Ethics in IEMT Practice: Lesson 2.3
Confidentiality and Data Protection
Welcome
In this lesson, we examine the ethical and legal responsibilities that IEMT practitioners have regarding confidentiality and data protection. As therapists, we are trusted with highly sensitive information, and maintaining that trust is fundamental to ethical practice.
Learning Objectives
By the end of this lesson, you will be able to:
- Understand the ethical principles behind client confidentiality.
- Determine the circumstances in which you may need to breach confidentiality.
- Describe your responsibilities under data protection laws (e.g., GDPR).
- Implement practical strategies to protect client information.
Why Confidentiality Matters
The ethical obligation to maintain confidentiality in IEMT practice extends beyond a mere procedural duty, embodying a profound commitment to fostering a therapeutic environment where clients feel secure in their vulnerability.
Given IEMT’s capacity to elicit rapid and often deeply personal disclosures, the assurance of confidentiality becomes a linchpin for client trust, enabling the uninhibited exploration of emotional experiences.
This duty aligns closely with the principle of autonomy, as it empowers clients to retain control over who accesses their private information, thereby reinforcing their agency within the therapeutic process.
Moreover, confidentiality serves as a bulwark against the potential harm—emotional, social, or reputational—that could arise from unauthorised disclosures, positioning it as a critical expression of non-maleficence in practice.
Confidentiality underpins the therapeutic relationship. It allows clients to speak openly, knowing their disclosures won’t be shared without good reason.
It reflects the ethical principles of:
- Autonomy (respecting client control over their information)
- Non-maleficence (protecting clients from harm caused by breaches)
- Integrity (acting honestly and responsibly with sensitive material)
Limits of Confidentiality
The limits of confidentiality, while necessary exceptions, introduce a complex ethical tension for IEMT practitioners, particularly given the therapy’s brief and intensive nature.
Situations involving imminent risk to the client or others, safeguarding concerns, or legal mandates compel practitioners to balance preserving trust and fulfilling their broader duty of care.
In IEMT, where emotional shifts can surface abruptly, practitioners must remain attuned to subtle indicators of risk—such as expressions of despair or aggression—that might necessitate a breach.
This discernment requires not only clinical judgement but also a transparent approach to communication, ensuring that clients are informed of these limits from the outset and understand the rationale behind any decision to disclose.
By documenting such decisions meticulously, practitioners uphold the principle of integrity, providing an accountable framework for actions that deviate from the norm of confidentiality.
Confidentiality is not absolute. There are situations where you may be required to share information:
- If the client poses a serious risk to themselves or others.
- If there is a safeguarding concern (especially with children or vulnerable adults).
- If required by law or court order.
Best practice:
- Ensure that the limits of confidentiality are clearly explained at the beginning of therapy.
- Revisit this explanation if circumstances change.
- Document any decisions to breach confidentiality, including your rationale.
Data Protection and GDPR
Compliance with data protection regulations, such as the General Data Protection Regulation (GDPR), imposes a structured legal overlay on the ethical imperative of confidentiality, demanding that IEMT practitioners adopt rigorous standards for handling client information.
The GDPR’s emphasis on data minimisation and security aligns with the therapeutic ethos of collecting only what is essential for effective practice. Yet, it challenges practitioners to operationalise these principles in both digital and physical realms.
For instance, using encrypted platforms for storing session notes or communicating with clients reflects a proactive response to the vulnerabilities inherent in modern technology.
This legal framework also amplifies the ethical call for transparency, requiring practitioners to provide clients with clear, accessible explanations of how their data is processed—a task that, in the context of IEMT’s conversational style, must be executed with both precision and sensitivity to avoid overwhelming the client.
As a practitioner, you must comply with your country's General Data Protection Regulation (GDPR) or equivalent data protection law.
This includes:
Key Responsibilities:
- Lawful Basis for Data Collection – e.g., client consent or contract.
- Data Minimisation – only collect what is necessary.
- Security – use encrypted storage and password protection.
- Transparency – inform clients how their data is used and stored.
- Retention and Disposal – keep records only as long as needed and dispose of them securely.
Provide clients with a privacy notice explaining your data practices.
Practical Strategies for Practitioners
The intersection of confidentiality and data protection in IEMT practice is further complicated by the potential for informal settings, such as online sessions or community-based workshops, to blur traditional boundaries of privacy.
The portability of digital tools, while enhancing accessibility, increases the risk of inadvertent breaches—whether through unsecured networks or casual discussions in shared spaces. Practitioners must, therefore, cultivate a heightened awareness of their environment and implement practical safeguards, such as using anonymised records or conducting regular audits of their data practices.
These measures not only mitigate risk but also reinforce the ethical principle of justice by ensuring that all clients, regardless of the context in which they engage with IEMT, receive equitable protection of their personal information.
This vigilance underscores the practitioner’s role as a steward of trust within an increasingly interconnected therapeutic landscape.
- Use secure digital platforms for note-taking and communication.
- Avoid discussing clients in public or unsecured environments.
- Lock physical files and shred outdated paper records.
- Keep passwords private and update them regularly.
Self-Reflection Exercise
Review your current confidentiality and data protection procedures.
- Are there any areas where you might be vulnerable to a breach?
- Do you have clear documentation, consent forms, and a privacy notice?
- How confident are you in explaining data use and confidentiality to clients?
Make a list of 2–3 improvements you might implement.
Key Takeaways
- Confidentiality builds trust and must be respected unless there is a clear reason to break it.
- Practitioners must comply with data protection laws, including GDPR.
- Clear, secure, and transparent data practices are vital for ethical IEMT work.
Next Steps
In Lesson 3.1, we shift our focus to working with children and young people, beginning with safeguarding and consent considerations for minor clients.
This ethics series is produced by The Association for IEMT Practitioners and is intended for professional development purposes. Always adhere to local laws, safeguarding requirements, and your professional judgement when applying ethical principles in practice.


