Most of the time, a session note is written for one reader. You write it, you read it before the next session, and nobody else ever sees it.
The exception is what makes the decision difficult. A client asks for everything you hold about them. A solicitor writes. A complaint is made three years after the work ended. A colleague has to establish what happened in a practice that has stopped operating. In those moments the note stops being a private aide-memoire and becomes a record that someone else reads, in a context you do not control, sometimes years later.
Good records are not primarily a defence. They help you hold the thread of the work, they support supervision, and they let anyone who legitimately needs to understand the care later actually do so. Choosing software is mostly about whether it can still serve those purposes when the reader is not you.
This guide sets out what to look for, as evaluation criteria rather than a feature list. It applies whether you are moving off Word documents, replacing a system that is not coping, or deciding whether an AI note-taker belongs in your practice at all.
In this guide
- What clinical notes software is, and what it should provide
- A checklist you can take into a demo
- Why the note that matters is the one somebody else reads
- Ten things clinical notes software should be able to do, each with a test
- What UK guidance actually says about retention, and why the seven-year figure you keep seeing is not a rule
- Whether process notes are really private, and what separate fields do and do not protect you from
- What to work through before using an AI note-taker in UK private practice
- Answers to the questions most commonly asked about therapy notes and software
What is clinical notes software?
Clinical notes software is a system for writing, storing and retrieving client session records, built around the obligations that come with holding health information: access control, audit trails, retention periods, subject access, and secure disposal. It differs from a word processor or a shared drive in treating the note as a record with a lifecycle rather than as a file, and in being able to evidence what happened to that record over time.
For counsellors and psychotherapists in UK private practice, it usually sits inside practice management software alongside client details, appointments and invoicing, rather than standing alone.
What should clinical notes software for therapists provide? Secure storage with access control, note formats that suit the way you practise, separation between the clinical record and reflective material, an audit trail and version history, retention you set rather than inherit, support for subject access and other disclosure requests, controlled export, and a full data export if you leave. Where AI is used to draft notes, it should also give you a lawful basis you can evidence, human review before anything enters the record, and clarity on where data is held, who processes it and whether it leaves the UK.
Ten things to check, in short
| What to check | Why it matters |
|---|---|
| Flexible note formats | Different modalities need different structures |
| Separate reflective notes | Lets you review each category of material properly |
| Retention controls | Retention should be a decision you made, not a default |
| Subject access export | Turns a day of assembly into a task |
| Version history | Shows how a record changed and when |
| Audit trail | Establishes who accessed or altered what |
| Human-reviewed AI drafts | Keeps unchecked generated text out of the record |
| Sub-processor visibility | Shows who else handles client data, and where |
| Granular permissions | Limits access to those who need it |
| Full export | Protects you when you change systems |
The rest of this guide explains each one, and gives you a way to test it.
Why a folder of documents stops being enough
Three things change once your caseload grows.
You are the data controller. In private practice, you decide what is recorded, why it is held and how long it is kept, and you carry the responsibility for those decisions. Session notes will ordinarily contain health information, which is special category data under UK GDPR. Not everything in a clinical system is special category data by virtue of sitting there, since whether information falls into that category depends on the nature of the data itself, but the notes themselves usually will. The ICO's guidance on special category data sets out the additional conditions and documentation that follow. We cover the broader picture in our guide to UK GDPR for therapists.
Records get read by people other than you. BACP's guidance on what complaints tell us is direct about the ordinary version of this: clients have a right to see their notes, and members are expected to explain that right at the contracting stage. The unusual versions, a solicitor's letter or a witness summons, arrive without warning.
Nobody can reconstruct what you did not record. A document that has been edited leaves no trace of what it said before. A folder does not know who opened it. If a complaint turns on whether a risk conversation happened, a note with no reliable date is worth less than one with a timestamp you did not control.
None of this makes a Word document unlawful. It makes it hard to evidence.
Ten things clinical notes software should be able to do
1. Let you write the way you actually practise
SOAP came from general medicine. Subjective, Objective, Assessment, Plan works reasonably well for structured, goal-focused work and poorly for approaches where the material of the session is the relationship rather than a presenting problem to be assessed. A psychodynamic practitioner asked to fill in an Objective field will either leave it empty or write something they do not believe.
Software should offer structure where it helps and get out of the way where it does not: SOAP and DAP for those who want them, narrative or free text for those who do not, and the ability to choose per session rather than per account. Watch for systems that make the template mandatory, because that is where notes start being written for the software rather than for the client.
The test: can you write a note for a person-centred session without leaving a required field blank or inventing something to put in it?
