BG-014Building Groups
Privacy and Records in Peer Groups
Notes, confidentiality and record keeping in peer support: what your group should decide, write down and store, or safely leave unrecorded.

What is actually at stake when a peer group keeps records?
Records create power. A shared notebook, a sign in sheet, a message thread, or a spreadsheet of names can help a group function and can also expose people. Two distinct things are usually tangled together: confidentiality, which is a promise about what people will not repeat, and record keeping, which is a decision about what gets written down and who can see it. They deserve separate conversations.
There is also a legal layer. Privacy rules around health information exist in many jurisdictions, and they vary. In Australia, for example, privacy law sets strict rules on how a health service provider may collect, use and disclose health information, and people can complain if their information is mishandled (https://www.oaic.gov.au/privacy/your-privacy-rights/health-information). Many peer groups are not health service providers, but the moment a group works alongside a clinic, receives referrals, or holds information someone would call health information, the environment changes. Human rights law in Ontario similarly frames services around equality, dignity and respect, which is relevant when you decide who may be asked for information and why (https://www.ohrc.on.ca/en).
None of that settles your group's choices. It sets the outer edges. Your group has to decide the rest, in writing, before a crisis makes the decision for you.
What should a peer group decide first about confidentiality?
First, decide what confidentiality means in plain language, not in a legal phrase. A workable starting point is: what is said in the room stays in the room, and the parts that cannot stay in the room are named in advance. The second half of that sentence is the hard part, and it is the part groups most often skip.
Second, decide whether the promise is individual or collective. Individual confidentiality means each person keeps their own counsel. Collective confidentiality means the group treats shared knowledge as shared property, so nobody repeats a story even to another member outside the meeting. Collective norms fit small, stable groups. Individual norms fit drop in settings. Pick one and say why.
Third, decide who is inside the circle. Facilitators, co facilitators, a bookkeeper, a landlord who holds the key, a funder who wants attendance numbers, and a messaging platform's servers are all potential recipients. If you cannot name them, you cannot promise anything about them.
Should the group keep notes at all?
Sometimes no. A group can run on memory and still be useful. Refusing notes is a legitimate design choice, especially where members have reason to distrust files kept about them. If that is your choice, say it out loud so members know there is no hidden archive.
Sometimes yes, for narrow reasons. Notes can carry practical threads: who agreed to book the room, what the group decided about the phone tree, which member asked for a lift next week. That is administrative memory, not personal history.
The useful rule is to write only what the group needs to function, and to keep the rest unwritten. If a detail would embarrass someone if it appeared on a shared screen, it probably does not belong in a file. For related thinking on what peer support is and is not, see What Peer Support Actually Means.
What belongs in a record and what never does?
A dependable practice is to define three categories and hold to them.
| Category | Examples | Default treatment |
|---|---|---|
| Administrative | Room bookings, supplies, phone tree, decisions | Written, kept short, named custodian |
| Group process | Ground rules, facilitation notes, patterns noticed | Written only with agreement, no personal detail |
| Personal disclosure | Diagnoses, medication, trauma accounts, family conflict | Not written, or written only by the person, for themselves |
The third row is where most harm happens. A group does not need a written record of who disclosed what in order to be a good group. If a member wants their own written account, they can keep it themselves. That respects autonomy and removes a store of sensitive material from your group's custody entirely.
Who can access records, and for how long?
Access should be by role, not by seniority or friendship. A named custodian holds the material. A second person knows where it is in case of emergency. Everyone else asks the custodian.
Retention needs an end date. "Forever, because we might need it" is not a policy. Decide a period, write it, and actually delete or shred when it passes. If a funder requires attendance counts, share counts, not narratives. If a referral partner wants a case story, get explicit consent from the person concerned and share the minimum necessary.
Member access matters too. People should be able to ask what is held about them and get a straight answer. If your records cannot survive that question, they are the wrong records. On the limits of what a peer group should be doing with clinical material, Peer Support and Clinical Care Compared is a useful companion.
How should digital tools and messaging be handled?
Treat every message thread as stored, searchable, forwardable, and possibly subpoenable. A chat group is not a room. Assume screenshots happen.
Practical rules that groups actually keep:
- Use one channel for logistics and a separate, clearly labelled one for anything personal, or none at all.
- Turn off auto download of media in group chats.
- Avoid full names plus sensitive context in the same message.
- Never post identifying stories from a meeting to a public account.
- Decide whether the group's cloud storage is acceptable before uploading anything.
If the honest answer is that the group cannot secure a channel, do not put sensitive content in it. A phone call and a closed room remain underrated technologies.
What goes wrong, and what should be in a written policy?
Common failures are predictable. Notes outlive the group. A facilitator keeps a personal file that the group never agreed to. A well meaning member shares a story to explain the group to a funder. A new facilitator inherits a binder nobody has read. A member asks to see what is written about them and discovers there is more than they expected.
A written policy can be one page. It should state: what confidentiality means here, what cannot be kept confidential and why, what is recorded, what is never recorded, who holds it, who may see it, how long it is kept, how someone asks about or corrects their own information, and how the policy changes. Review it every year with the group, because membership turns over and memory does not transfer automatically. If your group is still settling its structure, Starting a Peer Support Group covers the groundwork that this policy sits on.
One caution. Writing a policy is not the same as becoming a regulated service. If your group is entering arrangements with clinics, insurers, or funders where personal health information flows, get current advice rather than adapting a template. Rules differ by country, sector and funding stream, and they change. The sources cited here are starting points, not a substitute for checking current official guidance in your jurisdiction.
Groups that decide these things early tend to have an easier time later. Not because paperwork is virtuous, but because predictability is a form of care. People can speak more freely when they know exactly where their words will go, and exactly where they will not.


