Wholeness & Wellbeing Counselling Agency (WWCA) Policy 4: Data Protection & Privacy Policy Adopted: 30 May 2025 Reviewed: May 2026
Data Protection & Privacy Policy
Purpose
To ensure that WWCA collects, stores, processes, and shares personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, protecting the privacy and rights of all individuals whose data we hold.
Scope
This policy applies to all personal data processed by WWCA, including information relating to:
- Clients
- Counsellors and student counsellors
- Volunteers
- Trustees
- Administrative staff
- Any individual in contact with the organisation
It covers both digital and paper‑based records.
Legal Basis for Processing
WWCA processes personal data under the following lawful bases:
- Consent – freely given, informed agreement from the client.
- Legitimate interest – to provide safe and effective counselling services.
- Legal obligation – where disclosure is required by law or safeguarding duties.
Client Rights Under UK GDPR
Clients have the right to:
- Be informed about how their data is used.
- Access their personal data.
- Request correction of inaccurate information.
- Request deletion of data (where legally permissible).
- Restrict or object to processing.
- Data portability (where applicable).
- Assurance that no automated decision‑making is used.
WWCA will respond to data requests within one month, in line with GDPR requirements.
Data Collection
WWCA collects data through:
- Referral and assessment forms
- Session notes
- Attendance records
- Communication logs
- Emergency contact information
- Supervision notes (anonymised)
Only data necessary for safe and effective service delivery is collected.
Data Use
Personal data is used for:
- Providing counselling services
- Risk assessment and safeguarding
- Supervision (anonymised)
- Service monitoring and evaluation
- Legal compliance
- Administrative purposes
Data is never used for marketing or shared with third parties for commercial purposes.
Storage & Security
- Paper records are stored in locked filing cabinets in secure rooms.
- Digital records are stored on encrypted, password‑protected systems with restricted access.
- Access is limited to authorised personnel only.
- Records are retained for 7 years after counselling ends, then securely destroyed.
Data Sharing
Data may be shared with:
- Emergency services (if there is risk of harm)
- GPs or other professionals (with client consent)
- Authorities where legally required (e.g., safeguarding, serious crime)
WWCA will always seek consent where possible unless doing so increases risk.
Data Breach Management
A data breach is any unauthorised access, disclosure, loss, or alteration of personal data.
If a breach occurs:
- It must be reported immediately to the Service Manager.
- The breach will be investigated and documented.
- Serious breaches will be reported to the Information Commissioner’s Office (ICO) within 72 hours, as required by law.
- Affected individuals will be informed where there is a high risk to their rights or freedoms.
Complaint process
Individuals have the right to make a complaint regarding the processing of their personal data. Details of WWCA’s Data Protection Complaints Procedure are available on request and on our website.
Data Protection Lead
WWCA has appointed the Service Manager as the organisation’s Data Protection Lead. Any questions regarding this Privacy Policy, your personal data, or data protection complaints should be directed to lynne@wwca.uk
Training
All staff, volunteers, and counsellors must complete GDPR training during induction and undertake annual refresher training.
Record Keeping
WWCA maintains:
- A data processing register
- A breach log
- Secure storage and destruction records
Related Policies
Confidentiality Policy
Safeguarding Policy
Record Keeping Policy
Client Agreement & Counselling Contract Policy
