The new BACP ethical framework: answers to the questions therapists are actually asking

Aug 4 / Joel Bild

Confident Therapist Hub · Practice management · 16 min read · The practical long read

If you would prefer the shorter take focused on the three decisions you will need to make this year, the brief piece is here.

This piece works through the new BACP Ethical Framework as a series of questions UK practitioners are actually asking. Find the ones that apply to you and skip the ones that do not.

An important distinction

There are three different kinds of obligation here.

Legal duties

Apply to every UK therapist regardless of body membership. UK GDPR, the ICO data protection fee where applicable, HMRC tax obligations, safeguarding duties and the Equality Act.

Professional body requirements

Apply to members of that body specifically. For BACP members, the Ethical Framework is one of these.

Ethical good practice

What a thoughtful practitioner would do regardless of which categories apply to them.

The Ethical Framework for the Counselling Professions 2026 was published by BACP on 4 August 2026 and takes effect on 3 November 2026. The work involved is not hard. It just needs to be done properly.

The questions

Each of the ten questions below can be expanded. Open the ones that apply to your practice.

"I'm not a BACP member. Does any of this apply to me?"

Probably yes, and the reason involves untangling the three categories above.

Therapy is not a regulated profession in the UK. Anyone can call themselves a therapist or counsellor without joining a professional body. So strictly speaking, the BACP framework binds only its members.

But "I am not bound by the BACP framework" is a different statement from "none of this applies to me."

A surprising amount of what the framework covers is not BACP-specific at all. It reflects legal duties that apply to every therapist holding client data.

In most private practice contexts, you are a data controller because you decide why and how client information is collected, stored and used.

Many private practitioners will also need to pay the ICO data protection fee unless exempt. Worth checking the ICO's self-assessment rather than assuming either way.

HMRC tax obligations, including Making Tax Digital where your qualifying self-employment and/or property income is above the relevant threshold, are separate legal duties. None of these are about which professional body you have joined.

And then there is the question of what counts as ethical practice. The new framework does not create these ideas from nothing. It formalises them. The clinical will, the privacy notice, and the idea that you should be able to evidence ethical reasoning have all been in professional practice for years.

A therapist outside the bodies who decides they need not bother with a clinical will because they are not technically required to have one is making a choice their clients have not agreed to. A therapist who dies without one may leave their clients without records access or proper notification, regardless of which professional letters they hold.

The practical position is this. Legal duties bind everyone. Professional body commitments bind members of that body. Ethical good practice is broadly worth adopting regardless. The new framework is useful reading whichever of those categories you sit in.

The rest of this article assumes you are not necessarily a BACP member. Where something is specifically a BACP requirement rather than a legal duty or good practice, it is flagged as such.

"I use AI to help with notes. What do I actually need to do?"

This is the question with the most immediate practical work attached to it, and the one most likely to require something you are not currently doing.

Section 2.1(e) of the new framework requires members to assess the risk of any AI tool, digital tool or online platform before using them, and to be able to demonstrate five specific things:

  • competence to use the tool or platform
  • understanding of how data are handled and stored, and of any risks to confidentiality, with those risks mitigated as far as possible
  • honesty and transparency with clients about the use of AI, digital tools or online platforms, and the benefits and risks involved
  • informed consent from clients before inputting any of their personal data into AI or digital tools
  • that decision-making has not been deferred or outsourced to AI tools, with the practitioner remaining responsible for critically evaluating AI output and any subsequent decisions.

The last two of these are new since the draft, and they are the most consequential for therapists currently using AI in their practice.

In terms of obligation, this is primarily a professional body requirement for BACP members, with real legal overlap. UK GDPR's accountability principle means you should be able to evidence how you have assessed and managed risks when processing sensitive client data. So any therapist using AI tools is on stronger legal ground if they have done this work. Body membership or not.

The informed consent requirement is now explicit

Under the draft framework, therapists were asked to be "honest and transparent" about AI use. In practice, many read this as meaning a line in a privacy notice was sufficient.

The final framework goes further. Clause 2.1(e)(iv) requires informed consent from clients before their personal data is entered into an AI tool, digital tool or online platform.

Informed consent, in the sense used across UK data-protection guidance, means the client understands what they are agreeing to and can withdraw that agreement at any time. It is not something a client can be assumed to have provided by continuing therapy after reading a privacy notice.

