Digital Gloss

The brand paper for the beauty and wellness economy

Edition 2026-08-01Published by Northbank Media
Retention and lifecycle

Client data in a beauty business, and what the rules require

Consultation forms, patch test records, photographs and marketing lists. What a small beauty business actually has to do about the data it holds.

Retention9 min readReviewed 1 August 2026
A cream swipe on lacquer. What is recorded about a client is more sensitive than it looks.
A cream swipe on lacquer. What is recorded about a client is more sensitive than it looks.
The short answer

A beauty or wellness business holds more sensitive information than its owners usually realise: consultation forms, medical questions, patch test records, treatment histories and images. Some of that is health information, which attracts additional protection. The practical obligations are to know what you hold and why, to have a lawful basis for each use, to keep it secure and no longer than necessary, to tell people clearly what you do with it, and to be able to respond when someone asks for a copy or asks you to stop. Marketing is a separate permission from record keeping.

What a salon actually holds

Most owners think of client data as a list of names and email addresses. The reality is broader and more sensitive.

  • Contact details and booking history.
  • Consultation forms, which frequently include questions about medication, pregnancy, skin conditions, allergies and medical history.
  • Patch test records and reaction notes.
  • Treatment notes, including what was used and what happened.
  • Photographs and video, sometimes showing a condition.
  • Payment records and, where memberships exist, recurring payment details.
  • Marketing preferences, or an absence of any record of them.

Several of those categories concern a person's health, and health information attracts stronger protection than ordinary contact details. That single fact changes the seriousness of the whole picture, and it is why a beauty business cannot treat data protection as an administrative formality.

A consultation form asking about medication and skin conditions is a health record, whatever it is called on the folder.

The obligations, in the order they arise

1. Know what you hold and why

The starting point is an inventory: what data exists, where it lives, who can see it, why you have it, and how long you keep it. Most small businesses discover during this exercise that data is spread across a booking system, a spreadsheet, a paper folder, a phone camera roll and someone's personal messages.

2. Have a basis for each use

Different uses need different bases. Delivering a treatment safely, keeping a record for insurance purposes, sending an appointment reminder and sending marketing are separate uses, and the basis for one does not carry across to another. Health information requires additional conditions to be met.

3. Tell people, in language they can understand

A privacy notice that people can find and read, saying what you collect, why, who else sees it, how long you keep it and what rights they have. It should be available at the point where data is collected, not only in a footer.

4. Keep it secure

Proportionate measures: individual logins rather than shared ones, a locked cabinet for paper, encryption on devices, controlled access to the booking system, and a process for removing access when someone leaves.

5. Keep it no longer than necessary

Set retention periods and apply them. Insurance requirements and professional guidance may drive minimum periods for treatment records; that is a reason to keep records for a defined period, not indefinitely and not for marketing.

6. Be able to respond

People have rights, including to a copy of their data and to object to marketing. You need a process that works within the required timescales, and someone who knows it exists.

01What you hold, and how sensitive it is
CategorySensitivityPoint to watch
Contact and booking historyOrdinary personal dataOften duplicated across systems
Consultation formsFrequently health informationKept in paper folders with no access control
Patch test and reaction recordsHealth informationRetention period rarely defined
Treatment notesOften health informationShared logins make authorship untraceable
Photographs and videoCan be health informationHeld on personal phones, hardest to control
Marketing preferencesOrdinary, but criticalFrequently no record of what was agreed

Source: Framework is this paper's own; the underlying obligations derive from UK data protection law.

Orientation only, not legal advice. The ICO publishes guidance written for small organisations and it is the right starting point.

Marketing is a separate question

The most common error in this sector: treating the client record as a marketing list. Holding an address so you can confirm an appointment does not give you permission to send promotions to it.

Electronic marketing has its own rules, and the Information Commissioner's Office publishes detailed guidance on direct marketing and on the Privacy and Electronic Communications Regulations. Key practical points: consent needs to be specific, freely given and recorded; there is a narrow exception that can apply to existing customers where specific conditions are met; opting out must be simple and honoured promptly; and pre-ticked boxes do not work.

Design your intake form so that the service permission and the marketing permission are visibly separate. It takes one extra line and prevents the problem entirely. The practical side is covered in email and retention.

Photographs, which are the most common gap

Images of identifiable clients used in marketing are personal data, and where the image reveals something about a condition, it is health information. The requirements are the same as for other data, with the added complication that content published on platforms is harder to retrieve.

