Video calls for online therapy: what a GDPR checklist actually requires
Online therapy stopped being a compromise "for emergencies" some time ago: the client joins from home, where they feel safe, and the therapist is not tied to an office. What the format needs is a stable picture, sound without delay, and certainty that nobody outside the room can see the conversation. In Europe there is a fourth requirement: the platform has to be defensible under the GDPR, because health data is special-category data. This article goes through what the professional guides actually ask for, why they tell practitioners to avoid the free plans of the big services and messengers, and how a session works on Joyin.
Why the format works
The core of a session is contact, and contact lives in the face, the voice and the pauses. Good video carries all of that: the therapist sees expressions, hears intonation, notices when the client goes quiet. The online format also has advantages of its own:
- The client is in a familiar place. For many people it is easier to talk about hard things from their own room than from an unfamiliar office.
- No travel. A session takes exactly 50 minutes, not half a day. Fewer cancellations for "I can't make it there in time".
- Geography stops mattering. A client who moves to another city or country keeps their therapist.
- Regularity is easier. The same time, the same link, every week.
The only requirement on the client's side is a quiet place and headphones. The rest is the platform's job.
What the professional guides ask for
Spanish guides for psychologists published in 2025 and 2026 are unusually direct. They tell practitioners not to use, even though they are free, basic Zoom, standard Google Meet, WhatsApp or FaceTime for sessions, because these do not give the practitioner a valid processing agreement, control over metadata or a defensible position on health data. What they ask for instead reads like a checklist:
- Where are the servers? They should be in the EU.
- Is there a data processing agreement (DPA) you can sign? The therapist is the controller; the platform is the processor; without a contract there is no lawful processing.
- Encryption of the media path (TLS 1.2+ and SRTP at minimum).
- No recordings stored by default, and recording only with explicit consent.
- A waiting room, so nobody with the link walks into someone else's session.
Notice what is not on the list: a certificate, a badge, or a promise that the platform "complies with the GDPR for you". Compliance belongs to the practitioner; the platform can only make it possible or impossible.
How a session runs on Joyin
The most common mistake is to make joining hard for the client. If before the first session a person has to download a program, create an account and confirm an e-mail, part of their anxiety goes into fighting the technology instead of into the work.
The flow that works without friction:
- The therapist creates a meeting on joyin.work, or opens a permanent room with an address like
joyin.work/your-name/sessions. - The client gets the link in a message together with the reminder of the time.
- At the agreed time the client opens the link in the browser, on a computer or phone, with no install and no account, types a name and knocks.
- The therapist admits the client from the waiting room and the session begins.
If the previous session ran over, the next client waits at the door instead of walking into someone else's conversation. The client leaves nothing behind: no e-mail, no phone number, no account. The guest path is described in video call without registration.
The checklist against Joyin, honestly
| What the guides require | Joyin |
|---|---|
| Servers in the EU | Media runs through servers in Germany; data is stored in the EU; the operator of this site is an EU company |
| A signable DPA | Available on request; the public list of sub-processors is on the DPA page |
| Encryption | DTLS-SRTP on every connection, private link-only rooms |
| No recording by default | Recording is off unless the host turns it on; when it is on, every participant sees the indicator; files are deleted after 3 days |
| Waiting room | Yes, the host admits each person by hand |
| Client without an account or install | Yes, browser link on a computer or phone |
| Time limit | None; a 50-minute session or a 90-minute one, no cut-off |
| AI notes | Coming soon, off by default, host-controlled, visible to all participants when on |
What Joyin does not claim: a certificate, end-to-end encryption (the media is encrypted in transit and on the server side, which is what SRTP means, not E2EE), or that using it makes your practice compliant. You remain the controller of your client data; Joyin gives you the pieces the guides ask for and a contract to put them in.
Privacy: what the practitioner is responsible for
| Risk | How it is covered |
|---|---|
| Interception of video and audio | Encrypted media streams (DTLS-SRTP), always on |
| A stranger joins by link | Waiting room: the host sees the name and admits by hand |
| The session is recorded without consent | Only the host can record; everyone sees the status; off by default |
| Client data in third hands | The client needs no account and leaves no e-mail or phone number |
| Recordings piling up | Deleted after 3 days; download only what you have consent to keep |
Agree the rules with the client in the first session: we do not record (or only with explicit consent from both sides), nobody else is in the room on either side, and this is how we reconnect if the line drops.
Practical tips for sessions
- Headphones on both sides. They remove echo, make the conversation feel closer, and protect the client from being overheard at home.
- Camera at eye level. A laptop on a stand or a stack of books, and eye contact becomes natural.
- Light from the front, not behind. A window behind you turns the face into a silhouette.
- A backup channel. Agree in advance: if the connection drops, the therapist calls back or the client returns by the same link.
- Five minutes of buffer. Join the room a little early to check sound and settle.
FAQ
Does the client need to register or install anything?
No. The client opens the link in a browser on a computer or phone, types a name and lands in the waiting room. Only the therapist needs an account, and only to keep the permanent room and, if used, recordings.
Is there a time limit on a session?
No. A session can run 50 minutes, 90 minutes or as long as needed; the meeting does not end on its own.
Can a session be recorded?
Yes, but only by the host, only visibly, and in therapy only with the client's explicit consent. The file appears in the host's dashboard and is deleted after 3 days. See how to record a video call.
Does it work for group therapy?
Yes. A room holds up to 100 participants, so a group of 8 to 12 is no problem, and the waiting room lets in only the group's members. Breakout groups are available for exercises in pairs.
Is Joyin "GDPR certified"?
No platform is, and you should be wary of any that says so. Joyin gives you EU servers, an EU operator, a DPA, encryption, a waiting room and recording off by default. The compliance of your practice is yours.
The details for practitioners, including the DPA and the list of sub-processors, are on Joyin for therapists. Trying it is simpler than reading: open joyin.work, create a room and run your next session by link, with nothing for the client to install.