Industry GDPR documentation

Written and maintained by Chris Haycock, GDPRQuick.com/CliqTo Ltd
Last reviewed August 2026


GDPR for hair & beauty salons

Your salon holds more sensitive personal data than most small businesses realise. Allergy notes, medical conditions, medication, patch test results and before-and-after photos all sit on an ordinary client card. Most of that counts as "special category data" under UK GDPR, which has stricter rules than an email address or a phone number. This page sets out what that means in practice, and how GDPRQuick turns your answers into the statement, records and consent wording your salon needs.

Let's begin.

What counts as personal data in a salon

Personal data isn't just names and addresses. In a typical salon or barbershop, it includes:

  • Client contact details - that includes name, phone, email, addresses
  • Appointment history and treatment notes
  • Allergy information, medical conditions and medication
  • Patch test results and dates
  • Before-and-after photos, including any posted to social media
  • Payment and billing information
  • CCTV footage of clients and staff on the premises
  • Staff records, such as contracts, bank details, National Insurance numbers, sickness records

Some of this - health data in particular - falls into a stricter category under GDPR called "special category data," which needs its own specific legal basis to process, separate from your general basis for holding a client's contact details.

Do salons need to register with the ICO?

Most do. Under the Data Protection (Charges and Information) Regulations 2018, organisations that handle personal data electronically must register with the ICO and pay the annual data protection fee, which is currently £40 a year for organisations with 10 or fewer employees. unless a specific exemption applies. Very few salons qualify for an exemption in practice, because:

  • Holding client contact and treatment records electronically isn't covered by the narrow "accounts and records" exemption
  • Running CCTV on the premises removes the exemption on its own, even if nothing else would
  • Sending marketing texts, emails or loyalty offers counts as processing for marketing purposes

If you're not sure, the ICO publishes a free self-assessment tool that gives a direct answer in under a minute, which is worth two minutes before assuming either way.

What happens if you don't register

Non-payment can result in a fine and being listed on the ICO's public penalty notices page. Registering also gives you an ICO registration number you can display, which is a small but visible signal to clients that you take their data seriously.

Special category data: allergies, health notes and medication

Health information is one of eight categories UK GDPR treats as "special category data", alongside things like racial or ethnic origin and religious belief, because of the extra harm it could cause someone if mishandled. Processing it is prohibited by default unless you meet a specific legal condition, and salons hold this kind of data constantly: allergy notes, skin conditions, medication, pregnancy, and patch test results all count here.

Two things have to be true at once for this to be lawful:

  • You need an ordinary legal basis under Article 6 (the same test that applies to any personal data)
  • You separately need one of the specific conditions under Article 9 that applies to special category data

For most salons, the realistic condition is explicit consent: a clear, opt-in, specific statement from the client that they agree to their health information being recorded and used for a stated purpose. This is a higher bar than the general consent used for marketing: it has to be unambiguous, freely given, and the client has to know exactly what they're agreeing to.

Why a signature on a record card isn't enough consent

A client signing a card to confirm their treatment or acknowledge a patch test is usually evidence of a safety and liability process, and not documented, informed consent to process health data under GDPR. The two get bundled together on the same form, which is understandable, but they're legally different things. Consent for GDPR purposes needs to say, specifically, what health data is being recorded and why - not just confirm the treatment went ahead.

What a valid legal basis looks like in practice

In practice, this means:

  • The client is told, before or at the point of giving information, what health data you're recording and why
  • Agreement is a clear, affirmative action. Not silence, a pre-ticked box, or an assumption from booking an appointment
  • The client can withdraw consent later, and knows how
  • The record itself only holds what's necessary for the treatment, not extra detail "just in case"

Not sure what applies to your hair & beauty salons?

Take the quick risk check before you get too deep into the detail.

Take the 2-minute check

Before-and-after photos on social media

Posting a client's before-and-after photo is one of the most common salon marketing habits, and yet it's one of the least documented. A photo that shows someone's face or other identifiable features is personal data in its own right, and using it for marketing needs its own specific, opt-in consent, separate from the consent a client gives to have the treatment carried out.

  • Agreeing to a treatment isn't the same as agreeing to have it photographed
  • Agreeing to a photo being taken isn't the same as agreeing to it being posted publicly
  • Consent needs to say where the photo will be used, such as Instagram, a website, printed materials etc., not just "may be used for marketing"
  • Clients need a straightforward way to ask for a photo to be taken down later, and you need a process for actually doing it

What "implied consent" gets wrong

It's easy to assume that because a client didn't object in the chair, they're fine with the photo going online. That's not how GDPR consent works; silence or inaction isn't consent, and there's no such thing as consent by default. A documented, specific, affirmative yes is what's needed, ideally with a record of when it was given and for what purpose.

