What a salon actually holds
Most owners think of client data as a list of names and email addresses. The reality is broader and more sensitive.
- Contact details and booking history.
- Consultation forms, which frequently include questions about medication, pregnancy, skin conditions, allergies and medical history.
- Patch test records and reaction notes.
- Treatment notes, including what was used and what happened.
- Photographs and video, sometimes showing a condition.
- Payment records and, where memberships exist, recurring payment details.
- Marketing preferences, or an absence of any record of them.
Several of those categories concern a person's health, and health information attracts stronger protection than ordinary contact details. That single fact changes the seriousness of the whole picture, and it is why a beauty business cannot treat data protection as an administrative formality.
A consultation form asking about medication and skin conditions is a health record, whatever it is called on the folder.
The obligations, in the order they arise
1. Know what you hold and why
The starting point is an inventory: what data exists, where it lives, who can see it, why you have it, and how long you keep it. Most small businesses discover during this exercise that data is spread across a booking system, a spreadsheet, a paper folder, a phone camera roll and someone's personal messages.
2. Have a basis for each use
Different uses need different bases. Delivering a treatment safely, keeping a record for insurance purposes, sending an appointment reminder and sending marketing are separate uses, and the basis for one does not carry across to another. Health information requires additional conditions to be met.
3. Tell people, in language they can understand
A privacy notice that people can find and read, saying what you collect, why, who else sees it, how long you keep it and what rights they have. It should be available at the point where data is collected, not only in a footer.
4. Keep it secure
Proportionate measures: individual logins rather than shared ones, a locked cabinet for paper, encryption on devices, controlled access to the booking system, and a process for removing access when someone leaves.
5. Keep it no longer than necessary
Set retention periods and apply them. Insurance requirements and professional guidance may drive minimum periods for treatment records; that is a reason to keep records for a defined period, not indefinitely and not for marketing.
6. Be able to respond
People have rights, including to a copy of their data and to object to marketing. You need a process that works within the required timescales, and someone who knows it exists.
| Category | Sensitivity | Point to watch |
|---|---|---|
| Contact and booking history | Ordinary personal data | Often duplicated across systems |
| Consultation forms | Frequently health information | Kept in paper folders with no access control |
| Patch test and reaction records | Health information | Retention period rarely defined |
| Treatment notes | Often health information | Shared logins make authorship untraceable |
| Photographs and video | Can be health information | Held on personal phones, hardest to control |
| Marketing preferences | Ordinary, but critical | Frequently no record of what was agreed |
Source: Framework is this paper's own; the underlying obligations derive from UK data protection law.
Orientation only, not legal advice. The ICO publishes guidance written for small organisations and it is the right starting point.
Marketing is a separate question
The most common error in this sector: treating the client record as a marketing list. Holding an address so you can confirm an appointment does not give you permission to send promotions to it.
Electronic marketing has its own rules, and the Information Commissioner's Office publishes detailed guidance on direct marketing and on the Privacy and Electronic Communications Regulations. Key practical points: consent needs to be specific, freely given and recorded; there is a narrow exception that can apply to existing customers where specific conditions are met; opting out must be simple and honoured promptly; and pre-ticked boxes do not work.
Design your intake form so that the service permission and the marketing permission are visibly separate. It takes one extra line and prevents the problem entirely. The practical side is covered in email and retention.
Photographs, which are the most common gap
Images of identifiable clients used in marketing are personal data, and where the image reveals something about a condition, it is health information. The requirements are the same as for other data, with the added complication that content published on platforms is harder to retrieve.
A workable process: ask separately from treatment consent; be specific about the channels and the period; record it against the client record; keep a list of where each image has been published; and act quickly on withdrawal. A close-crop policy that avoids identifiable faces reduces the problem substantially, which is one reason many businesses adopt it, as described in art direction and photography on a real budget.
Third parties, which multiply the surface
Your booking system, marketing platform, payment provider and any consultant with access are all processing client data on your behalf. That relationship carries obligations, including having appropriate written arrangements in place and satisfying yourself that the provider handles data appropriately.
Two practical checks worth doing once: list every service that holds client data, and confirm what each one does with it. Businesses regularly discover a marketing tool retaining a full client export from three years ago, or a former staff member with active access.
| Item | What good enough looks like |
|---|---|
| Data inventory | One page: what, where, why, how long |
| Privacy notice | Available at the point of collection, in plain language |
| Permissions | Service and marketing separated on the intake form |
| Security | Individual logins, locked storage, device encryption |
| Retention | A written period, actually applied |
| Requests | A named person and a process within the timescales |
| Third parties | A list, with written arrangements in place |
| Breaches | A one-page process, written before it is needed |
Source: Working model used by this paper, not a measurement.
Proportionality is a real principle here. A single-site salon is not expected to operate like a hospital, but it is expected to have thought about it.
If something goes wrong
Have a short written process for a suspected breach: who is told, what is recorded, how you assess the risk to individuals, and the fact that certain breaches must be reported to the Information Commissioner's Office within a tight timescale. Losing a paper consultation folder, or a stolen laptop with an unencrypted client list, are realistic scenarios in this sector rather than theoretical ones.
The value of writing this down in advance is that the decisions are made calmly rather than at speed on the day.
A proportionate version for a small business
None of this requires a compliance department. For a single-site business, a proportionate position looks like: an inventory of what you hold and where; a privacy notice that is available where data is collected; separated service and marketing permissions on the intake form; individual logins and a locked cabinet; a written retention period; a named person who handles requests; a list of third parties with access; and a one-page breach process.
The ICO publishes guidance and tools aimed specifically at small organisations. Working through those once, properly, puts most businesses in a defensible position and takes a day rather than a month.
