Certix

Health & wellness

Data protection for
hairdressers and beauty centres

Customer files containing allergy and skin-reaction histories hold health data subject to enhanced protection. Beauty salons must also manage customer photographs and commercial communications correctly.

Art. 9

GDPR — allergies = health data

Explicit consent

required for photos on social media

Art. 21.2

LSSI — prior customer exception

24 h

personalised proposal

Sector challenges

General obligations for hairdressers and beauty centres

Allergies and health data

A customer's allergy history, product intolerances and skin reactions are health data (art. 9 GDPR). In general, explicit consent is required depending on the circumstances of each case, along with enhanced security measures.

Before-and-after photographs

Publishing customer photos on social media, the website or catalogues generally requires explicit consent, depending on the circumstances, separate from the service contract. The customer may withdraw that consent at any time.

Online appointment software

Online booking platforms that manage customer data may act as processors; it is advisable to review each provider's terms and, where the provider acts as such, to formalise the corresponding DPA.

WhatsApp communications

Using WhatsApp for appointment reminders or promotions involves a transfer of data to Meta in the USA. This must be disclosed in the salon's privacy policy.

Employee and freelance collaborator data

Payroll, contracts and schedules for salon staff generate employment data processing with its own notification and protection obligations.

Video surveillance

If the salon has security cameras, it must comply with video surveillance obligations: an information sign, a maximum retention period of 30 days, and documentation in the RoPA (Record of Processing Activities).

The service

What the service for your salon includes

RoPA (Record of Processing Activities)

Tailored Record of Processing Activities: customers, employees, video surveillance and management platforms.

Information clauses and consent forms

Customer file with health data clause, consent for photographs, and enrolment in commercial communications.

Privacy policy and legal notice

Documentation for the salon website.

Data Processing Agreements (DPA)

DPA for booking platforms, management software and marketing tools.

Data breach protocol

Response procedure with notification within 72 hours.

Data subject rights management

Procedure for handling requests from customers and employees.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO (if applicable)

If your centre falls within the cases set out in art. 37 GDPR or art. 34 LOPDGDD, it may be required to designate a Data Protection Officer (DPO). Whether the obligation applies depends on the individual analysis of each case. Separate contract, tailored to your needs.

Do you need a proposal for your salon or beauty centre?

Tell us the type of services and the number of staff. Proposal in under 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in hairdressers and beauty centres

Are hairdressers and beauty centres required to comply with the GDPR?

In general, hairdressers and beauty centres that manage customer data (name, telephone number, treatment history, allergies) process personal data and are subject to the obligations of the GDPR. The precise scope depends on the type of data and the purpose of the processing; it is advisable to analyse each business individually.

Is a customer's allergy and skin-reaction history a health data item?

Yes. Data relating to allergies, product intolerances, skin reactions or skin conditions recorded on a customer's file are health data under art. 4.15 of the GDPR. Their processing requires the explicit consent of the customer or the need to protect their vital interests. The centre must document this legal basis and apply enhanced security measures.

Can a beauty salon publish before-and-after photos of its customers?

Only with the customer's explicit consent for that specific purpose. Consent to publish photos on social media or on the salon's website must be free, informed, specific and unambiguous. It cannot be inferred from the service contract. The customer must be able to withdraw consent at any time, and the photos must be deleted if they do so.

Does online appointment software collect customers' personal data?

Yes. Online appointment booking platforms (Booksy, Fresha, SimplyBook, etc.) collect customers' personal data on behalf of the salon. As a general rule, the salon acts as the data controller and the platform provider may act as a processor. The exact legal relationship depends on each provider's terms; it is advisable to review them and, where the provider acts as a processor, to formalise the DPA and inform the customer that their data are managed through that platform.

Can the salon retain a customer's file indefinitely?

No. The customer's file must be retained for as long as necessary for the provision of the service and to address possible claims (generally 3–5 years). Health data (allergies, colour technical sheets) must be retained for as long as necessary for the customer's safety, but no longer. Once the retention periods expire, data must be deleted or anonymised.

Can a beauty salon send offers and promotions to its customers via WhatsApp?

Yes, with a valid legal basis. To existing customers who have already used the service, advertising for similar services may be sent without prior consent (prior customer exception, art. 21.2 LSSI), provided that the option to unsubscribe is offered. However, the use of WhatsApp involves a transfer of data to Meta in the USA that must be disclosed in the privacy policy.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Health & wellness

GDPR compliance
for your salon or beauty centre.

An expert analyses your activity and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.