Withdrawing consent later

A client can withdraw consent at any time, including after a photo has already been posted. Having a simple, known process for taking a photo down rather than having to work it out under pressure when someone asks, is part of being able to demonstrate GDPR compliance, not just a nice-to-have.

Booking platforms and your GDPR obligations

If you take bookings through Fresha, Treatwell, Phorest, Booksy, Vagaro or a similar platform, it's worth being clear on where responsibility sits. Under GDPR, your salon is the data controller. You decide what client data is collected and why. The booking platform is the data processor - it handles that data on your behalf, under your instructions. Fresha and Phorest both confirm this arrangement directly in their own terms.

That distinction matters because:

  • The platform's privacy policy explains how they handle data on their system. It doesn't cover your own obligations for walk-ins, paper records, photos, or anything happening outside the platform
  • You still need your own privacy notice that reflects what your salon actually does with client data
  • Marketing messages sent through the platform (texts, emails, promotions) still need proper opt-in consent under PECR, using the platform doesn't transfer that responsibility away from you
  • Most platforms include a data processing agreement in their terms, but it's worth confirming one exists rather than assuming

Why linking to your booking platform's privacy policy isn't enough

Some salons link to Fresha's or Treatwell's privacy policy instead of publishing their own. It's an understandable shortcut, but it doesn't meet the requirement. That policy describes the platform's own processing, not the full picture of how your specific salon collects, uses, and shares client data across every channel you actually use.

CCTV in your salon or barbershop

If you run CCTV on your premises (common in salons for staff safety, stock, and incident evidence) it almost certainly brings you into scope for the ICO data protection fee, even if nothing else about your business would. CCTV is treated as processing personal data whenever it can capture identifiable people, which a camera pointed at a reception desk or shop floor virtually always does.

  • You need visible, clear signage before someone enters the area being filmed; not just "CCTV in operation," but enough detail to say who's responsible and why it's there
  • Footage should only be kept for as long as it's needed for its purpose. UK GDPR sets no fixed legal limit, but 28–31 days is the widely used industry norm for routine commercial footage, with longer retention justified only where there's a specific reason, such as an ongoing incident
  • You must be able to respond to a subject access request for footage, meaning it needs to be stored in a way you can actually search and retrieve, not just recorded and forgotten
  • If your cameras capture anything beyond your own premises such as a shared doorway, the pavement outside etc., that footage is also in scope

What your CCTV signage should say

A sign that only says "CCTV in operation" generally isn't considered sufficient on its own. Effective signage names the purpose (for example, crime prevention and staff safety), identifies who's responsible for the system, and points to where someone can find the full privacy information - usually your website.

Marketing texts, reminders and appointment confirmations

Salons rely heavily on automated texts and emails such as appointment reminders, rebooking prompts, birthday offers, usually sent through booking software by default. Not all of these are treated the same way under the law.

  • Appointment reminders and confirmations are generally administrative, not marketing, so they sit outside PECR's marketing consent rules
  • Promotional messages such as offers, birthday discounts, "come back and see us" campaigns - count as direct marketing and need either specific opt-in consent, or to qualify for the "soft opt-in" exception
  • The soft opt-in only applies if you collected the contact details yourself during a sale, you're marketing similar services, and you gave a clear chance to opt out at the time. It doesn't apply to bought-in lists or contacts collected some other way
  • Every marketing message needs a simple way to opt out, and once someone does, you have to stop - for that channel, at least, until they opt back in

Where salons commonly go wrong

The most common issue isn't sending marketing texts, it's not distinguishing between a transactional message and a promotional one, and assuming that because a client is already in the booking system, any message to them is fair game. Booking software often defaults marketing features to "on," which puts the compliance decision back on you rather than the platform.

What happens if a client's data is lost or shared by mistake

A data breach isn't only a hack. In a salon, it's just as likely to be an appointment book left somewhere visible with health notes in it, a client list emailed to the wrong address, or a staff phone with the booking app on it going missing.

  • Any loss, unauthorised access, or accidental sharing of personal data is a breach in principle, however it happens
  • You then need to assess whether it's serious enough to be reportable - broadly, whether it poses a risk to the people affected
  • If it is, you must report it to the ICO within 72 hours of becoming aware of it
  • You also need to keep an internal record of the breach, even if you decide it doesn't meet the threshold for reporting, the ICO can ask to see this

Having a plan before you need one

Most of the pressure in a breach situation comes from having to work out what to do while also dealing with the incident itself. A short, written process (who to tell, what to check, how to report it) means that decision isn't being made from scratch under stress.

