GDPR for salons and service businesses
You do not need consent to manage appointments and issue invoices, because that processing rests on contract and legal obligation. You do need consent for marketing messages and for health data. With your software vendor you need a signed data processing agreement and a known list of subprocessors.
A salon, massage studio or clinic processes personal data all day long: a name and phone number for the appointment, a service history, sometimes health information as well. GDPR does not forbid any of this. It only requires that for each kind of processing, you know which legal basis you are relying on.
This article is not legal advice. It is a practical framework that will let you ask your software vendor and your lawyer the right questions.
You do not need consent for appointments
The most common mistake is collecting consent for something where consent is the wrong basis. When a customer books an appointment, you enter into a contractual relationship. Processing their name, phone number and chosen service is necessary to perform that contract, so no separate consent is needed. Asking for it would in fact be misleading, because consent can be withdrawn at any time and you cannot deliver the appointment without the data.
The same applies to invoices. You keep those because the law requires it, not because someone consented.
When you genuinely need consent
Consent is the right basis in three cases:
- Marketing messages. A promotion or an invitation to book again is not part of delivering an existing booking. That requires separate, freely given consent that can also be withdrawn.
- Health and other sensitive data. Allergies, diagnoses, pregnancy, injuries. You may keep these where you have explicit consent or another appropriate basis for healthcare activity.
- Photographs of the client. Before-and-after pictures are personal data. Publishing them on social media needs its own consent, separate from consent to store them.
The important part is that these consents are separate. One combined checkbox covering everything is not valid.
Where a reminder ends and an advert begins
The line is usefully simple: a message about an appointment that already exists is part of delivering the service. A message trying to create a new appointment is marketing.
| Message | Basis |
|---|---|
| Booking confirmation | Contract |
| Reminder 24 hours before | Contract |
| Reschedule or cancellation notice | Contract |
| "It has been a while, shall we book you in?" | Consent |
| Promotion or discount | Consent |
This is why it matters that your software separates transactional messages from campaigns. If everything goes out from one list, your first marketing message will breach the rules by accident. The Appointment reminders page describes how ours are designed.
How long to keep data
GDPR does not name a number of years; it states a principle. Keep data only as long as you need it. In practice that means three different periods:
- Invoices and tax records. The retention period comes from tax law rather than GDPR, and it is considerably longer than the others.
- Appointment history and client notes. As long as it is genuinely useful for treating that client. Healthcare activities have their own prescribed periods.
- Marketing list. Until consent is withdrawn, or after a reasonable period of inactivity.
Write these periods down. A retention policy that exists only in the owner's head does not count during an inspection.
What to require from your software vendor
The moment you enter client data into hosted software, that vendor becomes your processor while you remain the controller and stay accountable. So check five things before you commit:
- A data processing agreement. Signed, not merely mentioned on a page.
- A list of subprocessors. Who else sees the data: the hosting provider, the SMS gateway, the payment provider.
- The hosting region. Where the servers physically sit and whether data leaves the EU.
- Export and deletion. Whether you can export and erase a client's data without raising a support request.
- Breach notification. Within what period the vendor commits to telling you about a security incident.
Calendra publishes its data processing agreement and subprocessor list openly, with no login. That is a useful benchmark for any vendor: if you cannot find the documents yourself, note how long it took to get them.
Client rights you must be able to honour
A client has the right to access their data, correct it, erase it and take it with them. In practice that means being able to produce everything you hold about one person within a reasonable time. If the data lives in a paper diary, three spreadsheets and WhatsApp, you cannot. Beyond the time saved, that is one of the more serious arguments for keeping everything in one system.
There is more on how requests work with us on the Data rights page.
Three things to do this week
First, check that marketing messages rest on a separate consent rather than a general checkbox. Second, write down retention periods for invoices, client records and marketing. Third, go and find the data processing agreement for the software you use today. If you cannot locate it in five minutes, start there.
Try Calendra free for 14 days
Online booking, an appointment calendar, reminders and invoicing in one place. No credit card and no commitment.