For a therapist currently using an AI note-taking tool, this means, in practice:

  • a specific conversation with each client about the tool being used
  • clear information about what data goes into the tool, where it is stored, and who else processes it
  • informed agreement that is clearly recorded and could be evidenced later
  • a genuine alternative. A client who declines AI processing needs to know what will happen instead, and it cannot be that they lose access to therapy.

This is a meaningful practical shift. A checkbox in the tool's own terms is unlikely to demonstrate the informed consent the framework expects. A general statement in a privacy notice is also unlikely to be enough on its own. Existing clients where AI has been used without this level of informed consent may need a fresh conversation.

CTH RESOURCE
Where Do You Stand on AI?

A free reflection lesson that walks through this decision. Sit with it, and come to a considered position before your next client conversation.

Try the free lesson →

Decision-making cannot be outsourced

Clause 2.1(e)(v) is the other new requirement. It says that decision-making has not been deferred or outsourced to AI tools, and that the practitioner remains responsible for critically evaluating any output.

This is directed less at note-taking tools where the therapist retains the interpretive and clinical work, and more at any AI-assisted tools that suggest interpretations, formulations, risk assessments, or treatment approaches. If any of these are part of your workflow, the framework is clear that the responsibility for the output remains yours. The tool cannot be treated as a professional voice in the room.

The risk assessment work

In many cases, therapists will want to keep a short written assessment for each AI tool, digital tool or online platform they use, on file. A page is usually enough. It might cover:

  • what client-related data passes through the tool
  • where it is stored
  • who else processes it
  • what the residual risks are
  • what you have told clients about it
  • what informed consent process you use, and how you record it.

The chain of sub-processors can be longer than it looks. A sub-processor is a third party the tool passes data to, and those third parties often pass data to yet more services. Worth checking rather than assuming.

One more thing worth thinking about

Therapy works partly because nothing else is in the room. The attention, the held silence, the trust that what is said here is held here. These are conditions of the work.

A recording device introduces something else into the therapeutic space. An AI listener adds another layer. Even when the client agrees, the therapist who knows their device is listening may practise differently because they know something is listening.

Asking a client whether you may record or process a session through an AI tool creates a relational dynamic that warrants careful thought, as I'm sure most training would have covered.

Your client is not in a neutral position when you ask them a favour. They came to you for help. Many clients want to be a good client, to be easy, to not make things difficult. So when you ask, "would it be okay if I recorded our sessions through an AI tool?", a client may say yes even when part of them would rather not. They may not feel able to tell you no, or may not even notice they wanted to.

The framework now requires informed consent before client data goes into an AI tool. That means a formal conversation, whether or not you were having it before.

This is not a reason never to use AI tools. It is a reason to be honest with yourself about two things. First: the time saved has to be worth the possible cost to your relationship with the client. Second: your client's yes has to be a real yes, not a yes because they wanted to please you, or because they didn't know they could say no.

If you cannot be confident of both, you may not have the consent the framework now expects, whatever the client actually said.

The framework does not require you to avoid AI. It expects you to be able to defend your use of it. With a specific consent process, a documented risk assessment, and retained clinical responsibility.

Whether your answer is "yes, the trade-off works for my practice" or "no, the work is better protected with the device in my bag", both can be defended. What is harder to defend is defaulting into a tool because it saves time, without being able to explain the ethical and data-protection reasoning behind that choice.

CTH RESOURCE
Privacy notice and DUAA complaints template

A CTH-drafted privacy notice template that includes the AI tool disclosure and DUAA complaints process the framework now expects. Adapt to your practice.

Subscribe to access the template →
"Do I need a clinical will, and if I have one, is it good enough?"

The clinical will is the item that has probably moved the most.

In the 2018 framework it appeared at point 42, in non-mandatory language. In the new framework it sits at section 4.5(e), under the header "Manage breaks, endings in ways that minimise the impact for clients and service users." Its placement is deliberate. The clinical will is now framed as part of the broader work of managing endings well, not as a standalone administrative task.

Ensure we have a clinical will in place and have appointed an executor who, bound by confidentiality, can communicate with clients and service users if we are unable to contact them ourselves, or if we die.

Note that "unable to contact" is slightly broader than the draft's "too ill to contact". It now covers other forms of incapacity as well.

The main category here is professional body requirement for BACP members from 3 November 2026. BABCP has required clinical wills for accredited members since September 2023.

