Personal data means any information relating to a person who could be directly or indirectly identified by that information. This definition provides for a wide range of ways that a person may be identified by their data. This includes their name, identification number, location data or an online identifier. Some information is considered to be ‘Special Category’ information and needs more protection because of its sensitivity.
The University of Westminster is the Data Controller for the personal information held in relation to counselling and mental health advice services. This privacy notice is in addition to the University’s privacy notice.
How we collect information
We collect information about you when:
- You register for participation in our confidential individual counselling/mental health services.
- We send you further communications and appointments.
- We record notes during any counselling sessions.
Confidentiality
Information provided will only be shared with internal colleagues related to your service to the University in that role.
What information we collect and hold
Personal information collected includes (if you are a student with the University of Westminster, some information will be available on our Student Records System):
- Name
- Contact details, eg phone, email address
- Gender
- Year of study
- Reason/s for access to service
- Presenting issues provided by you on your registration form, eg home life, lifestyle, vulnerabilities, health conditions
Special category information collected includes:
- Ethnicity
- Medical information (mental and physical health records)
How the personal information we hold is used
Your personal information will be used to:
- Create an account and case files on our system.
- Make appointments for the counselling service.
- Communicate with you regarding your appointments.
- Liaise with internal colleagues to discuss the best possible support for you (with your consent).
- Liaise with external link professionals regarding your welfare if there is cause for concern (for student clients of participating institutions only).
- Liaise with, or write to, a third party, for example a general practitioner (GP), counsellor/psychotherapist, with a view to making a referral (with your consent).
- Contact and inform the appropriate authority where you or a third party may be thought to be in danger of harm. or where a member of staff would be liable to civil or criminal court proceedings.
Our reason for processing your personal data
We process your personal data for the following reason:
- You have given your consent.
- For the performance of a task in the public interest.
- For a vital interest: the processing is necessary to protect someone’s life.
- Monitoring and evaluation purposes within the service.
Special category data is processed for the following reason:
- You have given your explicit consent
- Health or social care
- For a vital interest
Organisations we may share your information with in relation to this processing
We may share your information with the following organisations:
- The University’s Disability, Accommodation teams and other internal advisers
- External delivery providers
How we protect your information
The personal information we hold will be processed with appropriate security and used in accordance with the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR). Your information may be held outside of the UK. Where this is the case, we ensure that appropriate measures are in place to protect your data.
Our data retention policy
We will retain this information only for as long as necessary. We may aggregate and anonymise data for wider internal management reporting or research purposes. Personal data will be kept in line with the university’s retention schedule and guidance from the British Association of Counselling and Psychotherapy. For further information, please see our Counselling FAQs.
Disclosure of information to third parties
Personal information will not be disclosed to external organisations other than those acting on the instructions of the University. Where this is the case, a written contract will be put in place between the University and the third party setting out appropriate data protection obligations.
We use several commercial companies and partners to either store personal information or to manage it on our behalf. Where we have these arrangements, we ensure that there is a contract or data sharing agreement is in place to ensure that the requirements of data protection legislation are met.
Sometimes we have a legal duty to disclose personal information. We may share your information:
- for the detection and prevention of crime and fraudulent activity
- if there are serious risks to the public, our staff or to other professionals
- to protect a child
- to protect adults who are thought to be a risk to themselves or others
Your rights
The law gives you several rights to control which personal information is used by us and how it is used by us.
How can you access the information we hold about you?
You are legally entitled to ask to see any records we hold about you. If you wish to request access to the personal information we hold about you, please contact the Information Compliance Team through the University's subject access procedure.
How can you request correction of inaccurate information?
Whilst we try to ensure that any personal data we hold about you is correct, there may be situations where the information we hold is no longer accurate. If this is the case, please contact the department holding the information so that any errors can be investigated and corrected. If you don’t know which department to contact, please contact the Information Compliance Team.
You can ask to delete information (right to be forgotten)
In some circumstances you can ask for your personal information to be deleted, for example, in instances where:
- Your personal information is no longer needed for the reason why it was collected in the first place.
- You have removed your consent for us to use your information (where there is no other legal reason for us to use it).
- Deleting the information is a legal requirement.
Please note that there are situations where the right to be forgotten does not apply. Please contact the Information Compliance Team to make a request.
You can ask to limit what we use your data for
In some circumstances, you have the right to restrict what processing an organisation carries out or ask that they stop processing your personal data. When processing is restricted, the organisation may continue to store your data but not process it further. Please contact the Information Compliance Team to make a request.
You can ask to have your information moved to another provider (data portability)
You have the right to ask for your personal information to be given back to you or another service provider of your choice in a commonly used format. Please contact the Information Compliance Team to make a request.
You can object
You have the right to object to processing of your personal data at any time. This means that you can stop or prevent an organisation from using your data. However, it only applies in certain circumstances. Please contact the Information Compliance Team to make a request.
Automated decision making and profiling
You have a right to request that decisions based solely on automated processing, including profiling, which may produce a legal effect or affect them significantly, to have some form of human input so they are not automatically generated by a computer. Please contact the Information Compliance Team to make a request.
Right to complain
You have the right to complain about how we use your personal data. In the first instance, please contact the Information Compliance Team.
How to contact us?
If you would like further information or if you have any concerns about how we handle your data, these can be raised with our Information Compliance Team by emailing [email protected] or writing to:
Information Compliance Team
University of Westminster
32–38 Wells Street
London
W1T 3UW
Independent advice
Independent advice can be sought from the UK regulator for data protection, the Information Commissioner’s Office (ICO).
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
T: 0303 123 1113 (local rate) or 01625 545 745 if you prefer to use a national rate number.
Alternatively, visit the ICO website or email [email protected].
This privacy notice and updates
If you have any queries about this privacy notice, or about how we hold and use your data, please contact the Information Compliance Team.
We will review and update this privacy notice to reflect changes in our processes and procedures. When such changes occur, we will revise the 'last updated' date on this notice. We encourage you to periodically review this notice to remain informed.
Last reviewed and updated June 2025