A genogram is probably the most sensitive document from a data protection perspective that arises in a therapeutic practice: health information, relationship patterns, addictions, psychiatric diagnoses – and not only about one person, but about entire families, often across three or more generations. Those who create genograms bear a responsibility that extends far beyond the individual client.

Datenfluss-Schema von der Klient:in über die Beratung zur verschlüsselten Datei
Datenfluss von der Klient:in bis zur verschlüsselten lokalen Datei — keine Cloud.

Why Genogram Data Requires Special Protection

A genogram contains data about the entire family system – health data, mental illnesses, addiction problems and relationship conflicts, documented in detail across several generations. And here lies the particular problem: this data frequently concerns people who have never sat in a consulting room, have never consented, and may not even know that their family history is documented somewhere.

The GDPR classifies health data as "special categories of personal data" (Art. 9) – their processing is fundamentally prohibited unless one of the listed exceptions applies. For therapeutic practice this means: the legal basis exists, but it is narrow, and anyone standing on it should know where the edges are.

Genogramm hinter einem Schutzschild mit Schloss-Symbol
Genogramm hinter Verschlüsselung — Daten bleiben lokal.

The Biggest Data Protection Risks with Genograms

In practice, numerous data protection pitfalls lurk when working with genograms:

Lebenszyklus-Kreis eines Genogramms mit vier Stationen
Lebenszyklus — Erstellung, Nutzung, Aufbewahrung, Vernichtung.
  • Cloud storage: Many genogram tools store data in the cloud. This means sensitive client data leaves your control – frequently to servers outside the EU.
  • Unencrypted files: Genograms as image files or unencrypted documents on the computer are immediately readable in the event of theft or unauthorised access.
  • Shared devices: In practices with multiple therapists, genograms can be accidentally viewed by unauthorised persons.
  • Missing consent: Genograms document data about family members who have never consented – a legal minefield.
Article 9 GDPR: The processing of health data, data concerning sexual life and genetic data is fundamentally prohibited. With genograms, these categories arise regularly.

Cloud vs. Offline: Which Is More Secure?

Cloud-based genogram tools are problematic from a data protection perspective. They require complex data processing agreements, server location checks and technical security measures that are barely manageable for individual practices. The risks in detail:

  • Server location: With US cloud providers, authorities can access data under the CLOUD Act – regardless of the physical server location.
  • Data breaches: Cloud services are regularly targeted by hackers. A data breach involving health data has severe consequences.
  • Dependency: If the cloud provider discontinues its service, your genogram data may be lost.
  • DPA obligation: For every cloud service processing client data, you need a data processing agreement under Art. 28 GDPR.

The Secure Alternative: Offline Software with Encryption

Offline software such as GenoEasy offers the highest data protection: all data remains on your local computer. No data is transmitted to the internet, no cloud account is required and no connection is established. AES-256 encryption additionally protects your genogram files from unauthorised access.

AES-256-GCM is the same encryption standard used by banks and the military. Even in the event of physical theft of the computer, the encrypted genogram files are unreadable without the password.

Practical Checklist: GDPR-Compliant Genogram Work

Use this checklist to make your handling of genogram data GDPR-compliant:

GDPR Checklist for Genograms
  • Client consent for genogram creation documented
  • Notice given that data of family members will be recorded
  • Genogram software operates offline (no cloud transmission)
  • Files are stored encrypted (AES-256 or equivalent)
  • Computer access protection (password, screen lock)
  • Deletion concept in place (retention periods defined)

Conclusion: Data Protection Is Not an Obstacle, But a Quality Mark

GDPR-compliant work with genograms is not bureaucratic overhead but a quality mark – and ultimately a question of respect. Clients entrust you with their most intimate family stories. This trust deserves the best possible protection, not merely the legally prescribed minimum.

GenoEasy was conceived from the outset for this standard: completely offline, AES-256 encryption, no cloud, no registration, no data that leaves your practice. So that you can concentrate on what clients come to you for – the therapeutic work, not the technology behind it.

Try GenoEasy for free

Try GenoEasy free for 14 days and discover how easy it can be to create professional genograms.

Download now