It is not a UK legal duty. But of all the items in this article, it is one where "not legally required" is a particularly weak defence.

The harm of dying without a clinical will is to your clients, not to you. That harm can be significant, and repeated across every active client on your list at the time.

A working clinical will typically needs four things:

  • a named executor who has agreed in writing to the role, usually a trusted colleague or supervisor
  • a confidentiality agreement with that person
  • secure arrangements for accessing your client list and records
  • clear instructions on how clients should be contacted.

If you do not have one, the work is usually a few hours. BACP, the BPC, and several supervision networks publish templates that can help you get started. You will still need to tailor them to your practice.

The most important practical step is the conversation with whoever you are asking to be your executor. They need to actually agree, understand what they are taking on, and know how to find the things they would need.

If you do have one, the audit questions are these:

  • Does your executor know, right now, where your current client list is held?
  • Can they actually access it if they needed to?
  • Have you written down what they should say to clients, and what they should not?
  • Have you reviewed the document in the last year?

A clinical will that has not been touched since you set it up five years ago is often a clinical will that no longer reflects your practice.

Many practitioners discover they need a clinical will only when a supervisor or a peer in their network raises it. The new framework, in effect, brings the question up for everyone.

"Is my privacy notice doing what it needs to do, and what about the new complaints rules?"

This is important because it crosses all three categories of obligation and two different regulatory updates.

Section 3.1(c) of the framework requires a clear and accessible privacy notice that outlines all key information including how personal data are collected, used, stored and protected in accordance with relevant data protection laws, including what rights people have in respect of these data. Section 3.1(d) requires you to inform clients about foreseeable limitations to confidentiality, including any legal obligations you may have to disclose information and the use of digital storage systems, platforms or tools that may monitor or collect data.

This isn't strictly a professional body issue. UK GDPR has required clear privacy information since 2018. The new framework makes the link explicit for BACP members, which is helpful because many practitioners had not connected the two.

There is also a separate, more time-pressing legal update here. The Data (Use and Access) Act 2025 introduced a new requirement for organisations to maintain a formal data protection complaints process, which came into force on 19 June 2026.

In practical terms, this means private practitioners need to be able to tell clients:

  • how to raise a data protection concern
  • how it will be acknowledged
  • how it will be investigated
  • how the outcome will be communicated.

The ICO has signalled a measured approach to enforcement during the transition, but the rule itself is statutory and applies to all data controllers. Regardless of size, sector or body membership, though the scale and formality of the process should be proportionate to the size and complexity of the practice.

So there are really two practical tests for your current privacy notice.

First: does it clearly identify the main systems, platforms and providers involved in handling client data?

For example, does it identify your practice management software, video platform, any AI tools you use, your email provider, payment processor and backup system? If your privacy notice uses phrases like "industry-standard secure tools" or "trusted third-party providers" without saying who those tools and providers are, it may not be specific enough for either UK GDPR transparency or the new framework.

Second: does it tell clients how to raise a data protection complaint with you directly, before going to the ICO? Since 19 June 2026, this has been a statutory expectation.

For a private practitioner this does not need to be elaborate, but it does need to be clear. A route for the client to raise the concern, an acknowledgement, an investigation, and an outcome communicated back to them.

Writing a more specific privacy notice and complaints process is not difficult. The structure is broadly:

  • what data you collect
  • what you do with it
  • who else has access to it, including the main named providers
  • how long you keep it
  • what rights the client has
  • how they can exercise those rights
  • how they can raise a data protection concern.

For most practitioners, adapting a good template is the most realistic starting point.

CTH RESOURCE
Privacy notice and DUAA complaints template

A CTH-drafted template covering the framework's transparency expectations and the new DUAA complaints process. Adapt to your practice.

Subscribe to access the template →

There is a small bonus to specificity. The clearer your privacy notice is about who handles client data, the easier the other framework conversations become. If a client asks about AI tools you use, your privacy notice has already disclosed it. If you ever need to evidence the risk-assessment work in section 2.1(e), your privacy notice supports the documentation chain.

"I see clients across borders, or I work from abroad sometimes. What changes for me?"

The new framework introduces clearer cross-border framing than the 2018 version had.

Section 3.2(b) requires records to be stored securely and to comply with the data protection requirements of the country where the record is held. Section 3.3(b), under the header "Act on our responsibilities in reporting serious crime and safeguarding concerns", notes that legal obligations may vary depending on the jurisdictions in which you provide services. Section 4.2(a)(ii) extends the insurance requirement to all jurisdictions of work.

