Skip to content
The journal

Compliance · 7 min read

GDPR for booking businesses, in plain English

What you must do, what you should do, and what is quietly optional, for a salon or studio holding client data.

Tom Whitfield · Legal, Cover Beauty · 18 February 2026

GDPR turned eight this year, and the ICO has quietly moved from 'raising awareness' to 'issuing meaningful fines'. A salon holding email addresses, phone numbers, and treatment histories is holding personal data, and in the case of medspa consultation notes, special-category data. Here is what you actually need to have in place.

Must-have

  • A privacy notice on your website that names what data you hold, why, and how long.
  • A lawful basis for marketing, contract, consent, or legitimate interest, and unsubscribe on every email.
  • A written data-retention policy. Two years post-last-visit is a reasonable default.
  • A signed data-processing agreement with every software vendor that touches customer data.

Should-have

  • A simple process for handling a customer's data-access request (30 days to respond).
  • Two-factor authentication on every admin account.
  • Regular backups, held separately from your live system.

Run your studio on Cover Beauty.

Bookings, memberships, gift cards, POS and marketing, in one calm platform.

See Cover Beauty for Business