A GDPR Checklist for Therapist and Coach Websites
Published 20 August 2026 · 6 min read
This isn't legal advice, and if you're unsure about your specific obligations it's worth a proper conversation with a solicitor or your professional body. But most therapist and coach websites touch the same handful of GDPR-relevant areas, and it's worth knowing what they are before you build or update a site.
1. Your enquiry and booking forms
Any form that collects a name, email, or phone number is processing personal data, which means UK GDPR applies from the moment someone hits submit. In practice, that means:
- Being clear about what you'll use the information for (arranging a session, not marketing they haven't agreed to).
- Having a privacy policy that explains this, linked near the form itself.
- Only collecting what you actually need: a "tell us anything else" field is fine, a required field asking for sensitive health information up front generally isn't.
2. Client testimonials
This is the one that catches people out. A testimonial that names a specific issue someone came to you for (bereavement, an eating disorder, addiction) can count as special category data under UK GDPR, because it can reveal something about their health. That means you generally need explicit, informed consent, not just "they said it was fine to use it." Many professional bodies, including BACP and NCPS, also have their own additional guidance here worth checking alongside the legal requirement, and the ICF has its own coaching-specific ethical guidelines that touch on the same territory.
3. Cookies and analytics
If your site uses anything beyond strictly necessary cookies (most analytics tools, embedded booking widgets, or chat plugins), UK PECR rules require a cookie banner that lets visitors genuinely opt in or out before those cookies load, not just a notice they can dismiss. "Implied consent" from continuing to browse is no longer considered sufficient by the ICO.
4. Where the data actually lives
Where your form submissions, hosting, and any booking data are stored matters. UK/EU-based providers with clear data processing terms are the simplest way to stay compliant without extra safeguards. If a tool you're using stores data outside the UK/EEA, check what safeguards they have in place, most reputable providers publish this clearly.
5. A basic privacy policy
Every site collecting any personal data needs one, covering what's collected, why, how long it's kept, and how someone can ask you to delete it. It doesn't need to be long, but it does need to actually reflect what your site does, not a generic template copied from elsewhere.
The practical takeaway
None of this is about ticking boxes for its own sake, it's the same care you'd bring to client confidentiality in the room, applied to the version of your practice that lives online. If your current site is missing any of the above, it's a quick fix, not a rebuild.
Every ROOTED build includes a privacy policy and cookie handling set up correctly from day one. If you'd like a second pair of eyes on your existing site, get in touch.
Book a Call