In terms of obligation, the data sections reflect legal duty. UK GDPR and corresponding regulations in other jurisdictions apply regardless of body membership. The insurance section is a BACP requirement that mirrors what any sensible practitioner would do anyway.

If your work is entirely UK-based, meaning UK clients, UK location, no travel, most of this will not apply to you directly. Though you should still be able to say where your data is stored and which legal regime applies.

If you work with clients abroad, or you yourself work from outside the UK for periods of the year, the practical steps are these.

Know where your client-related personal data may be processed or stored. Many cloud services are hosted outside the UK. US-hosted, EU-hosted, or both.

This is not inherently problematic. Many operate lawfully under UK adequacy arrangements, standard contractual clauses or other transfer mechanisms. But you should be able to explain the arrangements if asked.

Confirm with your insurer that your policy covers the actual jurisdictions in which you and your clients are located. Keep the written confirmation on file.

Cross-border insurance is genuinely complicated. It involves governing law, practitioner location, client location, regulatory recognition, and individual insurer exclusions. The framework does not resolve any of these questions.

What it does is make the obligation to think about them explicit. If you have even occasional cross-border clients, a written question to your insurer is worth the small effort.

CTH RESOURCE
Privacy notice and DUAA complaints template

A CTH-drafted privacy notice template that includes the data storage and jurisdictional disclosure the framework now expects. Adapt to your practice.

Subscribe to access the template →
"How do I actually evidence ethical reasoning when something difficult comes up?"

This is one of the strongest threads in the new framework.

Section 1.4(d) requires members to be able to demonstrate ethical rationale and reasoning, including the steps we have taken to resolve the dilemmas or challenges.

Importantly, the framework does not require a formal written rationale for every ethical decision. The rationale is expected to be recorded in a way that is consistent with good practice around record keeping, and with sufficient detail to provide an account of the decisions made and actions taken. The expectation is that your reasoning is articulable and, where appropriate, evidenced. Particularly for significant or contested decisions.

The main category here is professional body requirement, but with real protective value beyond body membership. If a complaint, lawsuit, or regulatory inquiry arises, the ability to demonstrate considered ethical reasoning is one of the strongest defences any therapist has. Body member or not.

Practically, three kinds of record do this work between them:

  • case notes: the formal clinical record
  • process notes or reflection notes: your own thinking about a session or a decision, kept separately from the clinical record
  • supervision notes: the record of conversations with your supervisor about difficult moments.

Process notes, separate from the clinical record and kept for your own reflection and supervision preparation, can be particularly useful here. They are the place where the difficult thinking happens.

If you keep them, they should be kept separately, remain purposeful, and be proportionate. Ensure they are also consistent with your privacy information and record-keeping policy. Whether particular notes are disclosable in response to a Subject Access Request is fact-specific, so it is safer not to assume they are automatically protected.

The framework does not require you to write a 1,000-word rationale every time you make a decision. It expects you to be able to point to some record, whether clinical, process, or supervision, that shows you thought about a difficult question.

"I mix personal and professional digital channels. Does that need to change?"

The 2018 framework asked members to take reasonable care to separate personal and professional social media.

The new framework, at section 1.3(d), is more direct. Members must ensure there is a clear boundary between our personal and professional social media, digital accounts and ensure that public communications, whether personal or professional, reflect the ethical principles set out in this Ethical Framework.

Note the second part of this. It is not just about keeping channels separate. It is about all public communications, including those on personal accounts, reflecting the ethical principles of the framework. That is a meaningfully wider expectation than the draft had.

The main category here is professional body requirement and broadly good practice. It is not a specific legal duty, but mixing channels creates real risk of accidental disclosure, boundary confusion, and data-protection breaches. Risks any thoughtful practitioner would prefer to avoid. The added expectation that personal communications reflect ethical principles also has implications for public engagement, political posting, and how members present themselves online generally.

For solo practitioners with limited resources, the question is what counts as adequate separation.

The honest answer: a separate work phone number is not strictly required, but a dedicated work email and separate professional accounts on whichever social platforms you use is fairly minimal.

Using personal WhatsApp or personal email for client contact has been quietly accepted by many UK therapists for years. The new framework wording suggests that this now needs more deliberate thought and clearer boundaries.

