Skip to content
GPTIGESTALT PSYCHOTHERAPY& TRAINING INSTITUTE

GPTI

GPTI data protection policy

The following is the policy of GPTI regarding handling of data. This policy applies to GPTI and all of its constituent committees, boards and subsidiary organisations.

Data protection policy

The principles

GPTI shall:

  1. Process personal data fairly and lawfully and, in particular, not process data unless these principles and the rules set out here are followed.
  2. Obtain personal data only for specified and lawful purposes, and not process data in any manner incompatible with that purpose or those purposes.
  3. Obtain personal data that is adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.
  4. Keep personal data accurate and up to date.
  5. Not keep personal data for longer than is necessary for their legitimate purposes.
  6. Process personal data in accordance with the rights of data subjects under the UK GDPR and the Data Protection Act 2018.
  7. Take appropriate technical and organisational measures against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
  8. Not transfer personal data to a country or territory outside the UK unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

What is data protection?

The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (the law) aim to protect individuals' fundamental rights and freedoms, notably privacy rights, in respect of personal data processing.

The law applies to paper and electronic records held in structured filing systems containing personal data, meaning data which relates to living individuals who can be identified from the data.

Data protection operates by giving individuals the right to gain access to their personal data. This is done by making a subject access request in which they are entitled to:

  • a description of their personal data
  • the purposes for which they are being processed
  • details of whom they are or may be disclosed to

Individuals can also prevent processing of their data in certain circumstances, opt-out of having their data used for direct marketing and in automated decision-making processes, apply to the courts for inaccurate data to be corrected and claim compensation for damage and distress caused as a result of any data protection breach.

Organisations that process personal data must pay a data protection fee to the Information Commissioner unless they are exempt; fee payers are included in a public register. The public register of fee payers is available on the Information Commissioner's website (ico.org.uk), from where you can search for GPTI's or any other organisation's entry.

Data Subjects are defined as being individuals about whom information is held

  • Psychotherapists
  • Trainees
  • Complainants, correspondents and enquirers
  • Advisors, consultants and other professional experts

Data Classes are the types of data which are being or which are to be processed:

  • Personal details
  • Education and Training details
  • Employment details
  • Offences (including alleged offences)
  • Criminal proceedings, outcomes and sentences
  • Financial details
  • Goods or services provided

Recipients

Recipients are individuals or organisations to whom GPTI as a data controller intends or may wish to disclose data. This list does not include any person to whom the GPTI as a data controller may be required by law to disclose in any particular case, for example if required by the police under a warrant.

This list should not be read as a list of those to whom data will be disclosed. GPTI is required to make clear all of the possible categories of recipient to which they might need or wish to disclose data, either in pursuit of their regulatory and public protection functions or in relation to permissions sought from and granted by a data subject.

  • Data subjects themselves
  • Current, past or future employers
  • Healthcare, social and welfare advisors or practitioners
  • Education, training and accrediting establishments and examining bodies
  • Employees and agents of GPTI
  • Suppliers, providers of goods and services
  • Persons making an enquiry or complaint
  • Police forces
  • Private investigators
  • Local government
  • Central government
  • Voluntary and charitable organisations
  • Ombudsmen and regulatory authorities

Purposes

The purposes to which GPTI as a Data Controller may put the data held are described here. This list does not represent the purposes to which all data held will always be put to.

GPTI holds a wide range of data types relating to diverse data subjects. At various times the data held in respect of these subjects may be used in relation to some or all of the following purposes.

Accounting and auditing. The provision of accounting and related services; the provision of an audit where such an audit is required by statute.

Administration of complaints processes. The administration of complaint and grievance processes of all kinds, including professional disciplinary processes, and complaints against officers, committees or other subsidiary bodies.

Administration of Membership records. The administration of membership records.

Education. The provision of education, training, accreditation and reaccreditation, supervision and/or research as a primary function or business activity.

Information and databank administration. Maintenance of information or databanks as a reference tool or general resource. This includes catalogues, lists, directories and bibliographic databases.

Licensing and registration. The administration of licensing or maintenance of official registers.

Processing for not-for-profit organisations. Establishing or maintaining membership of or support for a body or association which is not established or conducted for profit, or providing or administering activities for individuals who are either members of the body or association or have regular contact with it.

Realising the objectives of a voluntary body. The provision of goods and services in order to realise the objectives of the voluntary body.