What documents does a salon actually need

Pulling the above together, most salons and barbershops need some version of the following:

  • A GDPR statement / privacy notice, covering clients, staff, and anyone whose data you hold, written to reflect what your salon actually does, not a generic template
  • A Record of Processing Activities (ROPA), which is a working record of what personal data you hold, why, and where it's stored
  • A consent record for special category data, documenting how clients agree to health, allergy, and medical information being recorded
  • A photo consent process, for before-and-after images used in marketing, separate from treatment consent
  • A data retention policy, which says how long client cards, staff records, and CCTV footage are kept, and why
  • A CCTV policy (if applicable) with retention period, signage wording, who has access
  • A breach response process - what to do, who to tell, and how to report to the ICO if needed
  • A marketing consent record - evidence of opt-ins, and a working opt-out process
  • A data processing note covering your booking platform, naming the category of processor you use and what it handles on your behalf

None of this needs to be written from scratch, and it doesn't need to be identical to what a clinic or a retailer would produce, but it needs to reflect what your salon specifically collects and does.

Build your salon's GDPR documents from your own answers

GDPRQuick works through this as a guided wizard, not a blank template. You answer plain-English questions about what your salon collects, such as client health data, photos, CCTV, booking software, marketing. Your answers become the wording for your statement, action plan, and processing records.

  • Start free and see how the wizard builds your documents before paying anything
  • Unlock the full pack - statement, action plan, processing records, and supporting forms - for a one-off £129
  • Come back and update your documents whenever what your salon does changes

Really made us think about it all and get into action in a logical way.

Christine Heath, The Hitzone

GDPRQuick helps you create and maintain GDPR documentation. It does not certify compliance or replace legal advice; your salon remains responsible for its own data protection practices.

GDPRQuick.com UI Platform Screenshot

Check your GDPR risk first.

Use the GDPRQuick risk calculator to get an indicative view of where your hair & beauty salons data protection work may need attention.

Start the risk calculator

Questions about GDPR for hair & beauty salons

Do I need a DPO for a small salon?

Almost certainly not. A Data Protection Officer is only a legal requirement if your core activity involves large-scale, regular monitoring of individuals, or large-scale processing of special category data (health, biometric etc.) as a main activity — not as a side effect of running appointments. Most independent salons and small chains don't meet that bar. You still need someone responsible for data protection decisions; it just doesn't need to be a formal DPO role.

How long should I keep client record cards?

UK GDPR sets no fixed retention period — the rule is "as long as you need it for the purpose, then no longer," and you have to be able to justify whatever period you choose. Trade bodies do publish their own recommendations: the National Hair & Beauty Federation's Code of Practice suggests at least 2 years, while the Complementary Therapists Association recommends 7 years for adult client records. Picking one of these and writing it into a retention policy is usually the pragmatic route.

Do self-employed chair renters need their own GDPR documentation?

Yes, if they collect and control their own client data — which most do, even inside someone else's premises. Chair renters are typically their own data controller for their client list, so the salon's GDPR statement doesn't cover them automatically. It's worth agreeing this explicitly rather than assuming.

Is it legal to post before-and-after photos on Instagram without asking?

Not on the basis of implied consent from having the treatment done. Photos showing a client's face or identifiable features are personal data, and using them for marketing needs its own specific, opt-in consent — separate from the consent to carry out the treatment itself. Clients also need to know they can ask you to take a photo down later.

Do I need to register with the ICO if I only use booking software like Fresha or Treatwell?

Using a booking platform doesn't remove your own registration obligation — you're still the data controller for your clients' information, even though the platform processes it on your behalf. Most salons handling client data electronically need to pay the ICO's data protection fee unless a specific exemption applies; CCTV use in particular usually removes the exemption.

Does a client's signature on a patch test count as GDPR consent?

Not by itself. A patch test signature is usually evidence of a safety/liability process, not a documented, informed consent to process health-related data under GDPR's special category rules. The two are often confused because they happen on the same form.

What counts as a data breach in a salon?

Anything from a lost appointment book with client health notes in it, to a staff member emailing a client list to the wrong address, to a laptop with client records being stolen. If personal data is lost, altered without permission, or accessed by someone who shouldn't have it, it's reportable in principle — you then assess whether it meets the threshold for telling the ICO, which must happen within 72 hours if it does.

Do I need a separate GDPR policy for staff as well as clients?

Yes — staff records (contracts, bank details, National Insurance numbers, sickness records) are a separate category of personal data from client records, with their own retention logic tied to employment law rather than salon trade practice. One statement can cover both, but it needs to say so explicitly.

Is GDPRQuick a replacement for legal advice?

No. GDPRQuick helps you create and maintain practical documentation. It does not certify compliance, and your organisation remains responsible for its own policies, processes, security measures, and legal decisions.

GDPRQuick

Create and maintain your GDPR documents with GDPRQuick, the quicker way to get your documentation in order.

67 Burton Bank Lane, Stafford, England, ST17 9JJ
hello@gdprquick.com