GDPR Statement
My commitment to protecting your personal data, in plain terms.
Last updated: June 2026
At Counselling with Lana, I understand that trust lies at the heart of the therapeutic relationship. When you share personal and sometimes deeply sensitive information with me, you need to know it will be treated with the utmost care and respect.
This statement explains, in plain terms, what information I collect, why I need it, how I protect it, and what rights you have. It sits alongside my Privacy Policy and Data Retention Policy. If anything here is unclear, please ask me — I am always happy to explain.
1. Who I Am & ICO Registration
Counselling with Lana is a private counselling practice operated by Svjetlana Nowatschek, a BACP-registered integrative counsellor. I am the data controller. As a controller who processes health information electronically, I am registered with the Information Commissioner's Office (ICO). My registration reference is 00014598885.
2. What Information I Collect
To provide effective therapy and run my practice properly, I may collect:
- Your name and contact details (phone number, email address, postal address)
- Emergency contact information
- The reasons that bring you to therapy (your presenting issues)
- Notes from our sessions together
- Relevant medical or health history that may affect our work
- Payment and billing information
3. Why I Collect This Information (Lawful Basis)
I have a lawful basis under UK data protection law to collect and use your information:
- General personal data — Article 6(1)(b) UK GDPR: processing is necessary for the performance of the therapeutic contract between us. In simple terms, I need your information to provide the therapy service you have engaged me for.
- Health-related information — Article 9(2)(h) UK GDPR: because therapy involves sensitive data about your mental and physical health, I rely on the condition that processing is necessary for the provision of health or social care or treatment by a health professional. The additional condition under the Data Protection Act 2018 is Schedule 1, Part 1, paragraph 2 (health or social care). My handling of this data is set out in my Appropriate Policy Document.
4. Professional Obligations & Supervision
As a qualified counsellor, I am required to discuss my clinical work in professional supervision. This is an important part of maintaining high standards of care and a requirement of my BACP membership. Your identity is protected in supervision: I do not share your name or any identifying details, and my supervisor receives anonymised case material only. My supervisor is bound by their own professional body's confidentiality obligations.
5. Clinical Will
I have arrangements for a Clinical Executor — a trusted fellow professional — who would step in if I became suddenly unable to continue practising due to serious illness or death. They would contact you sensitively, offer to help you find another therapist if you wished, and handle your records confidentially and securely in accordance with my policies. This ensures you would not simply be left without communication or support.
6. Who Else May See Your Information
Beyond myself, the following may have limited access to your information. My accounting is done in-house, so no external bookkeeper is involved.
- Clinical supervisor: anonymised case material only (no names or identifying details).
- Hosting & email (IONOS): hosts my website and email on UK/EU-based servers.
- Online session tools (Microsoft Teams and WhatsApp): used to deliver online video sessions where you choose them.
- Statutory authorities: I may be legally required to share information with authorities such as the police or courts in specific circumstances (see section 7).
7. When I Might Need to Break Confidentiality
Confidentiality is fundamental to therapy and I take it very seriously. There are rare circumstances where I may need to share information without your consent:
- If I believe there is a serious risk of harm to you or someone else
- If there are safeguarding concerns involving a child or vulnerable adult
- If I receive a court order requiring disclosure
- Where I am legally required to report information under the Terrorism Act 2000
I will always try to discuss this with you first, unless doing so would increase the risk of harm, and I would only ever share the minimum information necessary.
8. How Long I Keep Your Records
I keep your clinical records securely for 7 years after our last session, in line with the Limitation Act 1980 and standard professional indemnity insurance requirements. After this period, your records are securely deleted. Full details are in my Data Retention Policy.
9. How I Keep Your Data Secure
All records are held digitally, encrypted and password-protected on secure UK/EU-based systems, with access restricted to me alone (and my Clinical Executor in the event of my incapacity or death). Website enquiries are transmitted over a secure (HTTPS) connection, and the site is protected with up-to-date security measures.
10. Data Breach Procedure
I have a procedure in place to deal with any suspected personal data breach. If a breach occurs that is likely to result in a risk to your rights and freedoms, I will report it to the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. If a breach is likely to result in a high risk to you, I will also inform you directly and without undue delay, and explain the steps I am taking to address it.
11. Data Protection Impact Assessments (DPIAs)
Although I am a sole practitioner and do not carry out large-scale or high-risk processing, I keep my processing under review. Where I plan a change that is likely to result in a high risk to individuals (for example, introducing a new system that processes health data), I will carry out a Data Protection Impact Assessment beforehand to identify and reduce the risks.
12. Your Rights
Under UK data protection law, you have important rights regarding your personal information:
- See your records — ask to see what information I hold about you.
- Correct errors — ask me to put right anything that is inaccurate.
- Request deletion — in some circumstances, ask me to delete your information (I may need to keep certain records for legal or insurance reasons).
- Restrict processing — ask me to limit how I use your data in certain situations.
- Data portability — request your data in a format that can be transferred elsewhere.
- Object — object to certain types of processing.
If you would like to exercise any of these rights, simply email me at gdpr@counsellingwithlana.co.uk and I will respond within one month.
13. Making a Complaint
If you are unhappy about how I have handled your information, I would encourage you to raise it with me first so I can try to resolve it: complaints@counsellingwithlana.co.uk. See my Complaints page for the full process. Under the Data (Use and Access) Act 2025, you also have the right to complain directly to the Information Commissioner's Office (ICO) — website ico.org.uk, telephone 0303 123 1113.