Data Protection and GDPR Policy – Creative Nurture Play Therapy

Data Protection and GDPR Policy

For Creative Nurture Play Therapy

Last updated: 28th January 2026

1. Introduction

This Data Protection and GDPR Policy outlines how the Licensed Therapist (“the Therapist”) processes personal data while providing therapeutic services under licence from Creative Nurture Play Therapy. The Therapist is committed to protecting the privacy, confidentiality, and security of all personal data in accordance with the General Data Protection Regulation (GDPR) and relevant Irish data protection legislation.

The Therapist acts as an independent data controller for the personal data they collect and process in the provision of therapy services depending on the specific referral pathway and contractual agreement.

2. Purpose of Data Processing

The Therapist collects and processes personal data solely for the purposes of:

  • Delivering therapeutic assessment and intervention
  • Managing referrals
  • Maintaining accurate clinical records
  • Communicating with clients regarding appointments and treatment
  • Meeting legal, professional, and ethical obligations

Personal data will not be used for purposes beyond those clearly explained to clients, unless required by law.

3. Types of Personal Data Collected

The Therapist may collect the following categories of data:

3.1 Personal Identification Data
  • Name
  • Date of birth
  • Contact details (address, phone number, email)
  • Emergency contact information
3.2 Clinical and Special Category Data
  • Mental health history
  • Treatment notes and session records
  • Medical or educational reports
  • GP or referrer details
3.3 Administrative Data
  • Appointment history
  • Payment records (where applicable)
  • Correspondence with the client or referrer

Note: Special category data (health data) is subject to stricter protection standards.

4. Lawful Basis for Processing

The Therapist processes data under the following lawful bases:

  • Article 6(1)(b): Processing necessary for the performance of a contract (therapy service agreement)
  • Article 6(1)(c): Compliance with legal obligations
  • Article 6(1)(f): Legitimate interests in providing safe therapeutic care
  • Article 9(2)(h): Provision of health or social care treatment (special category data)

Consent may be sought for optional processing activities such as sharing information with third‑party professionals.

5. Sharing of Personal Data

Personal data may be shared only when necessary and with appropriate safeguards.

5.1 Other Third Parties

Data may be shared with:

  • GPs or other health professionals (with consent, unless risk dictates otherwise)
  • Emergency services, where necessary to protect life or safety
  • Legal or regulatory bodies when required by law

No personal data will be sold or shared for marketing purposes.

6. Data Storage and Security

The Therapist ensures that all data is stored securely using the following measures:

  • Encrypted digital storage for electronic records
  • Password‑protected devices compliant with current security standards
  • Locked filing systems for any paper records

The Therapist is responsible for ensuring that any digital platforms used for communication or record‑keeping meet GDPR standards.

7. Data Retention

Personal data is retained only for as long as necessary to fulfil legal and professional obligations.

  • Therapy records: kept for 7 years from the date of final contact
  • Records relating to minors: kept for 7 years after the client reaches age 18
  • Administrative records: retained for the minimum period necessary for auditing or insurance requirements

After the retention period expires, data will be securely destroyed.

8. Client Rights

Under GDPR, clients have the following rights regarding their personal data:

  • Right to access their personal data
  • Right to rectification of inaccurate data
  • Right to erasure (in certain circumstances)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right not to be subject to automated decision‑making (not used in therapy services)

The Therapist must respond to data rights requests within one month.

9. Data Breaches

The Therapist will take immediate action in the event of a suspected or confirmed data breach.

Steps include:

  1. Assessing the severity and scope of the breach
  2. Taking necessary measures to contain and minimise impact
  3. Reporting breaches to the Data Protection Commission (DPC) within 72 hours, where required
  4. Informing affected individuals if there is a high risk to their rights or freedoms
10. Confidentiality

The Therapist maintains strict confidentiality in accordance with professional ethical standards and GDPR. Information is disclosed only with consent or when legally or ethically required.

12. Contact Information

Clients may contact the Therapist directly regarding data protection matters.

For licensor‑related data protection issues:

Creative Nurture Play Therapy
Data Protection Contact: 164 Cherryfield Road, Walkinstown, Dublin 12

13. Policy Review

This policy is reviewed annually or sooner if:

  • Legislation changes,
  • Professional guidelines update, or
  • Data processing practices are altered.