ClaudIA
The salon blog

GDPR in your salon: which client data you're allowed to keep

Updated 2026-08-02 · 4 min read

«GDPR is for big companies.» That myth, so widespread in the trade, lasts exactly until the first complaint from a client annoyed about a photo on Instagram or an unasked-for promotional WhatsApp — data protection authorities fine businesses of every size, and the smallest fines hurt a salon's till badly. The good news: complying in a hair salon is simple once you understand four rules. Here they are, in front-desk language.

One note on scope, because it changes who you'd be dealing with and nothing else: the rules below are the GDPR, which applies across the whole EU, and the UK GDPR keeps the substance the same. What changes is which authority supervises you — the AEPD in Spain, the CNPD in Portugal, the ICO in the United Kingdom.

Rule 1 — The client record: you can (and should), as long as you tell them

Keeping a name, a phone number, a service history, her exact colour formula and her preferences isn't just legal: it's good professional practice. The legal basis is the commercial relationship — you don't need a signed contract to note down that Carmen wears a 7.3 with a golden tone. What you do need is to inform: a visible notice or a line at the foot of the receipt or confirmation message («Your details are used to manage your appointments and your history. More info and opt-out: [your policy]»), and to have that basic privacy policy written down. The guiding principle is minimisation — keep what you use to look after her better; her marital status or where she works have no business on the record.

Rule 2 — Allergies and health: the delicate zone

Sensitivity to ammonia or a nickel allergy are health data — a special category under the GDPR. You can and should record them (they protect the client!), but with three precautions: explicit consent when you collect them («shall I note that on your record so we never forget it?» — and her yes, better in writing or in the chat), access only for whoever is treating her, and use only for that. Never in marketing («offer for sensitive scalps!» crosses every line at once).

Rule 3 — Photos: your Instagram needs permission

Your client's face is personal data. A before-and-after without demonstrable consent is the most common GDPR breach in the whole beauty sector — and the easiest to avoid.

The right process is asking permission and keeping the proof: a WhatsApp message («Do you mind if I put your new look on our Instagram? It came out spectacular!») with her «of course!» saved counts; verbal permission nobody can prove doesn't. Respect the scope (if she agreed to a shot from behind, don't post one from the front) and respect second thoughts: if one day she asks you to delete it, it gets deleted without debate — consent is always revocable.

Rule 4 — Commercial WhatsApp: clients yes, spam never

Confirmations, appointment reminders and notices about her service: no problem at all, that's the normal relationship. Marketing messages to actual clients about services similar to the ones they already buy: allowed, as long as you inform them and opting out is easy («reply STOP and we won't message you again» — and honour it religiously). Campaigns to numbers that aren't clients, or bought lists: forbidden and pursued. The golden rule is common sense: only write to somebody who has a reason to be pleased to hear from you.

Your one-afternoon checklist

ClaudIA's client record keeps what you should, the way you should — with data protection built in

The GDPR properly understood isn't against your business: it's squarely in favour of what already makes a good salon special — respect for the people whose hair secrets (and non-hair secrets) you look after every day.

Keep reading

Ready to let ClaudIA take over?

Ask for a demo and we'll show you how it works with your own salon. No commitment.