Back to the blog
Jurisdiction: this article describes the law of the United Kingdom. Obligations differ in other countries.
UK GDPR in a beauty salon — the five mistakes that cost most

20.07.2026

UK GDPR in a beauty salon — the five mistakes that cost most

It is not about a privacy notice on the wall. It is about the lawful basis for the health questions you ask, and how long you keep the answers.

UK GDPR in a beauty salon — the five mistakes that cost most

An ICO enquiry rarely opens with your privacy notice. It opens with a question: what is your lawful basis for processing health data? Here are the five answers that most often go wrong.

1. One consent for everything

Consent to the treatment, consent to process health information, and consent to post photographs are three separate decisions. If the client ticks one box, none of them is freely given — and consent that is not freely given is not consent.

The test is simple: can a client refuse the marketing consent and still have the treatment? If not, you have a problem.

2. Health questions with no Article 9 condition

A client card asking about pregnancy, medication and skin conditions is special category data under Article 9 UK GDPR. Processing it is prohibited unless a condition applies. An ordinary Article 6 lawful basis is not enough on its own.

For a salon the condition is usually explicit consent under Article 9(2)(a), which must also meet a condition in Schedule 1 of the Data Protection Act 2018. Clinics where a regulated healthcare professional performs the treatment sit under Article 9(2)(h) instead — and there you do not collect consent, because consent is not the basis.

Decide which one you are once, in writing.

3. Before-and-after photographs

A photograph of a face is not automatically biometric data. It becomes biometric only when it is technically processed to identify someone uniquely, which a salon rarely does. But a photograph of a skin condition is health data, which is enough on its own.

Publication is a separate question. Consent to document a treatment and consent to post it on Instagram are two different permissions, and the second cannot be assumed.

4. Keeping records "just in case"

Client cards from eight years ago, because you never know. The storage limitation principle requires a defined retention period and adherence to it.

A sensible anchor is the limitation period for claims: the Limitation Act 1980 gives six years for contract and three years for personal injury running from the date of knowledge. Six years is a defensible floor. Keeping data longer than necessary is an infringement in itself — and it enlarges the harm if you are ever breached.

5. No processor contract with suppliers

Booking systems, client-record software, your accountant, cloud photo storage — each processes personal data on your behalf, and each requires a written contract under Article 28(3) UK GDPR.

This is the document an enquiry asks for first, because its absence is immediately visible.

What to do this week

Split the consents into separate boxes. Check the health questionnaire has its own explicit consent. Write down a retention period and apply it. Collect processor contracts from your suppliers. Your supervisory authority is the Information Commissioner's Office, and that is where an unhappy client's complaint lands.

This article is for information only and is not legal advice.

Protect your business today

Try Aprovo free for 30 days and leave the paperwork behind.

Start your free trial