Of all the clinics I talk to, mental-health and counselling practices carry the heaviest data of all. A GP knows your blood pressure; you know a client's marriage, their trauma, their darkest week. That's a profound trust β and the PDPA sits underneath it. So this is worth ten quiet minutes. Let's keep it plain.
Yes, the PDPA applies β and you also need a DPO
The PDPA says every organisation must appoint at least one DPO and make that person's business contact available (a name or role plus an email, on your site or at reception). There's no size exemption β a solo private practice is covered the same as a group clinic. The DPO doesn't need a licence, and it can be you or a team member. But in a counselling setting, an in-name-only DPO is worse than useless: the whole point is that someone genuinely owns how this sensitive data is handled. (Our pillar guide on whether your clinic needs a DPO walks through the choice in full.)
Why your data is the most sensitive of all
Singapore's PDPA doesn't have a separate "sensitive data" category like the EU. Instead, the PDPC looks at how much harm a breach would cause β and expects a higher standard of protection where the harm is greater. For a mental-health practice, the potential harm is about as high as it gets. Think about what's in your files:
- βSession and progress notes β the running record of what a client shared in the room.
- βDiagnoses and assessments β mental-health conditions, risk assessments, medication history.
- βDeeply personal history β relationships, abuse, self-harm, family and financial detail.
- βThe simple fact that someone is a client at all β for many people, that alone is something they'd never want known.
A leak here doesn't just breach a rule β it can damage someone's job, relationships or safety. That's exactly why the protection bar is set so high for you.
Where the everyday gaps actually are
In practice, breaches almost never come from some sophisticated hack. They come from ordinary habits that quietly go wrong. These are the ones I'd watch hardest in a counselling clinic:
Session notes and how they're stored
Notes are your crown jewels. Keep them in an access-controlled system, not loose in a shared drive or a folder anyone at the front desk can open. Limit who can read a client's notes to the treating therapist. Don't let notes drift onto personal laptops, USB sticks or into email drafts. If you're on paper, that's a locked cabinet and a clear-desk habit β not a stack by the printer.
Sharing with GPs, psychiatrists and insurers
This is the big one. A client agreeing to counselling is not the same as agreeing that you'll send their notes to their GP, their psychiatrist, or their insurer. Each disclosure needs a proper basis β usually the client's clear, specific consent for that exact sharing. When you do share, send the minimum needed (a summary letter, not the full note history), and record what went out and why. "The insurer asked" is not, on its own, a basis to hand over a therapy file.
Tele-counselling: recordings and consent
Online sessions are personal data exactly like in-person ones β so use a secure platform, not whatever's convenient. And be very careful with recordings: never record a session without the client's clear, specific consent. If you do record (for supervision or notes), say why, store it securely, restrict access, and delete it when it's no longer needed. A recording of a therapy session is one of the most sensitive files you could possibly hold.
WhatsApp and personal devices
Messaging clients from a personal phone, or snapping a photo of a note "just to remember", is a real exposure β that data now lives on a device with no controls, backed up who-knows-where. Decide how your clinic communicates (a proper channel, not a therapist's private number), and keep client content off personal devices.
Reception privacy β never say a name aloud
In a mental-health setting, even a client's name is sensitive. Don't call it out across a waiting room; don't leave the appointment book or a screen angled where the next person can read it. Small front-desk habits β a lowered voice, a turned monitor, a discreet check-in β protect people who are often already anxious about being seen there at all.
Marketing to clients β tread very carefully
Marketing to your client list is especially sensitive here. Someone consented to therapy, not to receiving newsletters or promotions β and an email that reveals they're a mental-health client (even to someone glancing at their inbox) can cause real harm. Treat marketing consent as a separate, explicit yes, keep it clearly opt-in, and when in doubt, don't. (More in our guide to consent and marketing for clinics.)
The three separate consents
The cleanest way to stay out of trouble is to remember these are three different things, and a yes to one is not a yes to the others:
- 1Consent to treatment β the client agreeing to counselling and to you keeping the notes that care requires.
- 2Consent to share β a specific, separate yes before anything goes to a GP, psychiatrist, insurer or third party.
- 3Consent to marketing β an explicit, opt-in yes before any newsletter or promotion. Never bundled into the intake form.
How long to keep records
You're balancing two things. MOH-type record-keeping expectations point to keeping clinical records for a meaningful period, while the PDPA says don't keep personal data longer than you actually need it. The answer isn't "keep everything forever" or "bin it when the client leaves" β it's a written retention schedule that sets how long notes are kept and when they're securely destroyed, so the decision is made once, on principle, not case by case. If you're unsure of the exact clinical period for your setting, that's worth confirming with a qualified professional.
What to do β and what we can do for you
Appoint a DPO (you legally must), and be honest about whether that person truly has the knowledge and the time. Then tighten the everyday habits above β notes, sharing, tele-counselling, devices, reception, marketing β because that's where trust is actually won or lost. If nobody on your team has the hours or the specialist knowledge, outsource it: you get a named DPO, your data mapped, your policies and retention schedule written, your reception and admin staff trained, and a calm hand if a client ever complains or something goes wrong. For a small practice that's usually cheaper and safer than an incident β and in mental health, a client's trust is the entire relationship.
Common questions
Yes. Under Singapore's PDPA every organisation must appoint at least one Data Protection Officer and make their business contact available. A counselling or psychology practice is no exception, and because your data is so sensitive, the DPO role matters more, not less.
Session notes are among the most sensitive records you hold, so treat them that way: keep them in an access-controlled system, limit who can open them to the treating therapist, avoid storing them on personal devices or in chat apps, and set a clear retention schedule. The PDPC expects a higher standard of protection where a breach could cause significant harm.
Only with a proper basis β usually the client's clear, specific consent for that disclosure. Consenting to counselling is not the same as agreeing to share notes with a GP, psychiatrist or insurer. Get consent for each purpose, share only the minimum needed, and record what was shared and why.
Yes. Online sessions are personal data just like in-person ones. Use a secure platform, and never record a session without the client's clear consent. If you do record, be specific about why, store it securely, and delete it when it is no longer needed.
Sources
- Personal Data Protection Commission (PDPC) β pdpc.gov.sg (appointing a DPO; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) β record-keeping requirements & the Healthcare Services Act (HCSA)
Want this handled for your practice?
We help Singapore counselling and mental-health clinics get PDPA-ready and stand in as your outsourced DPO β mapped, documented, staff trained, done for you. Let's talk.