Health & wellness
Data protection for
hairdressers and beauty centres
Customer files containing allergy and skin-reaction histories hold health data subject to enhanced protection. Beauty salons must also manage customer photographs and commercial communications correctly.
Art. 9
GDPR — allergies = health data
Explicit consent
required for photos on social media
Art. 21.2
LSSI — prior customer exception
24 h
personalised proposal
Sector challenges
General obligations for hairdressers and beauty centres
Allergies and health data
A customer's allergy history, product intolerances and skin reactions are health data (art. 9 GDPR). In general, explicit consent is required depending on the circumstances of each case, along with enhanced security measures.
Before-and-after photographs
Publishing customer photos on social media, the website or catalogues generally requires explicit consent, depending on the circumstances, separate from the service contract. The customer may withdraw that consent at any time.
Online appointment software
Online booking platforms that manage customer data may act as processors; it is advisable to review each provider's terms and, where the provider acts as such, to formalise the corresponding DPA.
WhatsApp communications
Using WhatsApp for appointment reminders or promotions involves a transfer of data to Meta in the USA. This must be disclosed in the salon's privacy policy.
Employee and freelance collaborator data
Payroll, contracts and schedules for salon staff generate employment data processing with its own notification and protection obligations.
Video surveillance
If the salon has security cameras, it must comply with video surveillance obligations: an information sign, a maximum retention period of 30 days, and documentation in the RoPA (Record of Processing Activities).
The service
What the service for your salon includes
RoPA (Record of Processing Activities)
Tailored Record of Processing Activities: customers, employees, video surveillance and management platforms.
Information clauses and consent forms
Customer file with health data clause, consent for photographs, and enrolment in commercial communications.
Privacy policy and legal notice
Documentation for the salon website.
Data Processing Agreements (DPA)
DPA for booking platforms, management software and marketing tools.
Data breach protocol
Response procedure with notification within 72 hours.
Data subject rights management
Procedure for handling requests from customers and employees.
Document management platform
Access to a private platform with documents and electronic signature.
Ongoing support
Unlimited queries. Updates in response to regulatory changes.
External DPO (if applicable)
If your centre falls within the cases set out in art. 37 GDPR or art. 34 LOPDGDD, it may be required to designate a Data Protection Officer (DPO). Whether the obligation applies depends on the individual analysis of each case. Separate contract, tailored to your needs.
Do you need a proposal for your salon or beauty centre?
Tell us the type of services and the number of staff. Proposal in under 24 hours.
FAQ
Frequently asked questions about data protection in hairdressers and beauty centres
Are hairdressers and beauty centres required to comply with the GDPR?
In general, hairdressers and beauty centres that manage customer data (name, telephone number, treatment history, allergies) process personal data and are subject to the obligations of the GDPR. The precise scope depends on the type of data and the purpose of the processing; it is advisable to analyse each business individually.
Is a customer's allergy and skin-reaction history a health data item?
Yes. Data relating to allergies, product intolerances, skin reactions or skin conditions recorded on a customer's file are health data under art. 4.15 of the GDPR. Their processing requires the explicit consent of the customer or the need to protect their vital interests. The centre must document this legal basis and apply enhanced security measures.
Can a beauty salon publish before-and-after photos of its customers?
Only with the customer's explicit consent for that specific purpose. Consent to publish photos on social media or on the salon's website must be free, informed, specific and unambiguous. It cannot be inferred from the service contract. The customer must be able to withdraw consent at any time, and the photos must be deleted if they do so.
Does online appointment software collect customers' personal data?
Yes. Online appointment booking platforms (Booksy, Fresha, SimplyBook, etc.) collect customers' personal data on behalf of the salon. As a general rule, the salon acts as the data controller and the platform provider may act as a processor. The exact legal relationship depends on each provider's terms; it is advisable to review them and, where the provider acts as a processor, to formalise the DPA and inform the customer that their data are managed through that platform.
Can the salon retain a customer's file indefinitely?
No. The customer's file must be retained for as long as necessary for the provision of the service and to address possible claims (generally 3–5 years). Health data (allergies, colour technical sheets) must be retained for as long as necessary for the customer's safety, but no longer. Once the retention periods expire, data must be deleted or anonymised.
Can a beauty salon send offers and promotions to its customers via WhatsApp?
Yes, with a valid legal basis. To existing customers who have already used the service, advertising for similar services may be sent without prior consent (prior customer exception, art. 21.2 LSSI), provided that the option to unsubscribe is offered. However, the use of WhatsApp involves a transfer of data to Meta in the USA that must be disclosed in the privacy policy.
Sector resources
Learn more
Hair & beauty
Before/after photos on social media: how to capture client consent in hair and beauty salons
Publishing client before/after photos on social media in hair and beauty salons: express, specific and withdrawable consent under the GDPR and Organic Law 1/1982 on the right to own image.
7 min·Read article
Hair & beauty
Online booking apps in hair and beauty salons: the processor role
Fresha, Treatwell, Booksy and other booking apps as the centre's processors: art. 28 GDPR processing agreement, international transfers, DPF, RoPA and client information notice.
7 min·Read article
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Health & wellness
GDPR compliance
for your salon or beauty centre.
An expert analyses your activity and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.