Individual member consent

In order to be registered with the GPTI, Members must agree to GPTI holding the required details (along with any additional optional information requested that they elect to supply) and information on the database. If members do not agree to this they cannot be entered on the GPTI register. GPTI undertakes to use the information that Members provide in accordance with the UK GDPR, the Data Protection Act 2018 and GPTI policies. GPTI is a Data Controller and follows data protection guidelines in relation to all use and storage of data held by them. GPTI pays the data protection fee to the Information Commissioner's Office (ICO) and so appears on the ICO's public register of fee payers.

For GPTI to effectively perform its function it is necessary, at times, to send information to Members. By registering with GPTI, Members agree that GPTI may use their contact details to correspond with them.

Duration of data retention

As a data controller, GPTI must not hold data for longer than required. GPTI stores financial, academic, regulatory and CPD/re-accreditation records for up to 6 years and then deletes them by hand. Administrative records may if necessary be stored longer for historical purposes. Former members' details are deleted by hand after 6 years, or sooner if they ask by emailing admin@gpti.org.uk.

Special category and criminal offence data

The UK GDPR gives extra protection to special category data, which includes racial or ethnic origin, political opinions, religious beliefs, trade union membership, physical or mental health and sexual orientation, and to criminal offence data, which is information about criminal convictions and offences.

GPTI does not ask for special category data. It collects criminal offence data when someone applies. Criminal record details given in an application, and DBS certificates, are seen by GPTI's administrators and the committee that reviews the application. The administrator passes criminal record details to the Chair of the GPTI Ethics Committee.

Security

GPTI operates in a field in which confidentiality and record security is of paramount importance. GPTI's office is operated on the basis that all material entering the office be regarded as confidential until otherwise defined.

Subject access

Please email the administrator on admin@gpti.org.uk for a record of data held and this will be provided within one month.

Data breach

A personal data breach means a breach of security leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This means that a breach is more than just losing personal data.

The relevant supervisory authority will be notified of a breach where it is likely to result in a risk to the rights and freedoms of individuals. If unaddressed such a breach is likely to have a significant detrimental effect on individuals, for example, result in discrimination, damage to reputation, financial loss, loss of confidentiality or any other significant economic or social disadvantage.

What information must a breach notification contain?

The nature of the personal data breach including, where possible:

  • the categories and approximate number of individuals concerned; and
  • the categories and approximate number of personal data records concerned;
  • a description of the likely consequences of the personal data breach; and
  • a description of the measures taken, or proposed to be taken, to deal with the personal data breach and, where appropriate, of the measures taken to mitigate any possible adverse effects.

Review of this policy

This policy shall be reviewed annually by the Executive Council.

Data protection guidance for members

This document is for guidance purposes only and should be read in conjunction with the GPTI code of Ethics, the UK GDPR, the Data Protection Act 2018 and information from the Information Commissioner Office's (ICO) website (ico.org.uk).

Members should be aware and familiar with the GPTI code of Ethics and in particular Sect. 6.9 Responsibilities in law.

Members should familiarise themselves with the current Data Protection Legislation. The Information Commissioner Office (ICO) website (ico.org.uk) is a good source of useful and accessible information regarding Data Protection issues.

The Data Protection Legislation requires any practitioner who holds any data/records of individuals to register with the Information Commissioner by paying a data protection fee, unless they are exempt. This includes:

  • Data sheets (paper or electronic) of clients containing name, address etc.
  • Letters, written about or to clients, which include personal information e.g. name, address etc.
  • Tapes and transcripts of clients/supervisees.
  • Essays where clients are identifiable.
  • Any other records containing information about clients.

Registering is a straightforward process, which includes a small annual fee and can be done from the ICO website above.

Members should be aware that there have been recent changes to the Data Protection Legislation and now Members are required to:

  • Clearly inform their clients/supervisees what information they are storing, for what purpose, who this will be shared with and for how long the data will be held.
  • Keep records accurate and up to date.
  • Have processes in place to store any data securely. (see note 1. below)
  • Destroy securely any records no longer required (see note 2. below).
  • Have a mechanism in place where clients/supervisees can request access to their data, delete or correct their data and restrict their data.

Note 1: Members who store individual data digitally (including essays or taped recordings of clients) should consider using pseudonyms and/or encryption e.g. password protection to protect the data. In addition, if forwarding data to a third person e.g. for assessment or feedback, members should consider ways to encrypt/password protect files sent through email as attachments. Article 5(1)(f) of the UK GDPR states that data should be "Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures".

Note 2: The question of when therapy notes should be destroyed is currently debatable. Members should refer to any organisational requirements in which they work and/or their indemnity insurance policy which may stipulate a length of time for records to be retained. Otherwise, Members should consider the purpose of retaining client data and only keep records for as long as is deemed necessary. You may wish to discuss this with your supervisor.