Therapy records hold some of the most sensitive information a person will ever share: their mental health, relationships, trauma, identity, risk and safeguarding history. When that information is well protected, clients can speak freely. When it is not, a loss of confidentiality can expose someone to stigma, distress, discrimination or real danger.
The BACP Ethical Framework is the reference point BACP members commit to when they join or renew, and the main document consulted in professional conduct hearings. The current 2018 framework already sets duties around records, confidentiality and data protection. The 2026 framework, mandatory from midday on Tuesday 3 November 2026, brings digital practice much closer to the centre of ethical responsibility.
This article looks at what is changing for data protection and storing client data. It compares the 2018 duties with the 2026 expectations, and sets out practical steps you can take before the new framework takes effect.
At a Glance
- The BACP Ethical Framework 2026 becomes mandatory at midday on Tuesday 3 November 2026. Members continue under the 2018 framework until then.
- The 2018 framework already covers records, confidentiality and compliance with data protection law. The 2026 framework keeps those duties and makes data security a visible, explicit part of ethical practice.
- The clearest new addition is dedicated guidance on artificial intelligence (AI) and digital tools, which the 2018 framework did not address.
- The central change is an expectation that you can demonstrate your reasoning: what you checked, what risks you found, what you told the client and why the remaining risk was acceptable.
- The framework does not name approved software, platforms or encryption. It expects you to assess risk, understand your tools, reduce foreseeable harm, be transparent and remain accountable.
Learning Outcomes
By the end of this article, you will be able to:
- describe how the 2018 and 2026 BACP frameworks each treat records, confidentiality and data protection
- explain what is genuinely new in the 2026 framework for storing and handling client data
- map where client information is created, stored and shared across your practice
- apply proportionate security measures to devices, records, suppliers and remote sessions
- recognise the higher level of scrutiny the framework expects before using AI or new digital tools
- respond appropriately if a personal data breach occurs
Your Free Digital Tools & Client Data Checklist
A one-page checklist of the 9 checks to run, and record, before you enter client data into any app, platform or AI tool, so you can show your reasoning under the BACP 2026 framework.
From 2018 to 2026: What Is Actually Changing
The 2018 framework is built around three sections: Our commitment to clients, Ethics, and Good practice. Data protection sits mainly inside the Good practice section, in the points on records, confidentiality and working to professional standards.
The 2026 framework keeps the same underlying values but reorganises them into three sections: working ethically within all professional relationships, ethical principles, and a set of core responsibilities. BACP describes three main changes. The framework now emphasises working ethically within every professional relationship rather than the client relationship alone. Members are expected to provide a rationale for their ethical decision making, which they can use in supervision, in reflection and in choosing continuing professional development (CPD). And a core responsibilities section adds new guidance on the use of AI and digital technology.
For data protection, the change is one of emphasis and visibility rather than a complete rewrite. Many of the underlying duties already existed in 2018. What the 2026 framework does is bring them together, connect them to digital practice, and expect you to show your working.
What the 2018 Framework Says About Data and Records
The 2018 framework already contains clear commitments. Members commit to keeping accurate and appropriate records and to protecting client confidentiality and privacy. Good practice point 15 requires records that are “adequate, relevant and limited to what is necessary for the type of service being provided” and that comply with applicable data protection requirements, pointing members to the Information Commissioner’s Office (ICO).
Confidentiality is set out in good practice point 55. It requires members to actively protect information about clients from unauthorised access or disclosure, to inform clients how their personal data will be used and who is within the circle of confidentiality, to make sure anyone receiving identifiable information agrees to treat it as confidential, to explain foreseeable limits to confidentiality in advance, to disclose identifiable information only with consent or a recognised legal justification, and to use thoroughly anonymised information where that is a practical alternative.
Digital and online work appears more briefly. Good practice point 20 says the ethical principles apply regardless of whether you work online, face to face or by any other method, and that the technical and practical knowledge may vary by delivery method, but services will be delivered to at least fundamental professional standards. Point 33(c) asks members to keep a distinction between their personal and professional presence on social media. Point 42 covers what happens if a practitioner dies or becomes too unwell to contact clients, requiring someone to be appointed to communicate with them.
What the 2026 Framework Expects
The 2026 framework carries these duties forward and sharpens them for digital practice. Records must be factual, adequate and relevant, stored securely in accordance with the law where they are stored, and the wording explicitly includes communications, notes and other client information held. Privacy and confidentiality duties now sit alongside a requirement for a clear, accessible privacy notice covering collection, use, storage, protection, client rights and foreseeable limits to confidentiality.
The framework also introduces expectations that had no direct equivalent in 2018. It addresses AI and digital tools directly. It recognises that legal duties may arise both where the therapist works and where the client lives, which matters for online and cross-border practice. And it frames the response to things going wrong around candour, prompt explanation, apology and meeting legal duties.
