Is your website legally compliant?
A guide for UK therapists and health & wellbeing businesses
Written by Ingrid Fernandez, legal consultant
When you have been running a therapy or health and wellbeing business for several years, a website redesign is a good opportunity to review the legal side of your website and booking process, and make sure they still reflect how your business operates today.
Clients are increasingly aware of how their personal data is collected and used, so being clear about what you collect and how you handle it is important both legally and for building trust and credibility.
Most established business owners already have the basics in place. It is often the detail that needs revisiting, particularly where you handle health information, which receives additional protection under UK data protection law, or where your business, services or booking processes have changed.
This guide covers the key areas to review, with a practical checklist at the end to help you make sure everything is up to date on your new website.
Note: This article is written for UK-based therapists and health & wellbeing businesses working under UK data protection law (UK GDPR and the Data Protection Act 2018). If your clients are also based in the UK, this is the legal framework you will generally be working within. If you work internationally, or see clients based in the EU or elsewhere, you may have additional obligations under local data protection laws too, so it is worth getting advice from someone familiar with those jurisdictions.
1. Privacy and cookies
Your privacy policy
You may already have a privacy policy in place and it is worth checking that it still reflects how your business operates today. At a minimum, it needs to explain:
who you are. This means your legal identity, not just your brand name. So, your own name if you are a sole trader, or your registered company name, company number and registered address if you are a limited company;
what personal information you collect and how you collect it;
why you collect it and the legal basis you have for processing it;
who you share it with (if anyone), including any apps or software you use to store or manage client information;
how long you keep the personal information you hold about someone; and
a summary of the rights people have over their own data.
This covers the general requirements that apply to any business handling personal information, health-related or not. However, for therapy and health businesses, a privacy policy needs to properly reflect the fact that you collect health information, which may include details about symptoms, diagnoses, medication, mental health history or anything similar that a client shares through an intake form.
Personal data about someone's health is treated as “special category data” under UK data protection law. It gets extra protection because it's more sensitive, which means you need more than the usual justification to collect and use it. The simplest and safest route is asking for clear, explicit consent to process health information as part of your intake process.
Another important point for your privacy policy is how long you hold onto clients’ personal information. Data protection law says, broadly, that you shouldn't keep personal information for longer than you need it. In practice, “how long you need it” is often shaped by your professional indemnity insurer or professional body, which may recommend keeping client records for a set period after your last contact, particularly in case a claim is made against you. That period varies by profession and by insurer, so it is worth checking.
Cookie notice and consent
Cookies are small files placed on a visitor's device when they use your website. Different types of cookies serve different purposes and the distinction matters because they are treated differently under the law.
Strictly necessary cookies keep the site functioning; things like remembering someone is logged in. These do not need consent.
Functional cookies remember preferences, like a chosen language.
Analytics cookies track how visitors use your site, so you can see what is working.
Marketing or advertising cookies track visitors across sites to serve targeted ads. Anything outside the strictly necessary category needs the visitor's consent before it is set.
Your cookie policy should explain what cookies your website uses, what each one does, how long it stays on a visitor's device and who it belongs to (you or a third party like Google or Meta). It needs to be easy to find and it is good practice to provide a link to it from your cookie banner, so visitors can access more detailed information before making their choices. It is also a good idea to link to the policy from your website footer.
2. Website terms
Your website terms do a different job to the other legal information on your site. They set out the rules for using your website and its content, including your words, photos and resources, and can help protect your intellectual property. Your website terms can be particularly useful if your site has a blog or allows any kind of user-generated content, such as comments, since they can set out what people are allowed to share and what you can do if they share something they shouldn't.
Disclaimers
If your website includes general health, nutrition or wellbeing content, a disclaimer making clear that it is not a substitute for individual medical advice is standard practice. It can help make clear the purpose and limitations of the information you provide, while managing visitors' expectations.
Advertising standards
Most professional bodies have their own advertising and website standards covering things like how you can describe your qualifications, what claims you can make about outcomes and how, if at all, you should present testimonials. These sit alongside your legal obligations. It is worth checking your obligations with your regulatory or supervisory body and making sure your website content reflects them.
3. Booking terms
If someone can book and pay for a session through your website, you are entering into what the law calls a “distance contract”; namely a contract made without you and the client meeting first, and that brings the Consumer Contracts Regulations into play. These Regulations give consumers certain information and cancellation rights. There are some narrow exceptions (for things like specific-date leisure bookings), but for most practitioner bookings, the Regulations apply.
Two things follow from this. First, certain information has to be clearly available at the point of booking and before someone pays. This includes:
who you are (your own name if you are a sole trader or your registered company name, number and address if you are a limited company),
what the session actually involves,
the price, and
their right to change their mind, which is the next point.
Second, where the cancellation rights apply, clients generally have a 14-day “cooling-off” period. This is the right to cancel the contract without giving a reason within 14 days of booking, subject to the rules that apply where a service has already started. The 14-day period can be easy to overlook, particularly where a session has a fixed date and time. However, booking a specific appointment slot does not necessarily remove this right.
That does not mean you have to let a client cancel for free right up until their session starts or refund something you have already delivered. The law has a built-in solution in that you can ask the client, at the point of booking, to actively agree to two things:
that the session can go ahead straight away (rather than waiting out the 14 days first), and
that they acknowledge they will lose the right to cancel once the service has been fully performed.
This must be a genuine, active step at booking, through a checkbox for example, with the client expressly requesting that the service begins during the cancellation period and acknowledging the relevant consequences.
This is separate from your own cancellation policy (say, "48 hours' notice or the session is forfeit"). You are entitled to have a policy like that, but it works alongside the client's legal cancellation rights, rather than replacing them. A no-refund policy on its own does not remove statutory cancellation rights. Your booking process needs to deal separately with those rights and, where relevant, obtain the client's express request for the service to begin during the cancellation period.
Confidentiality
Confidentiality is a fundamental part of working with clients in a therapeutic or health setting, and is both a professional expectation and, in most circumstances, a legal duty. UK law recognises what's called a "duty of confidence", built up over decades through court decisions, which says that when someone shares information with you in circumstances where it's clearly meant to stay private, you are not free to pass it on without a good reason.
Data protection law adds another layer: UK GDPR requires organisations to process personal data securely and to take appropriate measures to protect it from unauthorised access, loss or disclosure.
So where do professional bodies such as BACP, UKCP, HCPC and similar bodies fit in? They don't create this duty, as it already exists. What they do is set out how you are expected to handle it in practice and what happens professionally if you don't, providing guidance on when confidentiality can or should be broken and a disciplinary process that sits alongside (not instead of) the general law.
This means telling a prospective client about the limits to confidentiality before they start working with you. If there are circumstances where you would need to break confidentiality, such as safeguarding concerns or a risk of serious harm to your client or someone else, that needs to be clear upfront and included in your booking terms.
Legal checklist for your website
If you are planning a website redesign, it is worth checking that the following are up to date before the project begins:
* Booking terms are usually managed within your booking system rather than as part of your website, so make sure these are also up to date and consistent with your current booking process.
About Ingrid Fernandez
Ingrid Fernandez is a qualified lawyer and the founder of HerLegals. She helps small business owners and service-based practitioners get their contracts, privacy policies and client-facing documents properly sorted.
Learn more at herlegals.com

