Data protection is a legal obligation for every therapy practitioner in the UK. Renting a room adds complications that home-based practitioners never have to think about. Who is responsible for data security in a shared building? Can you store client notes on-site? What happens if the landlord operates CCTV in communal areas? Those questions come up constantly. This guide answers the most common GDPR questions for therapy room renters and shows what compliance looks like in practice.

Under UK GDPR, you must have a lawful basis for processing any personal data. For therapy practitioners, the relevant bases are:
Most therapeutic record-keeping falls under contract or legal obligation. Not sure which basis applies to you? The Information Commissioner’s Office (ICO) has detailed guidance on identifying lawful bases.
Therapy records are classified as special category data because they concern health, mental health, and sex life. The ordinary rules are not enough. You must also meet an additional condition under Article 9 of UK GDPR. For healthcare practitioners, that condition is normally that processing is necessary for healthcare purposes.
When you rent a therapy room, you remain responsible for the security of any data you bring in or generate there. That duty does not pass to the landlord.
If you keep paper notes, lock them in a container that you control. Do not leave them in the room, even in a locked drawer, because the landlord may hold a key as well. The safest habit is a locked case that travels with you, emptied after every session.
Laptops, tablets and phones need a password, and ideally encryption. Before you connect to the room’s WiFi, ask the landlord whether the network is secured and whether traffic is monitored. Never open client records over an unsecured network.
Never write client names or anything identifiable on a whiteboard or flip chart in a shared room. Wipe them clean before you leave, every single time.
Many buildings have CCTV in communal areas such as entrances and corridors. Under GDPR, footage that identifies individuals is personal data. The landlord is the data controller for communal CCTV and must have a lawful basis, clear signage, and a privacy notice. Find out who runs it. You should be able to tell clients who operates the CCTV and how to contact them.
Covert recording inside a therapy room is illegal under the Investigatory Powers Act 2016 and UK GDPR. If you find a recording device in the room itself, treat it as a serious breach and act at once.
Most rental agreements give landlords access for maintenance and emergencies. That is a problem if client materials are sitting in the room. Take every note and device with you at the end of each session. If you really must store something on-site, use a locked container where you alone hold the key or combination.
If a breach occurs, for example if your laptop is stolen from the room or notes are left behind and read, you must assess the risk to the individuals involved. Timing counts here. If the breach is likely to result in a risk to their rights and freedoms, you must notify the ICO within seventy-two hours and inform affected clients without undue delay.
Your privacy notice should explicitly mention:
GDPR compliance in a rented therapy room comes down to good habits and clear policies. Minimise what you store on-site. Secure the rest. Be upfront with clients about the building they are walking into, and know exactly what you have to do if something goes wrong.
Need a secure therapy room? Browse available rooms across the UK that meet professional privacy standards.
Published: May 2026 | Last Updated: May 2026