A practical GDPR checklist for therapy practices
Health data is "special category" data under Art. 9 GDPR — the highest protection class. Here is the checklist we wish every practice ran against its current tooling.
The eight questions
1. Where exactly is client data stored, and is it inside the EU/EEA?
2. Do you have a signed Data Processing Agreement with every tool that touches client data — including your transcription or AI service?
3. Can you export everything you hold about one client, in a machine-readable format, within a month?
4. Can you erase a client completely — including recordings, messages, and backups — and prove it?
5. Who in your practice can read clinical notes? Can your front desk?
6. Is there an access log you could show a supervisory authority?
7. Are recordings and messages encrypted at rest, with keys held separately from the data?
8. Do clients consent to recording explicitly, per session, and is that consent stored?
Scoring honestly
Most practices we talk to answer "yes" to two or three. The uncomfortable ones are usually 4, 6, and 7 — erasure, audit, and encryption — because typical practice software treats them as enterprise features.
We built all eight into every Propela Therapy plan, because compliance that costs extra is compliance that does not happen.






