GDPR checklist for hair salons: the five steps you actually have to complete
You became a hairdresser for the craft, not to turn into a privacy lawyer. Yet you handle personal data every single day: phone numbers, appointment history, colour formulas and the occasional note about an allergy. Most articles on the GDPR spend their time explaining what the law says. This one does something different: it walks through the five steps you actually have to carry out to get your salon in order, in the order that makes them easiest to do. You will read what each step asks of you in concrete terms, which step nearly every salon skips, how long you may keep which records, and what to do in the 72 hours after something goes wrong.
What the GDPR actually touches in a hair salon

The European data protection regulation applies to anyone processing personal data, regardless of company size. There is no lower threshold for sole traders or two-chair salons. The moment you store a name and a phone number to confirm an appointment, you are covered.
In a salon this comes down to four kinds of data. Contact details, used to book and confirm appointments. Appointment history, including which treatment happened when. Professional notes such as colour formulas and the products you used. And finally health notes: a reaction to PPD, a sensitive scalp, a pregnancy that matters for a chemical service.
That last category sits in a different legal class. Under Article 9 of the GDPR, health data counts as a special category, requiring explicit consent and stronger safeguards. The line between ordinary and special data shapes everything else you set up, so it pays to have it clear before you start the checklist. If you would first like to go through which client data you may record at all and on what basis, read the GDPR basics for beauty salons.
A paper diary is not forbidden, but it makes almost every step below harder. You cannot encrypt it, you cannot restrict it per staff member, and if it is lost or burns you will not even know exactly which records are gone. That last point is precisely what you need when a breach has to be reported.
Step 1: map which data sits where
You cannot protect what you do not know exists. So the first step is dull but essential: write down what client data you hold, where it lives and who can reach it.
Set aside half an hour and walk through your salon literally. In practice more locations turn up than anyone expects: your scheduling software, the phone at the front desk, a team chat group, an old spreadsheet on the back-office computer, the mailbox holding every appointment confirmation, and the notebook next to the till.
For each location, note three things. What data is held there, why you keep it, and who has access. That third column is where most owners get a surprise: an apprentice using the front-desk login can often reach exactly the same information as the owner, including notes never meant for them.
This inventory is not paperwork for its own sake. It gives you the list you need for step 3 (who do you share data with), step 4 (what can go) and the notification in the final section (what exactly was exposed). So keep it, and update it whenever you adopt a new system.
Step 2: write a privacy notice that matches what you do
A privacy notice tells clients what data you collect, why, how long you keep it and what rights they have. It should be easy to find: on your website, and printed at the desk if that suits you.
The trap is not that salons have no notice, but that they copy one off the internet that does not describe what actually happens. If it states you process no health data while you are noting allergies, your notice is inaccurate and you have added a problem rather than solved one. Use the inventory from step 1 as your basis: every location on that list should be reflected in the notice.
Four things belong in it as a minimum. Which data you process and for what purpose. How long you keep it. Which parties you share it with, such as your software provider and your accountant. And how a client exercises their rights: access, correction and erasure, plus where to turn if they disagree with you.
Supervisory authorities publish guidance you can follow without legal training. The Dutch authority's general explanation of the GDPR is a workable starting point, and the principles it sets out apply across the EU. Then write the notice in your own words. Text your client understands is worth more than text that reads like a contract.
Step 3: the processor agreement almost every salon forgets
This is the step most often missing in practice, and it is one with a hard legal basis. As soon as an external party processes your clients' personal data, you need a data processing agreement with them. That is not optional and not a formality: it is set out in Article 28 of the GDPR.
For a salon this quickly means four or five parties. Your salon software. Your bookkeeping package or accountant. Whoever sends your newsletter. Your online payment provider. Sometimes your web developer, if the site carries a contact form.
You do not have to draft the agreement yourself. Serious providers have one ready, often as part of their terms or as a separate document you can review and accept inside your account. If you cannot find it anywhere, ask. A provider who cannot produce one after a direct question is telling you something important about how they treat your client data.
As you read it, two points genuinely matter to you: where the data physically sits, and what happens when you leave. Storage inside the European Union saves you a great deal of work around transfers to third countries. And an agreement that you get your data back in a usable file on departure stops your client list becoming hostage to your subscription. Salonnare stores data inside the EU and makes a processing agreement available on every plan, including the free one.
Step 4: retention periods, and why one number never fits everything
The GDPR sets no exact periods. It says you must not keep data longer than necessary for the purpose you collected it for. That sounds vague, but it works out neatly in a salon.
Your financial records are the clearest case, because tax law overrides your GDPR duty to delete. How long depends on where you operate: seven years in the Netherlands, ten in Germany and France, six in Spain. Check the rule for your own country and write it down. You may not erase those records at a client's request, and that is not a refusal but a legal obligation you can simply explain.
For everything else you choose a period and record it. A common line is two years after the last visit for client files and marketing profiles. If someone has not been in for two years, you are unlikely to need the colour formula from back then. Newsletter consent tends to lapse sooner: if a subscriber has opened nothing for a year, asking again beats carrying on.
