GDPR and Data Privacy for Therapy Room Rentals: What UK Practitioners Need to Know

Data protection is a legal obligation for every therapy practitioner in the UK. Renting a room adds complications that home-based practitioners never have to think about. Who is responsible for data security in a shared building? Can you store client notes on-site? What happens if the landlord operates CCTV in communal areas? Those questions come up constantly. This guide answers the most common GDPR questions for therapy room renters and shows what compliance looks like in practice.

Professional office environment with secure filingProfessional office environment with secure filing

Your Lawful Basis for Processing Data

Under UK GDPR, you must have a lawful basis for processing any personal data. For therapy practitioners, the relevant bases are:

  • Contract: Processing necessary to deliver the agreed therapeutic service
  • Legal obligation: Where record-keeping is required by law or professional regulation
  • Consent: For uses beyond direct therapy, such as research or marketing
  • Vital interests: In emergencies where life is at risk

Most therapeutic record-keeping falls under contract or legal obligation. Not sure which basis applies to you? The Information Commissioner’s Office (ICO) has detailed guidance on identifying lawful bases.

Special Category Data

Therapy records are classified as special category data because they concern health, mental health, and sex life. The ordinary rules are not enough. You must also meet an additional condition under Article 9 of UK GDPR. For healthcare practitioners, that condition is normally that processing is necessary for healthcare purposes.

Physical Data Security in a Rented Room

When you rent a therapy room, you remain responsible for the security of any data you bring in or generate there. That duty does not pass to the landlord.

Paper Records

If you keep paper notes, lock them in a container that you control. Do not leave them in the room, even in a locked drawer, because the landlord may hold a key as well. The safest habit is a locked case that travels with you, emptied after every session.

Electronic Devices

Laptops, tablets and phones need a password, and ideally encryption. Before you connect to the room’s WiFi, ask the landlord whether the network is secured and whether traffic is monitored. Never open client records over an unsecured network.

Whiteboards and Flip Charts

Never write client names or anything identifiable on a whiteboard or flip chart in a shared room. Wipe them clean before you leave, every single time.

CCTV and Recording Devices

Many buildings have CCTV in communal areas such as entrances and corridors. Under GDPR, footage that identifies individuals is personal data. The landlord is the data controller for communal CCTV and must have a lawful basis, clear signage, and a privacy notice. Find out who runs it. You should be able to tell clients who operates the CCTV and how to contact them.

Covert recording inside a therapy room is illegal under the Investigatory Powers Act 2016 and UK GDPR. If you find a recording device in the room itself, treat it as a serious breach and act at once.

Landlord Access and Confidentiality

Most rental agreements give landlords access for maintenance and emergencies. That is a problem if client materials are sitting in the room. Take every note and device with you at the end of each session. If you really must store something on-site, use a locked container where you alone hold the key or combination.

Data Breach Response

If a breach occurs, for example if your laptop is stolen from the room or notes are left behind and read, you must assess the risk to the individuals involved. Timing counts here. If the breach is likely to result in a risk to their rights and freedoms, you must notify the ICO within seventy-two hours and inform affected clients without undue delay.

Your Privacy Notice

Your privacy notice should explicitly mention:

  • That sessions take place in a rented room within a shared building
  • Whether the building has CCTV in communal areas
  • How and where records are stored and secured
  • How long records are retained
  • Clients’ rights under UK GDPR

Practical Compliance Checklist

  1. Take all notes and devices with you after every session
  2. Use encrypted storage for electronic records
  3. Lock your bag or case whenever it is unattended
  4. Confirm whether the building has CCTV and understand who operates it
  5. Include the rental location in your privacy notice
  6. Ask the landlord about their data protection policies
  7. Verify that your professional indemnity insurance includes data breach cover

Conclusion

GDPR compliance in a rented therapy room comes down to good habits and clear policies. Minimise what you store on-site. Secure the rest. Be upfront with clients about the building they are walking into, and know exactly what you have to do if something goes wrong.

Need a secure therapy room? Browse available rooms across the UK that meet professional privacy standards.

Published: May 2026 | Last Updated: May 2026

Regulatory References

Comments

About the Author: Peter Klein is the founder of Rent A Therapy Room, the UK’s largest platform for renting and letting therapy rooms, treatment spaces, and consulting rooms. A practising CBT therapist since 2008, Peter created RATR to help practitioners find affordable, professional therapy spaces across the UK and Ireland. Learn more →

Comments

  • No comments yet.
  • Add a comment