2. Separate the session record from your reflective notes, without overselling what that achieves
Many UK therapists keep two kinds of writing: a factual record of the session, and private reflection for supervision, formulation and their own thinking. Keeping these in separate fields is genuinely useful. It means that when a request arrives you can review each category on its own rather than reading one document and deciding line by line.
What separate fields do not do is make the second category confidential. Subjective opinions about an identifiable person can still be that person's personal data, and calling something a process note does not by itself put it outside a subject access request. The supporting authority is Nowak v Data Protection Commissioner (C-434/16), in which the Court of Justice held that a candidate's exam script and the examiner's comments on it were the candidate's personal data.
The protections that do exist are narrower and more specific: material identifying a third party may be withheld or redacted, and there is an exemption where disclosure would be likely to cause serious harm to the physical or mental health of the client or another person. The ICO's guide to the exemptions sets out how narrowly these operate, and the health data exemption in Schedule 3 of the Data Protection Act 2018 is not something to apply casually to your own records.
Any vendor telling you that process notes stored in their system are private is describing a product decision, not a legal position.
The test: ask what appears in a subject access export. If the answer is that process notes are excluded because they are private, ask on what basis, and who decided.
3. Let you set your own retention period, and evidence it
This is where most published advice is wrong, including advice published by software companies.
There is no general seven-year retention rule for counselling and psychotherapy records in UK private practice. BACP does not set a retention period. Writing on the BACP site, the association's Client Ethics Manager sets out the position plainly: where no statutory period applies, the therapist decides an appropriate period, taking data protection law and their professional body's requirements into account, and tells clients what it is. The reference point BACP does give is its own complaints procedure, which allows up to three years from the end of the therapeutic relationship, so some members set a minimum on that basis. Their guidance on notes and record keeping covers this directly.
Where seven years comes from is a mix of NHS records schedules, professional indemnity insurers, other jurisdictions and habit. It may well be the right answer for your practice. It is not a rule you are complying with, and describing it as one in your privacy notice means you have documented a decision you did not make.
The storage limitation principle sets the actual obligation: do not keep personal data longer than you need it for the purpose you collected it. Longer retention needs a reason, and so does shorter.
What actually decides the number. No statute sets a period for these records, and a court order does not create one either, since an order reaches what you still hold rather than what you disposed of under a policy you can point to. What shapes the decision is how long you could realistically be asked to account for the work:
- BACP's complaints procedure allows up to three years from the end of the therapeutic relationship
- Claims for personal injury, which includes psychiatric injury, generally run for three years from the date the claim arose or the date the client knew, whichever is later, under the Limitation Act 1980. The date of knowledge can fall long after the work ended, and the court has a discretion to allow a late claim
- Some other negligence claims have a six-year period, with additional rules around date of knowledge and, in some circumstances, a fifteen-year long stop
- Where the client was a minor, time generally does not begin to run until they turn eighteen, so a client seen at fifteen may be able to bring a claim well into their twenties
- Your professional indemnity insurer may specify a period of its own, and that one is contractual
Limitation rules vary by cause of action and this is a summary rather than advice on your situation. The point is that most practitioners settle somewhere above three years for a reason, and that reason is a risk judgement about how long the record might be needed rather than compliance with a rule.
One thing retention automation must not do. Intentionally altering, concealing or destroying information to prevent disclosure, once a subject access request has been made, can be a criminal offence under section 173 of the Data Protection Act 2018. The ICO secured its first conviction under that section in September 2025, against a care home director who blocked and erased records after a request arrived. Routine deletion running on schedule is not the target, since the offence turns on intent and the Act provides a defence where the disposal would have happened anyway. Deletion triggered while a request is open is a different matter, and the safe course is to suspend it and take advice.
Software should let you set a retention period, apply a different one where the client was a minor, flag records that have reached it rather than deleting them silently, delete properly when you decide to, including from backups, and hold a record in place while a request is live.
The test: can you set a different retention period for a client seen at fifteen and a client seen at forty-five, does the system tell you when either is due, and can deletion be suspended?
4. Produce a subject access response you can stand behind
A client, or their solicitor, asks for the information you hold. You have one calendar month, extendable by up to two further months where the request is genuinely complex, and the search you carry out needs to be reasonable and proportionate rather than exhaustive. The mechanics, including what changed under the Data Use and Access Act 2025, are covered in our GDPR guide.
The work is rarely finding the notes. It is producing them in a form you are willing to send: everything held on one client, assembled in one place, with material about other people removed, and a record of what was disclosed and when. Doing that from a folder of documents and an email archive takes a day. Doing it badly, by sending the lot, discloses a partner's or a family member's information along with the client's.