The Central Change: Being Able to Demonstrate Your Reasoning
The strongest practical shift is the expectation that you can show your reasoning. Under the 2018 framework, members already agreed to be openly accountable and ready to explain why they decided to act as they did. The 2026 framework makes this explicit and routine for digital decisions.
It is no longer enough to say that a platform looked secure or that everyone uses it. You should be able to show what you checked, what risks you identified, what information you gave the client, what consent or agreement you obtained, and why any remaining risk was reasonable. This reasoning is exactly what you would draw on in supervision, and what a supervisor, an insurer or a professional conduct panel would expect to see.
Storing Client Data: The New Standard in Practice
The framework does not prescribe specific technical controls. It expects proportionate risk reduction, judged against the sensitivity, volume and context of the information you hold. Three steps make the expectation manageable.
Map the Client Data Journey
List every place where client information is created, copied, viewed, transmitted or stored. Include the less obvious locations: website contact forms, calendar invitations and appointment reminders; email inboxes, text messages and phone backups; payment and accounting systems; cloud notes, local files, paper notes and printer queues; video platforms, transcripts, recordings and AI assistants; and supervision notes, agency systems and anything a clinical executor could access. This exercise usually reveals duplicate records and forgotten copies. Reducing unnecessary copies is one of the simplest ways to lower risk.
Review Your Privacy Notice and Working Agreement
A privacy notice should accurately describe the tools you actually use. It should explain what personal information you collect and why, the lawful basis and any special category condition, which suppliers process the information and where it is stored, how long you keep it and how you delete it securely, who may receive it and the foreseeable limits to confidentiality, the client’s data protection rights, and whether any platform records or transcribes sessions.
Bring Records Under One Policy
The 2026 wording is broad and includes communications, notes and other client information. That means a consistent approach to email, text messages, booking messages and platform chats, not just formal case notes. This does not mean keeping every trivial message forever. Records should stay factual, adequate and relevant. The point is to make a deliberate, documented decision about what forms part of the record, where it is kept and when it will be deleted.
Therapy Lock
An encrypted vault for UK counsellors and psychotherapists. Write your session notes, keep client records, and manage appointments in one secure place – built around UK data protection law and the ethical standards of the profession, by the team behind Counselling Tutor.
A Practical Security Standard for Small Practices
The following measures are sensible ways to show proportionate risk reduction. The right combination depends on what you hold. They fall into four areas: your devices and accounts, your records and backups, the suppliers and cloud platforms you rely on, and how you run remote sessions.
Devices and Accounts
- Use a separate professional account or device profile that family members and other users cannot access.
- Use strong, unique passwords, a password manager and multifactor authentication where available.
- Enable device encryption, automatic screen locking, security updates and remote wipe where appropriate.
- Keep confidential material out of unprotected downloads, desktops, shared photo libraries and consumer backups.
Records and Backups
- Store records in a system designed for confidential information, with encryption in transit and at rest where proportionate.
- Limit access to those who genuinely need it and review access when roles change.
- Keep a tested backup that can restore your records after loss, damage or ransomware.
- Use a written retention schedule and securely destroy paper and electronic records when the retention period ends.
Suppliers and Cloud Platforms
- Read the supplier’s privacy and security information rather than relying on marketing claims.
- Understand whether the supplier is a processor, what contract applies, which subprocessors are used and where data is stored or accessed.
- Check whether data can be exported and deleted, what happens when the account closes and how you would be told about a breach.
- Review the service periodically, because terms, ownership, functions and data locations change.
Remote Sessions
- Use a private room, headphones where appropriate and a screen that cannot be overlooked.
- Use unique meeting links, waiting rooms and appropriate access controls.
- Turn off recording, automated transcription, AI notes and smart assistants unless you have deliberately assessed, explained and agreed them.
- Agree in advance what happens if privacy is interrupted or the connection fails.
AI and Digital Tools: A Higher Level of Scrutiny
This is the clearest new addition. The 2018 framework did not mention AI. The 2026 framework expects you to demonstrate competence, an understanding of data handling, risk mitigation, transparency and informed consent before using an AI tool, digital tool or online platform, and to retain professional responsibility for any decision influenced by AI.
New requirement: informed consent before entering client data into AI tools
Before entering any client information into an AI or digital tool, work through these questions:
- What exact purpose does the tool serve, and is the use necessary and proportionate?
- Will the information identify the client directly, or indirectly when combined with other details?
- Does the provider keep prompts, use them to train models, allow human review, or share them with subprocessors?
- Where is the data stored or accessed, for how long, and can it be deleted?
- Has the client received a genuine explanation of the benefits, risks and alternatives, including the option not to use the tool?
- How will you check the accuracy, bias and relevance of the output?
- What will you record about the decision and the client’s consent?
