Online & Telephone Counselling Course – Enrolment Open

Choosing Safe Apps in the Age of AI: A Counsellor’s Guide to Vetting Digital Tools

A counsellor checking a counselling app privacy and security against a checklist before signing up, choosing safe apps for counsellors in the age of AI

A note-taking app, a booking system, an AI tool that writes up your sessions: the sales page shows a tidy interface and promises to save you hours. That is not the question that matters. The question is whether the tool is safe to trust with some of the most sensitive information a person will ever share.

Counselling records often contain information about a person’s physical or mental health. Where they do, that information is special category data under UK GDPR, a category subject to additional protection. You are usually the data controller, which means you carry the responsibility for those records even when they sit on someone else’s server on the other side of the world. Choosing the tool is not a shopping decision. It is an ethical and legal one.

Safe apps for counsellors start with the checks you make before you sign up, not with the feature list. This guide sets those checks out for the way most counsellors actually decide: quickly, from a phone, with a free trial in front of you. The BACP Ethical Framework 2026 raises the bar here, so the checks matter more than they used to.

At a Glance

  • Counselling records often contain health information. Where they do, that is special category data under UK GDPR, subject to additional protection. You will usually be the data controller and must be able to demonstrate compliance wherever the records are stored.
  • The BACP Ethical Framework 2026 becomes mandatory at midday on Tuesday 3 November 2026. Until then, members remain committed to the 2018 framework. It expects you to assess the risk of any AI tool, digital tool or online platform before you use it, and to be able to demonstrate how you reached that decision, including that you have your clients’ informed consent before entering their information into it.
  • Before signing up, five checks tell you most of what you need to know: can you find the paperwork, is there a real company behind it, where is your data stored, does it use AI, and can you leave with your data.
  • If a supplier hides its privacy policy, terms or data processing agreement, treat that as a significant warning sign and do not enter client data until the position is clear.
  • Sending data outside the UK may trigger the UK’s restricted-transfer rules. Your wider obligations as the UK controller continue, and the transfer needs an appropriate basis such as adequacy, a safeguard like the IDTA, or a legal exception.

Learning Outcomes

By the end of this article, you will be able to:

  • explain why choosing an app is an ethical and legal decision, not a convenience one
  • recognise what the BACP Ethical Framework 2026 expects before you adopt a digital or AI tool
  • carry out five practical checks on any app before you enter client data into it
  • understand why sending data outside the UK changes what you need to have in place
  • ask a supplier the right questions about AI, data storage, sub-processors and leaving the service
  • record the reasoning behind your choice so you can account for it later

Your Free Five Checks Vetting Checklist

The BACP 2026 framework says you should be able to explain why you chose a tool. This one-page checklist gives you the five checks to run before you enter a single client detail, plus a record you can keep.

Why Choosing an App Is an Ethical Decision

Two facts sit underneath everything that follows.

A counsellor holding a padlocked client record, reflecting on their responsibility as data controller when choosing where sensitive notes are kept

First, counselling records often contain information about a person’s physical or mental health. Where they do, that information is special category data under UK GDPR, a category subject to additional protection alongside data about sex life, beliefs and ethnicity. When that information is well protected, clients can speak freely. When it is not, a loss of confidentiality can expose someone to stigma, distress, discrimination or real danger.

Second, you will usually be the data controller. You decide why and how client information is collected and used, so the legal responsibility is yours. A supplier that processes those records only on your documented instructions will usually be a processor, but the parties’ roles depend on the actual arrangement, not simply on what the contract calls them, and in some setups a supplier can be a controller or joint controller.

Where a supplier acts as your processor, UK GDPR requires a written contract between you. This contract, usually called a data processing agreement or DPA, should cover matters including your instructions, confidentiality, security, the use of sub-processors, help with clients’ data rights, audits, and the return or deletion of the data at the end of the arrangement. The responsibility does not transfer to the supplier: you retain important controller duties and must be able to demonstrate compliance. If you work for an agency, service or organisation, it will usually be the controller for the records you keep there. In that case, use the tools it has approved, and raise any concerns through its own policies rather than choosing a tool yourself.

Choosing a tool, then, is not about the interface or the hours saved. It is about whether you can meet your duties as the person accountable for the data.

What the BACP Ethical Framework 2026 Expects

The BACP Ethical Framework is the reference point members commit to when they join or renew, and the document consulted in professional conduct hearings. The 2026 framework becomes mandatory at midday on Tuesday 3 November 2026, and until then members remain committed to the 2018 framework. It brings digital practice much closer to the centre of ethical responsibility than the 2018 version did.