Given that a mishandled request can itself become a complaint, it is worth speaking to your indemnity insurer before releasing clinical notes.
The test: how long does it take to produce everything the system holds on one client, in a form you could redact and send?
5. Show who did what, and when
Three things make a record trustworthy to someone reading it later: it is attributable, it is dated by something other than you, and changes to it are visible.
Editing a note is legitimate. You remember something, you correct an error, you add an outcome. What matters is that the change is recorded rather than hidden, because an amended note with no history is easy to characterise as a rewritten one. Version history, an audit trail covering views, edits, exports and deletions, and preserved authorship if a client moves between practitioners all do the same job: they let the record answer questions about itself.
The test: can you show what a note said before you edited it last week, and when the edit was made?
6. AI-assisted clinical notes: keep unreviewed drafts out of the record
AI note-taking is the biggest change in this category and the least well documented for UK practice, because almost everything written about it is American or NHS-facing.
Four things need to be worked through before using an AI note-taker responsibly in private practice.
A DPIA, in almost every case. A data protection impact assessment is mandatory where processing is likely to result in a high risk to people's rights and freedoms, and using new technology to process health records points firmly in that direction. NHS guidance for developers sets out the step on DPIAs, and the ICO's rules on special category data point the same way. For a private practice, completing one is a sensible baseline even where you are unsure the legal threshold is technically met. It is usually a short document, not a project.
A lawful basis you can evidence. You need both an Article 6 lawful basis and an Article 9 condition. Which Article 9 condition is appropriate depends on your circumstances, and some conditions carry additional UK law requirements and professional secrecy safeguards, so this is worth checking against ICO guidance rather than assuming. Note that this is a separate question from whether the client agrees to being recorded. Consent to a recording is a matter of the therapeutic contract and the frame, and you should decide in advance how you will work with a client who does not want the session recorded. For many practitioners that will mean continuing without it.
A human between the draft and the record. Transcription mishears names, attributes speech to the wrong person and invents plausible detail. UK GDPR requires personal data to be accurate, and an unchecked generated note is the actual risk in this technology, more than the transcription itself. The workflow has to end with a person reading the draft and choosing to save it.
Clarity on where the data goes. Whether session audio is retained and for how long, whether the model provider can train on your data, who the sub-processors are, and whether anything leaves the UK. Where personal data is transferred to, or accessed from, another country, the UK GDPR's international transfer rules apply and you need an appropriate transfer mechanism, commonly the UK Addendum to the EU standard contractual clauses or the IDTA, supported by a transfer risk assessment. Zero data retention on the model provider side is worth asking about specifically rather than assuming.
Underneath all of this is an architectural choice, and reasonable practitioners land in different places.
The three approaches to note capture
| In-session recording | Post-session dictation | Typed or handwritten | |
|---|---|---|---|
| What is captured | Client's voice and words | Your summary only | Your summary only |
| Consent conversation | Explicit, before every session | About the tool, not the session | None needed |
| Detail available | Highest | What you remember | What you remember |
| Data held | Audio of the session | Audio or text of your summary | Text only |
| Main risk | Client feels observed; a recording exists | Recall gaps | Time |
AI processing sits downstream of the first two rather than being the choice itself. Neither is the correct answer. Recording captures more and asks more of the client. Dictation asks nothing of the client and depends on your recall. What matters is that you chose deliberately and can explain the choice.
The test: can a generated note enter the clinical record without a person reading it and pressing save?
7. Be clear about where the data lives and who touches it
You are the controller. A software company will generally act as your processor where it processes client data on your behalf, though a provider can be a controller for particular activities of its own. Where it is your processor, there should be a written processing agreement under Article 28, a list of sub-processors, and a statement of where data is stored. Ask where notes are hosted, which third parties can access them, whether staff at the vendor can read clinical content, and what happens in a breach.
Separately, many private practitioners need to register with the ICO and pay the data protection fee, although exemptions exist and the answer depends on what your practice actually does. The ICO's self-assessment tool will tell you in a couple of minutes, and it catches out more sole practitioners than it should.
The test: can the vendor name every sub-processor that touches clinical content, and tell you where each one holds it?
8. Handle a request that comes from outside the therapy
Court orders, witness summonses, police requests and reports for a GP or insurer all have one thing in common: they arrive with a deadline and they are not subject access requests. You may have to produce records, or resist producing them, and either way you need to know exactly what you hold and be able to release a defined part of it rather than everything.
Software should let you export a specified date range for one client in a readable format, and record what was released, to whom, and on what basis.