The practical move is to audit your current channels:

  • Where do clients message you?
  • What email do they use?
  • What number do they text?
  • Which social accounts do they see?

Then decide which need to be moved or duplicated to professional-only versions. For most practitioners, this is a few hours of setup work, not a major restructuring.

"What about my working agreement and intake materials?"

Section 1.2(b) of the framework requires members to provide people with a record of the working agreement.

Several other framework items end up being documented inside this agreement, or referenced from it:

  • fees and payment terms, including how and when fees will be reviewed
  • how data are handled
  • foreseeable limits to confidentiality
  • the use of AI or digital tools, and the informed consent process for these
  • access to safeguarding policy details
  • the existence of a clinical will arrangement
  • how to raise a data protection concern.

The main category here is mixed. Partly legal duty, partly professional body requirement, and partly good practice.

The privacy notice and GDPR elements are legal duties. The formal working-agreement record is a professional body requirement for BACP members. The broader point is good practice. Any therapist offering paid services would prudently have clear written terms.

Whether all of this sits in a single working agreement or splits between a working agreement and a standalone privacy notice is a matter of preference. A short standalone privacy notice that the agreement references is a workable structure.

What matters is that the client has, in writing, a record of:

  • what is agreed
  • what is confidential
  • what might break confidentiality
  • what tools handle their information, including any AI tools they need to consent to
  • how to raise concerns about their data
  • how the relationship ends if you become seriously ill or die.

If your existing working agreement was written before 2023, it is likely missing some of these items. Particularly around AI use and informed consent, the clinical will, the specificity of the privacy notice, and the new complaints-handling expectations.

A review of the document against the framework sections above and the DUAA changes is the practical task.

CTH RESOURCE
Privacy notice and DUAA complaints template

A CTH-drafted privacy notice template that complements your working agreement, covering AI tools, data storage, and the DUAA complaints process. Adapt to your practice.

Subscribe to access the template →
"Are my fees, payment terms, and tax position OK?"

The new framework adds a financial responsibility section that did not exist in 2018.

Section 3.4 requires members to be aware of and comply with tax obligations in the country where they provide services, including reporting requirements. Section 3.4(b) requires you to provide clear and transparent information to clients about your fees, including when and how payments are to be made, and how and when fees will be reviewed.

The fee review requirement is new since the draft, and worth noting. Many practitioners do not have a documented process for fee reviews. Increases have historically been informal, letter-based, or verbal. The framework now expects the review process itself to be transparent to clients from the outset.

The tax obligation is a legal duty. It applies to every sole trader regardless of body membership. The written fees, payment terms and fee review requirement is professional body-specific and good practice combined.

For UK sole-trader therapists, the most consequential current piece of this is Making Tax Digital for Income Tax. It is being phased in from April 2026 for sole traders and landlords whose annual income from self-employment and property is over £50,000, with lower thresholds following.

If MTD applies to you and you have not yet prepared, this is the year to start.

CTH RESOURCE
Making Tax Digital: what it means for your practice

A standalone reflection lesson on whether MTD applies to you, when, and what to have in place. Around 25 minutes.

Access the MTD guide →

You will need either a full accounting package, such as Xero, FreeAgent or QuickBooks, or HMRC-compatible bridging software that connects to a record-keeping system. Bridging software may be cheaper than full accounting software if your needs are simple, although what is suitable will depend on your practice and tax position.

The written fees and payment terms piece is straightforward. Your working agreement should cover the session fee, when invoices are issued, acceptable payment methods, late payment terms, the cancellation policy, and how and when fees will be reviewed.

Most practitioners already do this informally. The framework requires it in writing.

"I have a supervisor. How do I actually use them to walk through all this?"

Supervision is a strong thread through the new framework.

Section 4.3 sets out the supervision requirement. Section 1.4(c) requires members to consult regularly with a supervisor about ethical dilemmas or challenges.

Beyond the framework itself, supervision is the place where the rest of these questions get worked through in real practice.

The main category here is professional body requirement. Supervision is also required by most other professional bodies, though the details vary.

It is not a UK legal duty as such, but it is commonly expected by professional bodies and may be relevant to indemnity and defensibility. Any therapist offering paid clinical work would benefit from it regardless.

A practical use of supervision for the framework changes is to block out a single session in the run-up to 3 November 2026 to walk through your current contracts, privacy notice, digital tool use, AI consent process, insurance arrangements and clinical will against the new framework.