Its clearest new expectation is that you assess the risk of any artificial intelligence tool, digital tool or online platform before you use it. The framework asks you to be able to demonstrate that you are competent to use the tool, that you understand how data are handled and stored and have reduced the risks to confidentiality as far as possible, that you are honest with clients about the benefits and risks, and that you have their informed consent before entering their information into it.

A checklist of what the BACP Ethical Framework 2026 asks counsellors to demonstrate before using an AI or digital tool: competence, data handling, transparency, consent and staying responsible

Alongside this sits a duty that runs through the whole framework: you should be able to give a rationale for your decisions. It is no longer enough to say a platform looked secure or that everyone uses it. You should be able to show what you checked, what you found and why you judged the remaining risk acceptable. The five checks below are how you build that record before you commit, rather than trying to reconstruct it after a problem.

The framework deliberately does not name approved apps, platforms or encryption standards. It expects you to assess the tool in front of you. The rest of this article is a way of doing that.

The Five Checks Before You Sign Up

These checks work for any tool that will hold or handle client information: a note-taking app, a practice management system, a video platform, or an AI assistant that transcribes or summarises sessions.

Run through them before you enter a single real client detail. A free trial is not a reason to skip them. Each of the five checks below is quick, and together they tell you most of what you need to know before you trust a tool with client data.

A five-step diagram of the checks to make before signing up to a counselling app or AI tool: paperwork, company, data location, AI and exit

Check 1: Can You Find the Privacy Policy, Terms and DPA?

A supplier that takes data protection seriously makes its paperwork easy to find. Look for three documents: a privacy policy, the terms of service, and a data processing agreement (or data processing addendum). The DPA is the written contract UK GDPR requires where a supplier acts as your processor. It should set out what the supplier does with the data, the security it applies, the sub-processors it uses and what happens when you leave.

Read past the marketing. A privacy policy should tell you what is collected, why, where it is stored, how long it is kept and who it is shared with. If you cannot find these documents, if the DPA is only available on an expensive enterprise plan, or if the language is vague about storage and sharing, treat that as a significant warning sign and do not enter client data until the position is clear. A supplier that hides how it handles data has not met a basic expectation.

Before a trial, search the supplier’s site for “privacy”, “terms” and “DPA” or “data processing”. Save copies of what you find, with the date, so you have a record of the version you agreed to. If a DPA is not offered to individual practitioners, email and ask for one. How a supplier responds to that email is itself useful information.

Check 2: Is There a Real, Registered Company Behind It, and Is It on the ICO Register?

An app is only as accountable as the organisation behind it. Find out who that organisation actually is. A legitimate supplier names its company, gives a registered address and can be looked up at Companies House. An app with no identifiable company behind it, or only an anonymous support address, leaves you with no one to hold to the contract.

Most organisations that process personal data in the UK must pay a data protection fee and appear on the ICO’s public register, though there are exemptions, and some organisations are exempt from the fee while still having to comply with the law. Check whether the supplier is required to pay the fee and, if so, whether it appears on the register, which you can search by name. Registration is not a security certification or a quality mark. If the supplier is not listed, ask it to explain whether an exemption applies, and weigh the answer alongside its contractual, security and privacy documentation. Keep your own ICO position separate from the supplier’s: you may be the controller while the supplier is a processor, and the fee and registration position depends on each organisation’s actual processing and any exemption.

Look up the company on the ICO register and at Companies House before you commit. Note the registered company name, which is often different from the app’s brand name. If you cannot identify the contracting legal entity, do not proceed until you can identify it and understand the contractual relationship.

Check 3: Where Is Your Data Stored?

This is the check most easily missed, and it can carry significant risk. Ask where the supplier stores and processes your data, and get a clear answer. Somewhere in the world, your client records sit on a physical server, and the country that server is in matters.

When personal data is sent to, or made accessible to, an organisation outside the UK, the UK’s restricted-transfer rules may apply. This does not mean UK GDPR stops applying to you: your wider obligations as the UK controller continue, and the transfer must be covered by an applicable UK adequacy regulation, an appropriate safeguard, or a legal exception. UK storage is not automatically required. The question is whether the transfer is necessary, transparent, properly documented and covered by the right mechanism, alongside suitable technical and organisational safeguards. “Cloud-based” is not an answer to the question. The question is which country.

A diagram showing counselling client data leaving the UK to an overseas server, illustrating the loss of UK GDPR protection when data is stored abroad

The United States is a common example. The UK has a partial adequacy arrangement for US organisations certified under the UK Extension to the EU-US Data Privacy Framework. Transfers to US organisations outside that arrangement may instead need an International Data Transfer Agreement (IDTA) or the UK Addendum, together with a transfer risk assessment. Either way, weigh whether you are comfortable that your clients’ most sensitive data sits under another country’s laws.