The test: could you produce three specific months of notes for one client, and evidence a year later exactly what you sent?
9. Work when more than one person is involved
Supervision, associates, an administrator, or a group practice each change the question. Supervisory oversight is a professional obligation. Blanket access to colleagues' clinical notes is not the way to discharge it, and clients rarely understand that it exists.
What good systems do is make access explicit and logged rather than ambient: role-based permissions, a record of every view, and a deliberate decision about whether a practice owner can read notes at all. Our guide to practice management software for UK group practices goes into this in more depth.
The test: who else can open a note, and does the client know that from your privacy notice?
10. Be accessible if you are not, and portable if you leave
Two questions that get asked too late.
If you are unwell, incapacitated or die, someone has to be able to establish what records exist, notify clients and dispose of records appropriately. A clinical will can form part of that continuity plan, but whoever takes responsibility still needs appropriate authority to access and manage confidential records, and where a practitioner has died that involves the estate as well. It needs setting up in advance rather than improvising, and a shared password is not a plan.
If you want to leave, you need your notes out. Ask about export format before you sign up, not after. Ask about import too, because some systems have no bulk import at all, which means switching leaves your history behind and you run two systems until the old records reach the end of their retention period.
The test: can you export every note for every client, today, in a format that is readable without the software?
How to test clinical notes software in a demo
- A note written in your own modality, without a mandatory field that does not fit
- Session record and reflective notes stored separately, with a clear answer on what a subject access export contains
- Retention period set by you, differing for clients seen as minors, with a prompt rather than silent deletion
- Everything held on one client produced in one place, redactable
- A note's previous version shown, with the time of the edit
- An AI draft that cannot be saved to the record without a person reviewing it
- A named list of sub-processors and hosting locations
- A defined date range exported for a single court request
- Access permissions visible, with a log of who has opened what
- A full export of all notes in a readable format
Frequently asked questions about therapy notes and software
What is the best clinical notes software for UK therapists?
There is no single answer, because the requirements differ by practice. A sole practitioner working with self-funding adults needs formats that suit their modality, a retention setting they chose, and a clean subject access export. A group practice additionally needs role-based access and logged oversight. Anyone considering AI drafting needs a DPIA, a review step and clarity on data location. Judge candidates against those criteria rather than against a feature count.
Are UK therapists legally required to keep notes?
There is no general legal requirement to keep clinical notes in private practice. BACP does not require it either, though its guidance notes that a member would be expected to explain their reasons for not making notes if a complaint were submitted. In practice the expectation is strong enough that most practitioners keep records, and notes are often the only evidence available if an account of the work is disputed.
How long should I keep therapy notes?
For as long as you need them for the purpose you collected them, which is a decision you make, document and tell clients about. BACP does not set a period, and no statute sets one for private practice. Seven years is widely quoted but it is not a rule for counselling records, and the source is usually NHS schedules or an indemnity insurer rather than BACP or the ICO.
What informs the decision is how long a claim or complaint could still be brought. BACP's complaints procedure allows three years from the end of the work. Personal injury claims, which include psychiatric injury, generally run three years from the date the claim arose or the client's date of knowledge, whichever is later. Some other negligence claims run six years, with further rules around date of knowledge. Where the client was a minor, time generally does not start until they turn eighteen. Check your indemnity insurance terms as well, since those are contractual.
Does a court order mean I have to keep notes for longer?
No. A court order, a witness summons or a request from a solicitor reaches what you still hold when it arrives. It does not reach records you destroyed earlier under a retention policy you can evidence. What you must not do is destroy records once a request is live: intentionally altering, concealing or destroying information to prevent disclosure after a subject access request has been made can be a criminal offence under section 173 of the Data Protection Act 2018, and the first conviction was secured in September 2025. If anything is under way, suspend deletion and take advice.
Can a client ask to see their therapy notes?
Yes. Clients have a right of access to their personal data under Article 15 of the UK GDPR, and that includes clinical notes. BACP expects members to explain this at the contracting stage rather than leaving clients to discover it. Practically, this is a reason to write notes you would be willing for the client to read.
Can a therapist refuse a subject access request?
Rarely outright. You can refuse where a request is manifestly unfounded or excessive, and you can withhold specific material under a narrow exemption, including information identifying a third party and information whose disclosure would be likely to cause serious harm to someone's physical or mental health. You still have to respond, explain what you are withholding in general terms, and tell the client they can complain to the ICO. Applying an exemption to an entire record because it feels uncomfortable is not a use these exemptions support.
Are process notes disclosable in a subject access request?