The real work is in the distinction. A client asking for erasure is entitled to have their file deleted, while their invoices must stay for tax purposes. Keeping those apart by hand goes wrong sooner or later. In a system that treats the client file and the financial records separately, you delete the file without touching your books. You can see what that client side looks like on the page about client management.
Step 5: health notes do not belong in the comments box
A PPD allergy, a scalp condition, a pregnancy: these are exactly the things you need to know before starting a chemical service. They are also exactly the things Article 9 of the GDPR covers.
The common habit is to drop them into the ordinary comments box on the client card. That is understandable, because the box is right there, but it does not meet the standard. Such a field is usually not separately encrypted and is visible to anyone opening the card, including the apprentice who only wants to confirm tomorrow's appointment.
The law asks two things here: explicit consent from the client to record this data, and safeguards proportionate to how sensitive it is. In practice that means a separate, encrypted location and access granted per staff member rather than to the whole team at once.
Salonnare provides a separate encrypted vault for this, apart from the ordinary notes field, with its own permission per staff member and a record of who viewed the data. Those last two are not luxuries: they are your evidence that access really was restricted. How to ask for and record consent, and which notes fall under Article 9, is covered in detail in the article on health data in the salon.
When it does go wrong: the 72 hours that start now
A data breach is not necessarily a hack. A stolen phone with your calendar on it, a lost notebook, an email with every client address in the cc field instead of bcc: these are everyday events and all three count.
The rule is that you report a breach to your supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to the people involved. Where the risk is high, you must inform the clients themselves as well. Those 72 hours start when you discover the breach, not when you finally understand what happened.
This is why the inventory from step 1 earns its keep: within those 72 hours you need to say whose data and how much of it was affected. Without that overview you burn valuable hours working out what was in the file in the first place.
Keep your own log of incidents too, including the minor ones you do not have to report. That is a requirement and it helps you spot patterns. For a plain-language explanation of what counts as a breach and how notification works, the Dutch government's information on privacy and personal data sets out the approach clearly. Agree with your team that anyone reports a suspicion to you immediately, because the clock starts the moment anyone in the salon notices.
What it costs to set this up properly
The five steps above mostly cost you attention once, not an ongoing budget. Most of the work sits in software that already separates ordinary from special data, so you are not policing the difference by hand every day.
Salonnare has a permanently free plan at 0 euro per month: one staff member and up to fifty bookings a month, with an online calendar, point of sale and client records. EU storage, per-staff permissions and the encrypted vault for health data are included there, so even as a solo hairdresser you can complete this entire checklist without a subscription. Starter is 29 euro per month for up to three staff with no booking limit; Pro is 59 euro per month with no limit on team size.
It is worth being clear about payment costs up front. Online and card payments run through your own Mollie or Stripe account, so the money lands directly in your own bank account and you agree the rates with your payment provider yourself. Salonnare charges no marketplace commission on new clients who book through the platform: that is zero. Online and card payments do carry a transaction fee of 0.5 percent with a minimum of 0.30 euro, on top of what your payment provider charges. That is more predictable than a percentage of every booking, but it is not nothing.
Bookkeeping runs through an export file you load into your accounting package, so you share financial data without sending your complete client file along. That lines up exactly with step 4: only what the accountant needs leaves the building.
Start with step 1 and put half an hour in the diary this week. If you would rather get the rest right straight away, you can start with Salonnare for free and set up your client records, retention periods and health notes properly from day one.
Set up your client data properly the first time
Start on the permanently free plan: one staff member, up to fifty bookings a month, EU storage, per-staff permissions and an encrypted vault for health notes. No credit card required.
Start for freeFrequently asked questions about the GDPR in hair salons
Does the GDPR apply to me as a self-employed hairdresser?
Yes. The GDPR sets no lower threshold for company size: every business processing personal data falls under it, including a sole trader with a single chair. The moment you record names, phone numbers and appointments, all five steps in this article apply to you. The size of your salon affects how much work it is, not whether you have to do it.
How long may I keep colour formulas and client records?
The GDPR names no fixed period, only that you must not keep data longer than necessary. Two years after the last visit is a common line for client files and marketing profiles. Financial records are separate and governed by tax law: seven years in the Netherlands, ten in Germany and France, six in Spain. Record your own period in your privacy notice and keep the two categories apart.
Do I really need a processor agreement with my software provider?
Yes, it is required under Article 28 of the GDPR as soon as an external party processes your clients' personal data. That covers your salon software, your bookkeeping package, your newsletter service and your payment provider. You do not have to draft it yourself, as serious providers have one available. If you cannot find it anywhere, ask for it explicitly.
Can I put client allergies in the ordinary notes field?
Better not. Allergies and scalp conditions are health data and fall under Article 9 of the GDPR, which requires explicit consent and stronger safeguards. An ordinary notes field is usually not separately encrypted and is visible to anyone who opens the client card. Use a separate encrypted vault with access granted per staff member.
What should I do if I have a data breach?
Report it to your supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to the people involved. Where the risk is high, inform the affected clients as well. Keep your own log of all incidents too, including minor ones you do not have to report. A stolen phone or an email with addresses in the cc field also counts as a breach.