Ask the supplier plainly: in which country is my data stored, and in which country is it processed or accessed? Storage and access can be in different places, so ask about both. If the answer is outside the UK, check which transfer mechanism the supplier relies on, whether that is adequacy, the IDTA or the UK Addendum, and whether a transfer risk assessment has been carried out.

TherapyLock, an encrypted vault for counsellors and psychotherapists to store session notes and client records

TherapyLock

An encrypted vault for UK counsellors and psychotherapists. Write your session notes, keep client records, and manage appointments in one secure place. Built around UK GDPR and the ethical standards of the counselling profession, by the team behind Counselling Tutor.

Check 4: Does It Use AI, and Where Do Your Notes and Recordings Go?

A counsellor pausing before entering client information into an AI tool, considering consent and where the data goes

Many tools now add AI features: transcription, session summaries, note generation, chat assistants. Some are built entirely around them. Before you use any of these, you need to know what happens to the material the AI processes, because a recording or transcript of a session is about as sensitive as data gets.

Ask where the recordings, transcripts and prompts go. Are they processed in the UK or sent abroad? Are they retained, and for how long, including in backups? Are they used to train the provider’s models or to improve the product? Can a member of the provider’s staff, or an administrator, read them, and is that access logged and audited? Which sub-processors are involved, and how would you be told about a data breach? An AI feature bolted onto an app can route your clients’ words through a different supplier, in a different country, under different terms. The convenience is visible on the screen. The data journey is not, so you have to ask.

Some of this processing needs more than a supplier checklist. Where a tool records, transcribes or analyses therapy sessions, or processes sensitive information at scale, consider whether it is likely to result in a high risk to people’s rights and, if so, whether you need to carry out a data protection impact assessment (DPIA). Processing of this kind may warrant specialist data protection advice.

General-purpose AI tools such as ChatGPT, Claude or Gemini were not built for clinical records. Do not enter client information into them, even with names removed. Small details can still identify a person, and once the material is entered you cannot control where it goes or how long it is kept.

Where a tool is built for confidential clinical material and has passed the checks above, enter as little identifiable material as the task needs. Remove names and direct identifiers where you can, leave out unnecessary dates, locations and distinctive details, check whether the tool can work without keeping what you input, and turn off model training or secondary use where that is an option.

This is also where consent becomes non-negotiable. The BACP framework expects informed consent before you enter a client’s information into an AI or digital tool. That means a genuine conversation about what the tool does, where the data goes and the option to decline, not a line buried in a working agreement.

Checking how a tool handles data is one part of using AI ethically. For a fuller, structured way to think an AI tool through, our AI & Therapy Critical Thinking Matrix sets out ten ethical domains to reflect on, from confidentiality to professional accountability.

For any AI feature, get answers in writing: where the data is processed, whether it is retained and for how long, whether it trains models or improves the product, who can access it and whether that is logged, which sub-processors are used, and how breaches are notified. If the supplier cannot answer clearly, do not enter client material. The framework is explicit that you must critically evaluate the AI’s output and must not defer or outsource your decision-making to it. The AI produces a draft; reviewing it and taking responsibility for what ends up in the record, and for any decision that follows, stays with you.

Check 5: If You Leave, Can You Take Everything With You?

Suppliers change. Prices rise, features are withdrawn, companies are bought or close down, and terms are rewritten. Before you commit your records to a service, know how you would get them out again. If your notes are effectively trapped inside one app, you are not in control of your own records, and neither is the client whose data it is.

Check whether you can export your full records in a usable format, not a locked or partial one. Check what happens to your data when you close the account: is it returned, and is it then deleted, including from backups, and how would you know. A supplier confident in its service will make leaving straightforward. One that makes your data hard to remove has given you a reason to be cautious before you ever start.

Check, too, that the tool lets you keep records for as long as you need to. Your professional body, your insurer and your own records policy may require you to keep notes for a set number of years after therapy ends, often longer for children and young people. A tool that deletes data automatically, or on a timetable you cannot change, may leave you unable to meet that duty.

Before signing up, find the supplier’s answer to two questions: how do I export all of my data, and what happens to it when I close my account. Test the export during a trial if you can. Keeping your own secure backup of the records means a supplier’s failure or closure does not become the loss of your clients’ notes.

New requirement: informed consent before entering client data into AI tools

The BACP Ethical Framework 2026 expects informed consent before you input any client’s personal information into an AI or digital tool. This is an ethical duty, and it sits on top of, not instead of, your legal obligations under UK GDPR.

BACP informed consent is separate from identifying your lawful basis and, for health data, the Article 9 condition for processing special category data. Do not assume that the client’s consent makes the processing lawful or the arrangement secure. A signed consent form does not cure an inadequate DPA, an unlawful transfer, excessive retention, weak security or an incompatible secondary use of the data. Consent means the client understands what the tool does, where their data goes, the benefits and the risks, and that they can say no. If you cannot explain the tool clearly enough to gain that consent, that is a sign you do not yet understand it well enough to use it.

