← Insights Say hi πŸ‘‹
Data protection Β· Mental-health clinics

PDPA for mental-health & counselling clinics in Singapore

The short answer

Yes β€” the PDPA applies to you in full, and the bar is at its highest. If you run a counselling, psychology or mental-health practice, you hold the most sensitive personal data there is β€” session notes, diagnoses, and deeply personal history. Like any clinic, you must appoint a Data Protection Officer (DPO). But the everyday habits matter far more here, because confidentiality isn't a compliance box β€” it's the therapeutic relationship itself. This guide covers what you hold, where the real gaps are, and how to keep client trust intact.

Of all the clinics I talk to, mental-health and counselling practices carry the heaviest data of all. A GP knows your blood pressure; you know a client's marriage, their trauma, their darkest week. That's a profound trust β€” and the PDPA sits underneath it. So this is worth ten quiet minutes. Let's keep it plain.

Yes, the PDPA applies β€” and you also need a DPO

The PDPA says every organisation must appoint at least one DPO and make that person's business contact available (a name or role plus an email, on your site or at reception). There's no size exemption β€” a solo private practice is covered the same as a group clinic. The DPO doesn't need a licence, and it can be you or a team member. But in a counselling setting, an in-name-only DPO is worse than useless: the whole point is that someone genuinely owns how this sensitive data is handled. (Our pillar guide on whether your clinic needs a DPO walks through the choice in full.)

Why your data is the most sensitive of all

Singapore's PDPA doesn't have a separate "sensitive data" category like the EU. Instead, the PDPC looks at how much harm a breach would cause β€” and expects a higher standard of protection where the harm is greater. For a mental-health practice, the potential harm is about as high as it gets. Think about what's in your files:

A leak here doesn't just breach a rule β€” it can damage someone's job, relationships or safety. That's exactly why the protection bar is set so high for you.

Where the everyday gaps actually are

In practice, breaches almost never come from some sophisticated hack. They come from ordinary habits that quietly go wrong. These are the ones I'd watch hardest in a counselling clinic:

Session notes and how they're stored

Notes are your crown jewels. Keep them in an access-controlled system, not loose in a shared drive or a folder anyone at the front desk can open. Limit who can read a client's notes to the treating therapist. Don't let notes drift onto personal laptops, USB sticks or into email drafts. If you're on paper, that's a locked cabinet and a clear-desk habit β€” not a stack by the printer.

Sharing with GPs, psychiatrists and insurers

This is the big one. A client agreeing to counselling is not the same as agreeing that you'll send their notes to their GP, their psychiatrist, or their insurer. Each disclosure needs a proper basis β€” usually the client's clear, specific consent for that exact sharing. When you do share, send the minimum needed (a summary letter, not the full note history), and record what went out and why. "The insurer asked" is not, on its own, a basis to hand over a therapy file.

Tele-counselling: recordings and consent

Online sessions are personal data exactly like in-person ones β€” so use a secure platform, not whatever's convenient. And be very careful with recordings: never record a session without the client's clear, specific consent. If you do record (for supervision or notes), say why, store it securely, restrict access, and delete it when it's no longer needed. A recording of a therapy session is one of the most sensitive files you could possibly hold.

WhatsApp and personal devices

Messaging clients from a personal phone, or snapping a photo of a note "just to remember", is a real exposure β€” that data now lives on a device with no controls, backed up who-knows-where. Decide how your clinic communicates (a proper channel, not a therapist's private number), and keep client content off personal devices.

Reception privacy β€” never say a name aloud

In a mental-health setting, even a client's name is sensitive. Don't call it out across a waiting room; don't leave the appointment book or a screen angled where the next person can read it. Small front-desk habits β€” a lowered voice, a turned monitor, a discreet check-in β€” protect people who are often already anxious about being seen there at all.

Marketing to clients β€” tread very carefully

Marketing to your client list is especially sensitive here. Someone consented to therapy, not to receiving newsletters or promotions β€” and an email that reveals they're a mental-health client (even to someone glancing at their inbox) can cause real harm. Treat marketing consent as a separate, explicit yes, keep it clearly opt-in, and when in doubt, don't. (More in our guide to consent and marketing for clinics.)

The three separate consents

The cleanest way to stay out of trouble is to remember these are three different things, and a yes to one is not a yes to the others:

How long to keep records

You're balancing two things. MOH-type record-keeping expectations point to keeping clinical records for a meaningful period, while the PDPA says don't keep personal data longer than you actually need it. The answer isn't "keep everything forever" or "bin it when the client leaves" β€” it's a written retention schedule that sets how long notes are kept and when they're securely destroyed, so the decision is made once, on principle, not case by case. If you're unsure of the exact clinical period for your setting, that's worth confirming with a qualified professional.

What to do β€” and what we can do for you

Appoint a DPO (you legally must), and be honest about whether that person truly has the knowledge and the time. Then tighten the everyday habits above β€” notes, sharing, tele-counselling, devices, reception, marketing β€” because that's where trust is actually won or lost. If nobody on your team has the hours or the specialist knowledge, outsource it: you get a named DPO, your data mapped, your policies and retention schedule written, your reception and admin staff trained, and a calm hand if a client ever complains or something goes wrong. For a small practice that's usually cheaper and safer than an incident β€” and in mental health, a client's trust is the entire relationship.

On cost: getting a counselling or psychology practice PDPA-ready is more affordable than most owners expect β€” and right now we're running a founding-clinic offer (a substantial first-year discount) to make it easy to start. Ask us about it.
This is general information to help clinic owners understand the PDPA β€” it isn't legal advice. For your practice's specific situation, check the PDPC's official guidance, the MOH healthcare guidelines, or a qualified professional.

Common questions

Yes. Under Singapore's PDPA every organisation must appoint at least one Data Protection Officer and make their business contact available. A counselling or psychology practice is no exception, and because your data is so sensitive, the DPO role matters more, not less.

Session notes are among the most sensitive records you hold, so treat them that way: keep them in an access-controlled system, limit who can open them to the treating therapist, avoid storing them on personal devices or in chat apps, and set a clear retention schedule. The PDPC expects a higher standard of protection where a breach could cause significant harm.

Only with a proper basis β€” usually the client's clear, specific consent for that disclosure. Consenting to counselling is not the same as agreeing to share notes with a GP, psychiatrist or insurer. Get consent for each purpose, share only the minimum needed, and record what was shared and why.

Yes. Online sessions are personal data just like in-person ones. Use a secure platform, and never record a session without the client's clear consent. If you do record, be specific about why, store it securely, and delete it when it is no longer needed.

Sources

  • Personal Data Protection Commission (PDPC) β€” pdpc.gov.sg (appointing a DPO; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
  • Ministry of Health (MOH) β€” record-keeping requirements & the Healthcare Services Act (HCSA)
Eugene
Eugene

I build websites and help Singapore businesses run them well. HeyAda is my Singapore web studio β€” design, SEO, and the practical side of running a business online, including the deeply sensitive data a counselling or mental-health practice collects. I write these guides in plain English, and I can be your clinic's outsourced DPO. Getting your practice PDPA-ready? Say hi.

Want this handled for your practice?

We help Singapore counselling and mental-health clinics get PDPA-ready and stand in as your outsourced DPO β€” mapped, documented, staff trained, done for you. Let's talk.