A workable process: ask separately from treatment consent; be specific about the channels and the period; record it against the client record; keep a list of where each image has been published; and act quickly on withdrawal. A close-crop policy that avoids identifiable faces reduces the problem substantially, which is one reason many businesses adopt it, as described in art direction and photography on a real budget.

Third parties, which multiply the surface

Your booking system, marketing platform, payment provider and any consultant with access are all processing client data on your behalf. That relationship carries obligations, including having appropriate written arrangements in place and satisfying yourself that the provider handles data appropriately.

Two practical checks worth doing once: list every service that holds client data, and confirm what each one does with it. Businesses regularly discover a marketing tool retaining a full client export from three years ago, or a former staff member with active access.

02A proportionate checklist for a single-site business
ItemWhat good enough looks like
Data inventoryOne page: what, where, why, how long
Privacy noticeAvailable at the point of collection, in plain language
PermissionsService and marketing separated on the intake form
SecurityIndividual logins, locked storage, device encryption
RetentionA written period, actually applied
RequestsA named person and a process within the timescales
Third partiesA list, with written arrangements in place
BreachesA one-page process, written before it is needed

Source: Working model used by this paper, not a measurement.

Proportionality is a real principle here. A single-site salon is not expected to operate like a hospital, but it is expected to have thought about it.

If something goes wrong

Have a short written process for a suspected breach: who is told, what is recorded, how you assess the risk to individuals, and the fact that certain breaches must be reported to the Information Commissioner's Office within a tight timescale. Losing a paper consultation folder, or a stolen laptop with an unencrypted client list, are realistic scenarios in this sector rather than theoretical ones.

The value of writing this down in advance is that the decisions are made calmly rather than at speed on the day.

A proportionate version for a small business

None of this requires a compliance department. For a single-site business, a proportionate position looks like: an inventory of what you hold and where; a privacy notice that is available where data is collected; separated service and marketing permissions on the intake form; individual logins and a locked cabinet; a written retention period; a named person who handles requests; a list of third parties with access; and a one-page breach process.

The ICO publishes guidance and tools aimed specifically at small organisations. Working through those once, properly, puts most businesses in a defensible position and takes a day rather than a month.

Questions we get asked

Do we need consent to keep treatment records?

Consent is not always the appropriate basis for record keeping, and other bases may be more suitable depending on the purpose, particularly where records are kept for safety or insurance reasons. What matters is that you have identified an appropriate basis for each purpose, met any additional conditions that apply to health information, and told clients what you do.

How long should we keep consultation forms?

Long enough to meet insurance requirements and any professional guidance that applies to your discipline, and no longer than necessary after that. Set a period, write it down and apply it. Indefinite retention because deleting feels risky is itself a problem.

Can we use client photos we took years ago?

Only if you have a valid basis for the specific use you now intend, and old general permissions rarely cover new uses on new platforms. If in doubt, ask again. Where the image reveals a condition, treat it as health information and be correspondingly careful.

What if a client asks us to delete everything?

You need a process to handle the request within the required timescale, and to explain where you are required or entitled to retain some records, for example for insurance or legal reasons. The right answer is rarely simply yes or simply no, which is why having thought about it in advance matters.

Is our booking system responsible for compliance?

It is processing data on your behalf, and you remain accountable for what happens to your clients' information. Check the arrangements you have with each provider, know what they do with the data, and remove access for former staff and former suppliers promptly.

Sources

  1. Information Commissioner's Office
  2. ICO, Guide to the Privacy and Electronic Communications Regulations
  3. ICO, direct marketing and electronic communications guidance
  4. Chartered Trading Standards Institute

Keep reading

The trade newsletter

For people who build beauty and wellness brands. Sent when there is something worth sending, not when the calendar says so.

One email when something changes that affects a pricing, packaging or claims decision. No schedule, no third party advertising, no sharing of your address.

About this article. Digital Gloss is an independent publication of Northbank Media. This article contains no commercial links of any kind. We do not sell links, we do not publish sponsored articles, we do not name businesses in order to make claims about them, and we take no commission for introducing anyone to a supplier. The external links here point to regulators, legislation and official guidance so that you can check the source. Figures cited come from the sources listed; any panel that sets out a working model rather than a measurement says so in its own footnote. See our editorial standards.