevant and necessary for the purposes for which it is being processed. Accuracy I will take reasonable steps to ensure that personal information is accurate and, where necessary, kept up to date. Inaccurate information will be corrected or deleted where appropriate. Storage limitation Personal information will not be kept for longer than is necessary. My usual retention periods and arrangements for secure disposal are explained in my Data Retention Policy. Integrity and confidentiality Appropriate technical and organisational measures will be used to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction or damage. Accountability I am responsible for demonstrating appropriate compliance with these data protection principles and for reviewing the measures I use to protect personal information.

Special category data and confidentiality

Counselling and psychotherapy may involve information about your physical or mental health, wellbeing, relationships and personal experiences. Information concerning health is classed as special category data under Article 9 of the UK GDPR and is given additional protection under data protection law. Where I process health or therapy-related information in connection with providing counselling and psychotherapy, I rely on Article 9(2)(h) of the UK GDPR, which permits the processing of special category data where necessary for the provision of health or social care or treatment. This is read alongside the relevant provisions of the Data Protection Act 2018, including Schedule 1, Part 1, paragraph 2, and the requirement for appropriate professional confidentiality. I also have a professional and ethical duty to protect the confidentiality of information shared with me. Information disclosed during therapy will therefore be treated as confidential and will not ordinarily be shared with another person or organisation without your knowledge or agreement. There are limited circumstances in which confidentiality may need to be broken, for example where there is a serious concern about risk of harm, a safeguarding concern, where disclosure is required by law, or where information is required in connection with legal proceedings. Where possible and appropriate, I would aim to discuss this with you before information is disclosed. I will only disclose information that is necessary and relevant to the circumstances and will take reasonable steps to protect your privacy when doing so.

Professional practice and clinical supervision

As a counsellor and psychotherapist, I work within professional and ethical standards and undertake regular clinical supervision as part of responsible and accountable practice. Clinical supervision provides a confidential professional space in which I can reflect on my therapeutic work, consider the needs of clients and maintain the quality and safety of my practice. As part of supervision, aspects of my work with clients may be discussed. I take care to protect your privacy and will keep identifying information to the minimum necessary. My clinical supervisor is also bound by the same professional and ethical duties of confidentiality. Information would only be shared beyond the usual boundaries of confidentiality where there is an appropriate professional, safeguarding or legal reason to do so. Further information about the limits of confidentiality and how I use and protect personal information is provided in my Privacy Policy. I maintain appropriate professional supervision, insurance and continuing professional development in support of safe, ethical and competent practice.

Data security and personal data breaches

I take appropriate technical and organisational measures to protect the personal information I hold against unauthorised or unlawful access, accidental loss, disclosure, alteration or destruction. Electronic information is protected using appropriate security measures, including password-protected and encrypted systems and devices where applicable. Access to client information is restricted to me, except where information needs to be shared lawfully and appropriately as described in my Privacy Policy. I take reasonable steps to ensure that any services or systems I use in connection with my practice provide appropriate safeguards for personal information. If a personal data breach occurs, I will assess the nature and potential impact of the breach and take appropriate action to contain and address it. Where the breach is likely to result in a risk to an individual's rights and freedoms, I will report it to the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to an individual's rights and freedoms, I will inform the person affected without undue delay. I will keep an appropriate record of personal data breaches and the action taken in response.

Responsibility, review and contact

As the data controller for my private practice, I am responsible for ensuring that personal information is handled in accordance with applicable data protection law and for reviewing the measures I use to protect it. I will review this Data Protection & GDPR Statement periodically and may update it to reflect changes in my practice, the services or systems I use, professional guidance or applicable data protection law. When changes are made, I will update the “Last updated” date at the top of this page. If you have any questions about this statement or how I handle your personal information, please contact me: Maria Apiafi Counselling & Psychotherapy Email: maria@apiaficounselling.co.uk Website: apiaficounselling.co.uk Further information about how I collect, use and protect personal information, the lawful bases on which I process it and your data protection rights is provided in my Privacy Policy. Information about how long I retain information is provided in my Data Retention Policy.