Compliance · 7 min read
GDPR for booking businesses, in plain English
What you must do, what you should do, and what is quietly optional, for a salon or studio holding client data.
Tom Whitfield · Legal, Cover Beauty · 18 February 2026

GDPR turned eight this year, and the ICO has quietly moved from 'raising awareness' to 'issuing meaningful fines'. A salon holding email addresses, phone numbers, and treatment histories is holding personal data, and in the case of medspa consultation notes, special-category data. Here is what you actually need to have in place.
Must-have
- A privacy notice on your website that names what data you hold, why, and how long.
- A lawful basis for marketing, contract, consent, or legitimate interest, and unsubscribe on every email.
- A written data-retention policy. Two years post-last-visit is a reasonable default.
- A signed data-processing agreement with every software vendor that touches customer data.
Should-have
- A simple process for handling a customer's data-access request (30 days to respond).
- Two-factor authentication on every admin account.
- Regular backups, held separately from your live system.

