Health data and GDPR in the salon: recording Article 9 safely
An allergy to a colouring product, blood thinners before a pedicure, a skin condition ahead of a peel, or a pregnancy that decides which products are off limits: these are all pieces of information you need as a salon to treat someone safely. But they are also health data, and that falls under a strict part of the GDPR: Article 9, on "special categories of personal data".  Ordinary client data (name, phone number, treatment history) is fairly simple to keep - you can read all about that in our broader guide to [the GDPR for beauty salons](/blog/gdpr-for-beauty-salons). This article goes one level deeper and stays strictly with that one sensitive category: health data. What makes it special, when are you allowed to process it, and - most importantly - how do you record it so that your client is protected and you stay within the rules?
What is special category personal data under Article 9?
The GDPR sets aside a separate, heavier category: "special categories of personal data" (Article 9). These are data so sensitive that processing them is in principle prohibited. The category includes data about racial or ethnic origin, religion, political opinions, sexual orientation - and, most relevant for a salon, data concerning someone's health.
For a beauty salon, hair salon, nail studio, pedicurist or skin therapist, you are quickly dealing with health data the moment you record the following:
- Allergies and sensitivities - to colouring products, glue, latex or certain ingredients. - Medication - blood thinners, medicines that make the skin more sensitive, hormone treatments. - Skin conditions - eczema, psoriasis, rosacea, scars, acne. - Pregnancy - relevant because some treatments and products are then discouraged. - Other medical circumstances - diabetes before a pedicure, circulation problems, recent surgery.
The GDPR's starting point is clear: in principle you may not process these data. "Not process" means not collect, not record and not store. There are exceptions, however, and one of them is crucial for a salon: the client's explicit consent.
Why a salon needs this data anyway
If processing is in principle prohibited, why record health data at all? Because without that information you cannot guarantee a safe treatment. It forms the contra-indications: the reasons why you should not perform a treatment, or should adapt it.
A few real examples:
- A client with a known allergy to a colouring product risks a serious reaction if the wrong colour is applied. - Blood thinners can lead to more bleeding during a pedicure or certain skin treatments. - A pregnancy means certain essential oils, chemical peels or products are best avoided. - Diabetes calls for extra care during foot care because of slower healing and infection risk.
In short, this is not about curiosity or building a file, but about responsible craftsmanship. The GDPR recognises that too - you may process these data, provided you do it carefully. The key is that word "carefully". Asking for consent is step one, but just as important is how you store the data afterwards, who is allowed to see it, and how long you keep it.
The five requirements for health data
To process health data properly and lawfully, five principles come together. They apply across the EU and form the thread running through any sound GDPR policy around Article 9.
1. Explicit consent. For ordinary client data, "performance of the contract" is often enough, but for health data the bar is higher: you need explicit consent. It must be specific, informed and actively given - think of a separate checkbox or a signature on an intake form that states which data you record and for what. Consent buried in general terms and conditions does not count.
2. Data minimisation. Record only what is relevant to the treatment. Noting an allergy to a specific product is fine; building a complete medical file is not. Ask yourself for every piece of data: do I really need this to treat this client safely?
3. Encrypted and separate storage. Health data does not belong loose in the general notes field between "likes coffee" and "always parks by the door". It belongs stored encrypted and apart, so it does not simply leak out in an export, a screenshot or a glance from a colleague who has nothing to do with it. The GDPR explicitly names encryption as an appropriate security measure.
4. Restrict access. Only the staff who actually carry out the treatment need to see the health notes. A front-desk employee who only schedules appointments does not need them. Role-based permissions per staff member keep sensitive information with the right people.
5. Retention period. Keep health data for as short a time as possible. If a client has not been in for years, there is no reason to keep their allergies or medication. A fixed retention period with automatic deletion prevents you from unknowingly building a growing archive of sensitive data.
Why an ordinary notes field is not enough
Most salon software has a notes field on the client. Handy for "always wants the same stylist" or "was happy with the new colour". But that very convenience makes the field unsuitable for health data.
A general notes field is, after all:
- Visible to everyone who opens the client profile, regardless of role. - Not separately encrypted - it sits in the same row as the rest of the client data. - Part of exports and backups without any separate protection. - Without a consent record - you record nowhere that the client agreed to storing precisely these sensitive data. - Without a retention period - the allergy from five years ago simply stays.
For ordinary remarks that is fine. For an allergy, medication use or pregnancy it does not meet Article 9. What you need is a separate, shielded place - a vault - that has the five requirements above built in.