Consent and Lawful Basis Are Not the Same Thing
BACP requires informed consent before personal data is entered into AI or digital tools. This ethical agreement does not replace your separate duty to identify a lawful basis under UK GDPR, as amended by the Data (Use and Access) Act 2025, and, for special category data, an appropriate condition. A signed consent form does not make an insecure or unlawful arrangement acceptable.
Do Not Assume Anonymised Means Safe
Removing a name may not be enough. A rare occupation, a location, a family event, a diagnosis or a combination of life details can still identify a person. For supervision prompts or case summaries, use the minimum necessary information, and consider whether the task can be done without entering any client material at all.
AI Does Not Carry the Ethical Responsibility
An AI output may be useful information, but it cannot hold the therapeutic relationship, understand the full context, take responsibility for harm or provide an ethical rationale to a client, supervisor, court or conduct panel. That responsibility stays with you.
When Something Goes Wrong
A personal data breach can involve loss, destruction, alteration, unauthorised access or disclosure. Everyday examples include sending an email to the wrong person, losing an unlocked device, an account being compromised, notes being seen by someone at home, or a supplier exposing stored data.
Because the framework expects candour, it helps to have a plan before an incident happens:
- Contain it. Recover information where you can, change compromised credentials, contact an unintended recipient, isolate an affected device or get specialist help.
- Establish the facts. Record what happened, when you found out, who and what was involved, the likely consequences and the actions already taken.
- Assess the risk. Consider the potential for distress, stigma, discrimination, safeguarding harm or identity fraud.
- Meet notification duties. A breach that meets the reporting threshold must be reported to the ICO without undue delay and, where feasible, within 72 hours. High-risk breaches may also need prompt communication to the people affected.
- Communicate with candour. Explain promptly and clearly, describe the likely effects, apologise and say what you are doing to limit harm.
- Learn from it. Record the outcome, discuss it in supervision, review your systems and change whatever allowed it to happen.
Not every breach must be reported to the ICO, but every breach should be assessed and documented. If you are unsure, use current ICO guidance or seek appropriate advice promptly.
Your Free Digital Tools & Client Data Checklist
A one-page checklist of the 9 checks to run, and record, before you enter client data into any app, platform or AI tool, so you can show your reasoning under the BACP 2026 framework.
Frequently Asked Questions
When does the BACP Ethical Framework 2026 take effect?It becomes mandatory at midday on Tuesday 3 November 2026. Until then, BACP members continue to work under the 2018 framework. Check the BACP website for the final implementation details and updated resources.
Does the 2026 framework tell me which software or platform to use?No. It does not name approved platforms, encryption or systems. It expects you to assess risk, understand how your tools handle data, reduce foreseeable harm, be transparent with clients and remain accountable for your choices.
What is the biggest change for data protection?The expectation that you can demonstrate your reasoning. You should be able to show what you checked, what risks you found, what you told the client, what consent you obtained and why the remaining risk was acceptable. Dedicated guidance on AI and digital tools is the clearest new addition.
Do I need client consent before using AI tools with their information?Yes. BACP requires informed consent before personal data is entered into AI or digital tools. Consent is separate from your legal duty to identify a lawful basis under UK GDPR and, for special category data, an appropriate condition. Consent does not make an unlawful or insecure arrangement acceptable.
What should I do if I have a data breach?Contain the incident, establish the facts, assess the risk to the person, and meet any notification duties. A breach that meets the reporting threshold must be reported to the ICO without undue delay and, where feasible, within 72 hours. Communicate with candour, then review your systems in supervision.
Final Reflections
Data security is relational before it is technical. It protects the trust, dignity and freedom that allow a client to speak openly. The 2026 framework asks you to treat every digital decision as an ethical decision: one you can understand, explain, agree where required, protect and review.
Much of this already lives in the 2018 framework. The shift is that data protection is now visible and demonstrable, and that digital competence is treated as continuing competence. A tool that suited you last year may change its functions, terms, ownership or data location. The months before 3 November 2026 are a good opportunity to map your data, review your privacy notice, tidy your records and put a breach plan in place.
References and Further Reading
The information in this article is correct at the time of publishing (August 2026). The BACP Ethical Framework 2026 becomes mandatory at midday on 3 November 2026; check the BACP website and the linked official sources for the latest details before acting on them.
Transparency note
This article was written and reviewed by human contributors. AI was used as a supportive tool to assist with formatting, layout clarity, and language refinement. All content, interpretations, and ethical positions were created and checked by the authors.
💡 About Counselling Tutor
Counselling Tutor provides trusted resources for counselling students and qualified practitioners. Our expert-led articles, study guides, and CPD resources are designed to support your growth, confidence, and professional development.
👉 Meet the team behind Counselling Tutor
Notice any broken link or issues with this resource? Kindly let us know by email
Email us