This is the kind of audit that is easier collaboratively than alone. Your supervisor's perspective on what counts as adequate evidence is genuinely useful. Most supervisors will welcome this as a productive use of a session.

What to do this month

If the article above has flagged any specific concerns for your practice, the highest-leverage actions are these.

1. Check your privacy notice and complaints process

  • Does it identify the main tools and providers handling client data?
  • Does it tell clients how to raise a data protection concern with you directly?

The DUAA complaints rules came into force on 19 June 2026, so this is the most legally exposed item. Start here.

2. If you use AI tools, digital tools or online platforms that touch client material, revisit your consent process

The framework now explicitly requires informed consent before client data goes into any AI tool, digital tool or online platform. Draft a short written risk assessment for each one. Confirm your consent process meets the framework's requirements. Not a checkbox in software terms, but informed client agreement, ideally recorded. Confirm decision-making responsibility remains with you. This is the item most likely to be missing for current users.

3. Check your clinical will

If you do not have one, put one in place. The work is a few hours and templates exist. If you do have one, audit it. Does your executor know where your client list is right now, and could they actually access it?

The remaining items in this article are worth attending to but less urgent. They can wait for the run-up to 3 November 2026, when the framework takes effect and the accompanying Ethics in Practice and Ethics Essentials resources are available.

If this has helped you spot gaps in your own documents, start with the privacy notice, AI position and consent, and clinical will. Those are the three areas most likely to need action before the new framework takes effect on 3 November 2026.

Where to find the framework, and what else to read

The framework is available on the BACP website on the Ethical Framework for the Counselling Professions page.

The framework itself is short and well worth reading directly.

The Confident Therapist Hub publishes regular pieces on the practical side of UK private practice. Future articles will go deeper into AI note-taking ethics and informed consent, working agreements that meet the new framework, and clinical wills in practice.

CTH resources referenced in this article:

If you would find it useful to think through these themes with other UK practitioners, the CTH email list will let you know when each is published.

References and sources
  1. BACP, Ethical Framework for the Counselling Professions 2026, published 4 August 2026, effective from 3 November 2026: https://www.bacp.co.uk/media/26472/bacp-ethical-framework-for-the-counselling-professions-2026.pdf
  2. ICO, Exemptions: https://ico.org.uk/for-organisations/data-protection-fee/data-protection-fee/exemptions/; ICO, Data protection fee self-assessment: https://ico.org.uk/for-organisations/data-protection-fee/data-protection-fee-self-assessment/
  3. ICO, What privacy information should we provide?: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/the-right-to-be-informed/what-privacy-information-should-we-provide/; ICO, Transparency: https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/accountability/transparency/; ICO, What is valid consent?: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/consent/what-is-valid-consent/
  4. ICO, How to deal with data protection complaints: https://ico.org.uk/for-organisations/how-to-deal-with-data-protection-complaints/; GOV.UK, Data (Use and Access) Act 2025: data protection and privacy changes: https://www.gov.uk/guidance/data-use-and-access-act-2025-data-protection-and-privacy-changes; GOV.UK, Data (Use and Access) Act 2025: plans for commencement: https://www.gov.uk/guidance/data-use-and-access-act-2025-plans-for-commencement
  5. BABCP, Clinical Wills Policy: https://babcp.com/about/who-are-babcp/our-policies/clinical-wills-policy/
  6. GOV.UK, Making Tax Digital for Income Tax: https://www.gov.uk/government/collections/making-tax-digital-for-income-tax; GOV.UK, Find out if and when you need to use Making Tax Digital for Income Tax: https://www.gov.uk/guidance/find-out-if-and-when-you-need-to-use-making-tax-digital-for-income-tax

This article does not constitute legal or compliance advice. Consult your supervisor, your professional body, your indemnity insurer, and a qualified data protection adviser for guidance specific to your practice.

Based on the Ethical Framework for the Counselling Professions 2026, published by BACP on 4 August 2026 and taking effect from 3 November 2026.

A note on the date: the PDF of the framework states "takes effect from 1 November 2026," but BACP's implementation guidance for members states the framework becomes mandatory from midday on Tuesday 3 November 2026. This article follows BACP's implementation guidance.

This article was developed with the assistance of AI writing tools and carefully reviewed by the Confident Therapist Hub team in line with our AI Use Policy.

Created with