Ethical AI Practice by Kenneth Kelly

Ethical AI Practice for Counsellors and Psychotherapists in the UK

Kenneth Kelly’s practical framework for counsellors and psychotherapists — navigate AI ethically, protect your clients and practise with clarity.

Recording the Reason for Your Choice

The 2026 framework asks you to be able to give a rationale for your decisions, and choosing a tool is one of them. You do not need a lengthy report. A short note is enough: which tool you chose, what you checked against the five questions above, what you found, what you told clients, why you judged the arrangement acceptable, and a date to review it. Suppliers change their terms and features, so look again on that date, or sooner if the supplier changes its terms, adds AI features or is bought by another company. Keep it with your other practice records. Where the processing is high risk, that record may need to take the fuller form of a DPIA.

A counsellor writing a short note recording why they chose an app, with a review date, as the BACP 2026 framework expects

This is the same reasoning you would bring to supervision, and the same reasoning an insurer or a professional conduct panel would expect to see. Writing a few lines when you adopt a tool is far easier than reconstructing your thinking after something has gone wrong. Good-quality clinical supervision is the natural place to test these decisions before you commit to them.

Frequently Asked Questions

Do I really need a data processing agreement with a note-taking app?

Usually yes. Where an app stores or handles client data only on your documented instructions, it acts as a data processor and you remain the data controller, and UK GDPR requires a written contract between you, usually called a data processing agreement or DPA. Roles depend on the actual arrangement, so a supplier is not always a processor. If a supplier acting as your processor cannot provide a DPA, it is not a safe choice for client records.

Is it a problem if an app stores my data outside the UK?

It can be, but overseas storage is not automatically unacceptable. Sending data outside the UK may trigger the UK’s restricted-transfer rules. Your wider UK GDPR obligations continue, and the transfer must be covered by adequacy, an appropriate safeguard such as the IDTA or UK Addendum, or a legal exception. Where the supplier relies on the IDTA or UK Addendum, a transfer risk assessment is also needed. Always ask which country your data is stored and processed in, and which mechanism the supplier relies on.

How do I check whether a company is registered with the ICO?

Most UK organisations that process personal data must pay a data protection fee and appear on <a href=”https://ico.org.uk/ESDWebPages/Search” target=”_blank” rel=”noopener noreferrer”>the ICO’s public register</a>, which you can search by company name, though exemptions exist. Registration is not a security certification or quality mark. If a supplier is not listed, ask whether an exemption applies and weigh the answer alongside its security and contractual documentation.

Do I need client consent before using an AI tool with their information?

Yes. The BACP Ethical Framework 2026 expects informed consent before you enter client information into an AI or digital tool. Consent is separate from your legal duty to identify a lawful basis under UK GDPR and, for health data, an appropriate Article 9 condition. Consent does not make an unlawful or insecure arrangement acceptable.

Which app should I use?

No framework, including the BACP one, names approved apps. The responsibility is to assess the tool in front of you: check the paperwork, the company, where data is stored, how AI is used and how you would leave, then record why you judged it acceptable. This article gives you the questions; the judgement is yours.

Your Free Five Checks Vetting Checklist

The BACP 2026 framework says you should be able to explain why you chose a tool. This one-page checklist gives you the five checks to run before you enter a single client detail, plus a record you can keep.

Final Reflections

The safest question to ask about any app is not “how much time will this save me?” but “if this went wrong, could I explain the choice I made?” Client trust is built on the confidence that what they share stays protected, and that protection now depends as much on the suppliers you choose as on the room you sit in.

The five checks are quick once they become habit. Find the paperwork, confirm the company, ask where the data lives, ask what the AI does with it, and know how you would leave. Run them before you enter real client data, write down what you found, and you will have met the harder part of the 2026 framework long before it becomes mandatory at midday on Tuesday 3 November 2026.

References and Further Reading

This article is for education and reflective practice. It is not legal advice. Always use the current BACP framework, data protection law, organisational policy and appropriate professional advice for your own context, and review any decision immediately before you act on it. Correct at the time of publishing (September 2026).

Transparency note
This article was written and reviewed by human contributors. AI was used as a supportive tool to assist with formatting, layout clarity, and language refinement. All content, interpretations, and ethical positions were created and checked by the authors.

💡 About Counselling Tutor

Counselling Tutor provides trusted resources for counselling students and qualified practitioners. Our expert-led articles, study guides, and CPD resources are designed to support your growth, confidence, and professional development.

👉 Meet the team behind Counselling Tutor