Most therapists in private practice know they're supposed to protect patient data. Fewer know exactly what that means under the GDPR — or which tools they're currently using that put them at risk.

This article explains the key concepts and what a compliant independent practice looks like in practice.

Why therapy data is different: Article 9

The GDPR treats health data differently from ordinary personal data. Article 9 of Regulation (EU) 2016/679 designates health information as a special category — the highest protection level under European law.

This covers more than just medical diagnoses. It includes any data that reveals a person's mental or physical health condition. The fact that someone is seeing a therapist, when they attend sessions, and any notes about those sessions — all of this is Article 9 data.

Special category data requires:

Tools that are not compliant

The most common GDPR risks in independent therapy practices come from using consumer tools for clinical purposes. These tools are not designed to handle Article 9 data and do not meet the technical or contractual requirements:

Not appropriate for patient health data

  • Notes app (phone or computer) — no encryption at rest, no access controls, no audit trail
  • Google Docs or Excel — consumer account, no Data Processing Agreement for health data
  • Personal email — no end-to-end encryption, no appropriate DPA
  • WhatsApp — Meta infrastructure, personal account, messages not GDPR-compliant for Article 9
  • Google Calendar — consumer privacy policy, not designed for health data processing

Using these tools doesn't automatically mean you'll be sanctioned. But if a patient makes a data subject request, if there is a data breach, or if a regulator investigates, "I was using my personal Google account" is not a compliant answer.

What a compliant independent practice looks like

Compliance is not about paperwork for its own sake. It's about having systems that actually protect your patients' information and that you can explain clearly if asked.

A basic compliance checklist for an independent therapist:

Why Frankfurt matters

GDPR applies to data processed within the EU and data processed by EU-based entities. When patient data is stored on servers outside the EU — even with a provider that claims GDPR compliance — you enter a more complex legal territory involving cross-border transfer mechanisms and adequacy decisions.

The simplest approach for an independent therapist: use a tool that stores data in the EU, with a clear contractual commitment. Servers in Frankfurt, Germany, are within EU jurisdiction. A data breach, a subject rights request, a regulatory inquiry — all of these are handled under clear EU law.

APONIA.ro stores all patient data in Frankfurt, Germany, with AES-256 encryption. A Data Processing Agreement is available for every account. Article 9 compliance is built into the infrastructure, not added on.

The practical question

Ask yourself: if a patient asked you today where their data is stored, who has access to it, how it's encrypted, and what you would do in case of a breach — could you answer clearly?

If not, that's the gap. Filling it doesn't require a lawyer or an IT department. It requires choosing tools designed for the purpose, and having a few documents that explain your practices clearly to patients.

Sources