Last reviewed on 29 September 2026.
NNWA publishes the name and qualifications of everyone who writes and checks its material. You can see the full teaching team on the faculty page.
The underlying idea is simpler than the legislation. You hold information people gave you for a purpose. Keep what that purpose needs, keep it somewhere only you can reach, keep it no longer than necessary, and be able to hand it back or delete it when asked.
What a practice actually holds
More than practitioners realise once they list it. Intake forms with medical history and medication. Consultation notes. Diet plans. Measurements over time. Photographs, often in a phone gallery alongside everything else. Payment records. Message threads on whatever app the client uses.
That last category is the one people forget. A year of consultation detail sitting in a messaging app is a record, whatever it feels like, and it is usually the least protected thing in the practice.
The four habits that do most of the work
One place, not five
Pick a single store for client files and use it consistently. Scattered records are the root cause of almost every failure here, because you cannot protect, produce or delete what you cannot find.
Access control that is real
A password on the device is the minimum. Anything holding health information should not be reachable by whoever picks up your phone. If a family member uses the same laptop, client records need their own account or their own encrypted folder.
Separate identity from detail where you can
For anything you use in study, supervision or a portfolio, strip the name and contact details and refer to the person by a reference. The clinical detail is what makes a case useful; the identity is what makes it a risk. There is more on this in building a portfolio with no clients yet.
A backup you have actually tested
A single copy is not a record, it is a hope. Whatever you use, restore one file from it once so you know the backup works. Practitioners discover otherwise at the worst possible moment.
How long to keep things
There is no single answer that fits every practice, and anybody offering a confident number without knowing your circumstances is guessing. What matters is that you have a stated period and that you apply it, rather than keeping everything forever by default.
Think about it in two parts. Clinical notes have a reason to persist: a client returning after two years benefits from you having their history. Payment records have their own retention logic driven by tax rather than by health. Marketing consent is different again and should lapse rather than persist.
Write down the period for each category, put a recurring reminder in your calendar to review, and actually delete when the review says so. A retention policy nobody executes is a document rather than a practice.
When somebody asks for their data, or for deletion
This will happen, and the first time is much easier if you have thought about it once.
Be able to produce what you hold about one person in a reasonable time. That is a direct consequence of the one place habit: a practitioner with organised files can do it in ten minutes, and a practitioner with records across four apps cannot do it at all.
For deletion, the practical complication is that some records cannot simply vanish, because tax and accounting obligations attach to payment history. The workable answer is usually to delete the clinical file and retain the minimum financial record, and to say that clearly to the client rather than either refusing or over promising.
Photographs deserve their own rule
Before and after images are the most sensitive thing most practices hold and the most casually stored. They should be in the client store rather than the camera roll, they should have been consented to separately, and any use in marketing needs its own explicit permission that names where they will appear.
The separate consent for this is covered in a client consent form under the DPDP Act.
If you use software
Most practitioners eventually adopt something. Two questions are worth asking any provider: where the data is held, and what happens to it if you stop paying. The second is the one people never ask and the one that strands records.
The one risk people underestimate
Not a breach by somebody malicious. A device that is lost, shared or repaired. A phone handed to a shop with a year of client photographs on it, or a laptop used by a relative who opens the wrong folder, accounts for far more real exposure in small practices than anything dramatic.
That is why device level protection matters more than sophisticated tooling. A passcode, a separate account for practice work, and photographs kept out of the general gallery deal with the ordinary failure modes, which are the ones that actually happen.
What to do if something does go wrong
Do not improvise. Write down what happened and when you noticed. Work out whose data was affected and what exactly was exposed. Take the obvious immediate steps, such as changing credentials or remotely wiping a device. Then take advice about whether anybody needs to be told, because notification obligations depend on circumstances a page cannot assess.
The instinct to say nothing and hope is the one that turns a contained problem into a serious one.
The honest summary
One place, access controlled, backed up and tested. Collect only what the work needs and say why. Write down a retention period for each category and act on it. Keep photographs out of the general gallery and consent to them separately. Be able to produce or delete one person's file on request. That is the whole of it, and it is an afternoon rather than a project.