Blog · Security & compliance

Clinical Notes, GDPR and HIPAA: What to Actually Check Before You Trust a Tool

"GDPR compliant" and "HIPAA compliant" appear on almost every note-taking tool's homepage. Neither phrase means much on its own. Here's what to actually check — usable whether or not you end up choosing Lectendo.

Published September 26, 2026 · Lectendo · 7 min read

Every vendor selling to therapists knows "compliant" sells. Fewer explain what it actually requires. If you're comparing tools that touch client data — recording sessions, transcribing them, drafting notes — the badge on the pricing page tells you almost nothing. What follows is a working checklist, not a sales pitch, for evaluating any tool in this category.

GDPR and HIPAA aren't the same thing

GDPR is a European Union regulation (also enforced in the UK through the UK GDPR) governing personal data broadly — it applies to any organization processing data of people in the EU/UK, regardless of where the company is based. HIPAA is a US federal law specifically about protected health information, with its own definitions, its own required contracts, and its own enforcement body. A tool can be strong on one and weak on the other. If you practice in the US, HIPAA is the relevant framework; if you practice in the UK or EU, it's GDPR; some tools serving both markets need to satisfy both, which is harder than satisfying either alone.

Where your data actually lives

Ask directly: which country, or countries, is the audio, transcript, and note data stored in? For EU/UK-based practices, data hosted in the EU under GDPR's framework avoids a whole category of international transfer complications. For US-based practices, storage location matters less than whether the vendor will sign a Business Associate Agreement and follows the required technical safeguards (encryption at rest and in transit, access controls, audit logs). A vague answer — "we use industry-standard cloud infrastructure" — isn't an answer. A specific one names the region and, ideally, the hosting provider's compliance certifications.

Consent, in writing

Recording a session, even briefly, to generate a note requires informed consent from the client — not just a checkbox buried in your intake paperwork, but a clear statement of what's being recorded, what happens to the recording, how long it's kept, and that they can decline without it affecting their care. Check whether the tool gives you consent language you can actually hand to a client, in their language, rather than leaving you to draft it yourself.

Retention and deletion

This is the section most homepages skip. Ask specifically:

QuestionWhy it matters
How long is raw audio kept after the note is generated?Audio is the most sensitive artifact; it should not be retained indefinitely by default.
Can a client request their data be deleted?Required under GDPR (right to erasure) and good practice generally, even where not strictly mandated.
What happens to data if you cancel your subscription?You need a clear export and deletion path — not data held hostage or silently deleted without warning.
Is deleted data actually gone, or just hidden from the interface?"Deleted" should mean deleted from backups within a stated timeframe, not just archived.

Business Associate Agreements (US practices)

If you're in the US and the tool touches protected health information, a signed Business Associate Agreement isn't optional — it's a HIPAA requirement for any vendor acting on your behalf with that data. If a vendor hedges on providing one, or treats it as an enterprise-tier add-on rather than a standard document, that's worth taking seriously as a red flag, not a minor inconvenience.

A short checklist

BEFORE YOU TRUST A CLINICAL NOTE TOOL [ ] Data hosting location named specifically (not just "cloud infrastructure") [ ] Encryption at rest and in transit confirmed [ ] Consent language provided, in the language of your clients [ ] Stated retention period for raw audio [ ] Clear, self-service way to delete client data [ ] Data export available if you cancel [ ] Business Associate Agreement available (US) or equivalent processing agreement (EU/UK) [ ] No use of client data for model training without separate, explicit consent

What "compliant" doesn't mean

It doesn't mean the vendor has been audited by a regulator — neither GDPR nor HIPAA issues certificates. It doesn't mean the tool is immune to breaches — no system is. It doesn't mean you're absolved of your own obligations as the clinician holding the primary duty of care for the record. A compliant tool is a foundation, not a substitute for your own judgment about what you record, how you phrase consent, and what you keep.

Where Lectendo stands on this list

Lectendo hosts data in Europe, provides consent language in the language of the session, states a defined retention period for audio, and gives clients and clinicians a direct way to request deletion. For US-based practices, a Business Associate Agreement is available on request. None of that replaces reading the checklist above for yourself — it's meant to hold up against any tool you're comparing, not just this one.

This article is general information, not legal advice. Confirm specific GDPR and HIPAA obligations for your practice with your own legal counsel or compliance officer.

Frequently asked questions

Is a tool "GDPR compliant" or "HIPAA compliant" just because it says so?

No. Neither GDPR nor HIPAA issues a certificate a vendor can display. Both frameworks describe obligations for how data is handled — compliance depends on actual practices (hosting location, contracts, retention, deletion), not a badge on a pricing page.

Do I need a Business Associate Agreement for a note-taking tool in the US?

If the tool processes protected health information on your behalf, yes — a signed Business Associate Agreement (BAA) is a HIPAA requirement, not optional paperwork. If a vendor can't provide one, that's a clear signal to look elsewhere.

Does hosting in Europe alone make a tool GDPR compliant?

It removes one major risk (international data transfer questions) but doesn't cover everything on its own. You still need clear consent language, a defined retention period, and a real way to delete client data on request.

See the checklist applied to Lectendo

Hosted in Europe, clear consent language in your clients' language, defined retention, and a Business Associate Agreement available on request for US practices. 7-day trial, no card required.

Try Lectendo free (7 days, no card)

Hosted in Europe · GDPR · BAA available on request · Solo plan €49/month.