They can be. There is no blanket exemption for private or reflective notes, and subjective opinions about an identifiable person can still be that person's personal data. What exists are narrow exemptions, including for information identifying a third party and where disclosure would be likely to cause serious harm to someone's physical or mental health. Keeping reflective material in a separate field makes it easier to review each category properly, which is worth doing. It does not put that material out of reach.
Can I use AI to write my therapy notes?
Yes, with conditions. Complete a DPIA before you start, confirm your Article 6 basis and Article 9 condition cover the processing, review every draft before it enters the record, and know where the audio and text are held, who the sub-processors are and whether anything leaves the UK. Decide separately whether you are recording the session or dictating afterwards, and tell clients which.
Is it safe to use ChatGPT or a general chatbot to write therapy notes?
Pasting session content into a general-purpose consumer chatbot is a disclosure of special category data, and the questions you would ask any processor mostly go unanswered. There is usually no Article 28 processing agreement covering your clinical data, no commitment about where the data is held, no named sub-processor list, and, on consumer tiers, terms that may permit the content to be used for model improvement. Business and enterprise tiers of the same products often differ materially on all four points, which is exactly why the tier matters. A tool built for clinical records should be able to answer those questions in writing.
Do I need a DPIA for an AI note-taker?
Very likely. A DPIA is mandatory where processing is likely to result in a high risk to people's rights and freedoms, and using new technology on health records points that way. Even where you are unsure the threshold is met, completing one is the sensible baseline. For a solo practice it is a short document setting out what data is involved, why the tool is necessary, what could go wrong and what you have done about it.
Where should therapists store clinical notes?
In a system with access control, an audit trail, encryption in transit and at rest, reliable backups, and a written processing agreement with whoever runs it. Personal devices and general consumer cloud storage fail on most of those points. Where the data is held matters too, because processing outside the UK brings the international transfer rules into play.
Do I need to tell clients I use notes software?
Yes. Your privacy notice should say what you record, why, where it is held, how long you keep it and who else can access it. If you use an AI tool, say so. Clients discovering it later is the version of this that generates complaints.
Is Word or Google Docs good enough?
For a very small caseload, possibly. What you are missing is access control, an audit trail, version history and a straightforward way to assemble everything held on one client. None of that matters until it does, and the moment it matters is usually a complaint or a solicitor's letter.
Can my supervisor see my notes?
Not automatically, and in most private practice arrangements they do not need to. Supervision usually works from what you bring rather than from direct access to records. Where a practice does give supervisory or managerial access, it should be role-based, logged, and described in the privacy notice clients read.
What happens to my notes if I stop practising?
They still need managing, which means a plan: who acts, what they can access, how clients are told and how records are eventually destroyed. Whoever acts needs appropriate authority and a lawful basis for what they do, so this is set up in advance rather than improvised.
Where to start
Two questions separate software built for therapy from software adapted to it.
The first is what happens in a subject access request. Ask a vendor to show you everything the system would hand over for one client, and watch how much assembly is involved. The second is whether an AI-generated note can reach the clinical record without a person reading it. If it can, the tool has made a decision that belongs to you.
My-Therapy-Suite keeps session notes alongside client records, appointments and billing, so everything held on a client sits in one place, and AI-generated notes require human review before they enter the clinical record. It is built for UK counsellors and psychotherapists in private practice.
If you are choosing a whole system rather than a notes tool, our buyer's guide to practice management software for UK therapists covers the wider comparison, and our guide for trainee and newly qualified counsellors deals with the placement records question specifically.
About this guide
This guide was written by the team behind My-Therapy-Suite, a practice management platform built specifically for UK counsellors and psychotherapists. The requirements discussed here come from building and testing clinical record-keeping workflows for UK private practices, and from the questions practitioners bring us while they are choosing a system.
Last reviewed: August 2026. Guidance and law change. Check the linked BACP, ICO and legislation.gov.uk sources for the current position. The information here is general guidance rather than legal advice, and limitation and disclosure questions in particular depend on the specific circumstances.
Sources
- BACP, Notes and record keeping
- BACP, Confidentiality: what complaints tell us
- BACP, FAQs about UK GDPR and DPA 2018
- ICO, Special category data
- ICO, What are the rules on special category data?
- ICO, A guide to the data protection exemptions
- ICO, Principle (c): Data minimisation
- NHS AI and Digital Regulations Service, Do a data protection impact assessment
- Nowak v Data Protection Commissioner, C-434/16, Court of Justice of the European Union, 2017
- Data Protection Act 2018, section 173
- Limitation Act 1980