Salonnare's encrypted health vault
Salonnare was deliberately designed for this. Alongside the ordinary client notes field there is a separate, encrypted health vault, specifically for Article 9 data. That keeps the sensitive information strictly apart from day-to-day notes.

What that vault offers:
- AES-256 encryption. Health notes are stored with AES-256-GCM envelope encryption, separate from the ordinary client data. Even within the system they are not simply readable. - Consent recorded. Every health note has a record of the client's consent (consent events), so you can demonstrate that the client agreed - a core GDPR requirement. - Role-based permissions. Only staff with the right authorisation see the health notes. Anyone without it simply does not see the vault. - EU servers. All client data, including the health vault, sits on servers within the EU. - Automatic retention period. The vault has an automatic retention period (by default around 12 months after the last activity), so sensitive data does not linger forever.
That is how you process health data the way Article 9 intends: with consent, encrypted, shielded and temporary - without having to build a technical security plan yourself.
Set up properly in a few steps
Moving to a clean way of working with health data takes less time than you might think. These steps keep it manageable.
Step 1 - Create an intake form with a separate consent checkbox. Put health questions (allergies, medication, skin conditions, pregnancy) on a digital intake form with an explicit checkbox: the client gives consent to record these data for a safe treatment.
Step 2 - Record the answers in the health vault, not in the ordinary notes field. That keeps them encrypted and shielded.
Step 3 - Set role-based permissions per staff member. Decide who may see the health notes. Usually that is the person doing the treatment, not the front-desk employee.
Step 4 - Keep it minimal. Record only what you really need for the treatment, in short, factual wording.
Step 5 - Rely on the automatic retention period. Let the system clear out outdated data instead of tracking it by hand.
Step 6 - Link it to your [client management](/features/client-crm). That way you see at a glance for each client whether there are treatment-relevant points of attention, without the sensitive content being visible to everyone.
Conclusion: sensitive data belongs in a vault, not a note
Health data is the most sensitive information that passes through your salon. That is why the GDPR treats it separately: processing is in principle prohibited, unless you have explicit consent and keep the data minimal, encrypted, shielded and temporary. An allergy or medication use does not belong in the ordinary notes field, but in a separate, secure place.
Salonnare has that place built in: an encrypted health vault with consent recording, role-based permissions per staff member, EU storage and an automatic retention period. You start for free - the permanently free plan (Free, €0 per month, for 1 staff member and 50 bookings per month) lets you try everything. As your salon grows, you move to Starter (€29) or Pro (€59) per month, with a fixed price and no commission per booking, payments via local methods to your own account, an interface in five languages, and both a web app and an installable app.
Want to record health data properly and safely from today? Create a free account and set up the health vault before you take in your next client.
Frequently asked questions
What is special category personal data under Article 9 GDPR?
Special category personal data is extra-sensitive data for which the GDPR sets a strict regime in Article 9. It includes data about health, racial or ethnic origin, religion, political opinions and sexual orientation. For a salon, health data is the most relevant: allergies, medication, skin conditions and pregnancy. Processing this category is in principle prohibited, unless you have a valid exception - for a salon usually the client's explicit consent.
Can I as a salon record clients' allergies and medication?
Yes, but only with explicit consent and if it is relevant to the treatment. An allergy, blood thinner or skin condition can determine whether a treatment is safe, so you may record it as a contra-indication. The condition is that the client actively agreed (for example via a checkbox on an intake form), that you record no more than necessary, and that you store the data encrypted and shielded.
Can I just put it in the ordinary client notes field?
No, that is not wise. A general notes field is visible to everyone who opens the client profile, is not separately encrypted, comes along in exports and backups, and has no consent record or retention period. Health data belongs in a separate, encrypted vault with restricted access. In Salonnare that health vault sits apart from the ordinary notes field, with AES-256 encryption, role-based permissions and an automatic retention period.
How long may I keep clients' health data?
As short as possible. The GDPR does not prescribe an exact term for health data in a salon, but the principle of storage limitation means you delete it as soon as it is no longer needed. If a client has not been in for a long time, there is no reason to keep their allergies or medication. An automatic retention period - in Salonnare by default around 12 months after the last activity - prevents you from unintentionally building a growing archive of sensitive data.
What exactly is "explicit consent"?
Explicit consent is a heavier form of consent that the GDPR requires for special category personal data. It must be freely, specifically, informed and actively given: the client knows exactly which health data you record and why, and consciously says yes to it. That can be done, for example, with a separate checkbox or a signature on an intake form. Consent buried in general terms and conditions, or pre-ticked, does not count.

