Colin Milne Counselling Commitment:

  • maintaining a data protection system that meets UK GDPR obligations
    • dedicated to safeguarding your personal information
    • ensuring protection of all held personal information

Colin Milne Counselling practice is summarised below


How Colin Milne Counselling Prepared for UK GDPR:

Colin Milne Counselling has a consistent level of data protection and security and has introduced measures to ensure compliancy.

  • Policies and Procedures to meet UK GDPR requirements and standards including:
  • Data Protection Colin Milne Counselling main policy and procedure for data protection has been revised to meet the standards and requirements of the UK GDPR. Accountability and governance measures are in place to ensure that Colin Milne Counselling understands and adequately disseminates and evidences its obligations and responsibilities, with a dedicated focus on privacy and rights of individuals.
    • Data Retention and Erasure to ensure that it meets the ‘data minimisation’ and ‘storage limitation’ principles and that personal information is stored, archived and destroyed in accordance with our obligations. Colin Milne Counselling has procedures in place to meet ‘Right to Erasure obligations’.
    • Data Breaches Colin Milne Counselling procedures ensure that safeguards are in place to identify, assess, investigate, and report any personal data breach as early as possible.
    • Subject Access Request (SAR) Colin Milne Counselling has revised SAR procedures to accommodate the revised 30-day timeframe for providing the requested information and for making this provision free of charge
  • Privacy Notice/Policy (see below) Colin Milne Counselling has revised Privacy Notice(s) to comply with the UK GDPR, ensuring that all individuals whose personal information is processed have been informed of why it is needed, how it is used, what their rights are, who the information is disclosed to and what safeguarding measures are in place to protect their information.
  • Obtaining Consent Colin Milne Counselling has revised consent mechanisms for obtaining personal data, ensuring that individuals understand what they are providing, why and how we use it and giving clear, defined ways to consent to us processing their data.

Colin Milne Counselling provides easy-to-access information at the start of Counselling outlining an individual’s right to access any personal information that is processed about them and to request information about:

  • what personal data is held about them
  • the purposes of the processing
  • the categories of personal data concerned
  • the recipients to whom the personal data has/will be disclosed
  • how long we intend to store your personal data for
  • if we did not collect the data directly from them, information about the source
  • the right to have incomplete or inaccurate data about them corrected or completed and the process for requesting this
  • the right to request erasure of personal data (where applicable) or to restrict processing in accordance with data protection laws, as well as to object to any direct marketing from us and to be informed about any automated decision-making that we use
  • the right to lodge a complaint or seek judicial remedy and who to contact in such instances.

Information Security and Technical and Organisational Measures

Colin Milne Counselling takes the privacy and security of clients and their personal information very seriously and takes every reasonable measure to protect and secure the personal data processed. There are robust information security procedures in place to protect personal information from unauthorised access, alteration, disclosure, or destruction.

GDPR Roles

Colin Milne Counselling has designated Colin Milne as Data Protection Officer (DPO) responsible for awareness of the UK GDPR, assessing UK GDPR compliance, identifying any gap areas, and implementing the new policies, procedures and measures.

If you have any questions about our GDPR compliance policies, please contact Colin Milne directly.


Your Personal Data
Client privacy is very important. Colin Milne Counselling adheres to the high standards of data privacy as required by the UK GDPR (General Data Protection Regulations).

My professional registration with the British Association for Counselling and Psychotherapy (BACP), requires that I keep information both about you and the work that we do. I cannot offer you counselling services unless you allow me to keep this data, which I will use only to provide the services that you have requested. The information that I will keep falls into two categories:

  • Basic personal data: your name, address, email, phone number, video conference ID (if online counselling), and GP contact details.
  • Sensitive personal data: Counselling/therapy records (notes, letters, reports etc.)

Retention of your personal data
will be retained for only as long as it is required to provide therapy, by legislation or to ensure BACP compliance:

  • Basic personal data will be retained on paper, computer or mobile phone and will be deleted within 6 months of the end of therapy.
  • Sensitive personal data will be held on paper or work computer, and retained for a period of 7 years after the end of therapy. After this time, it will be deleted (at the end of that calendar year).

Sharing of your personal data
Your personal data will only be shared as follows:

  • If you are referred by your health insurance provider, or otherwise claiming through a health insurance policy to fund therapy, I will share appointment schedules with that organisation (for billing purposes). I may also share information with that organisation to provide treatment updates.
  • In cases where treatment has been instructed by a solicitor, with your written consent, relevant clinical information (from therapy records) will be shared with legal services as required

In exceptional circumstances, Colin Milne Counselling might need to share your personal information with relevant authorities:

  • When there is need-to-know information for another health provider, such as your GP.
  • When disclosure is in the public interest, to prevent a miscarriage of justice or where there is a legal duty, for example a Court Order.
  • When the information concerns risk of harm to you, or risk of harm to another adult or a child. I will discuss such a proposed disclosure with you unless I believe that to do so could increase the level of risk to you or to someone else.

Security of your personal data
If kept on paper, the container involved will be secured by lock & key.
if kept electronically, the device involved will be password protected. Where possible, individual electronic files will also be individually password protected. Electronic devices holding your personal data will themselves be kept in the personal possession/control of the authorised user, or if not, securely stored.

Your right of access to your personal data
You have a right to access your personal information held by Colin Milne Counselling.
Please contact me to request a copy of your personal data (if any). I will usually be able to respond within 30 days and the records will (usually) be provided on paper.

  • I may charge an admin fee to cover the work involved
  • I may require confirmation of  your identity
  • If data held by Colin Milne Counselling is incorrect,  you may request that I correct it
  • If you think that I have not complied with data protection laws, you can lodge a complaint with the Information Commissioner’s Office (ico.org.uk)

By engaging Colin Milne Counselling to provide you with counselling services, you are acknowledging and agreeing with the above privacy policy. Please do not hesitate to ask any questions you may have about how I hold your data.