Table of contents
GDPR-compliant hairdressing software: which salon data is protected, what the contract with the provider has to settle, and how access and deletion requests work in practice.
A hair salon holds far more personal data than most owners realise. The client record carries a name, a phone number and an appointment history, and alongside them colour formulas, notes on hair condition, references to earlier reactions and now and then photographs. Every one of those entries is a processing operation for which the salon is responsible — including when the software is run by somebody else.
Which law says so depends on where you are. The GDPR applies if your salon is established in the EU or the EEA, and it reaches your data when it is processed there; the United Kingdom runs its own closely modelled version alongside the Data Protection Act 2018. A salon in Canada answers to PIPEDA, one in Australia to the Privacy Act, one in Singapore to the PDPA, and several US states now have consumer privacy statutes of their own. The wording differs, but the structure this article works with holds in all of them: the salon decides what is collected and stays answerable for it, the software provider processes it on the salon's instructions, and the split has to be written down. This is not legal advice — for a binding answer about your own business, your data protection authority or a qualified adviser is the right address.
1. What counts as personal in a salon, and what may be protected more strictly
Personal data is any detail that can be attributed to an identifiable person. In a salon that covers considerably more than the address list: the phone number used for the reminder, the email address from the online booking, the appointment history, the note reading “often arrives late”, the record of who served the client last — and the colour formula itself.
One small group of entries deserves particular care: references to allergies, intolerances, skin conditions, a pregnancy or a course of chemotherapy. Details of that kind can be health data, and most privacy regimes hold them to a stricter standard than a phone number — under the GDPR they are “special category” data, and comparable carve-outs exist in the other laws named above. Recording them in a salon is not forbidden, and for a proper consultation it is often necessary. But they need an explicit basis, and they should not end up casually in an open notes field.
A practical first step costs nothing: go through the fields of your client record once and mark which of them you genuinely need for the consultation. What you do not need does not have to be collected — and what is never collected can neither be stored wrongly nor disclosed by accident.
The salon stays responsible for the client data, even when the software belongs to somebody else.
2. Colour formulas and notes: how long they should stay in the system
The retention question arises differently in a salon than in most businesses, because the data stays useful for years. A colour formula from three years ago is an asset for a regular client, not an old record. That is precisely why salons rarely delete anything — and precisely why client files fill up with people who have not been in for seven years.
What helps is a rule you set once and then apply: how long does the record of a client who no longer comes stay in the system? Two years after the last appointment is a common order of magnitude for consultation data. Receipts and invoices sit under tax retention periods that run independently of that, differ from country to country, and are not deleted along with the client file. Which period is appropriate for your business is best settled with your accountant, and where health details are involved, with qualified advice.
Then check against the system whether such a rule can be carried out at all. Does it show you inactive client records? Can a single record be deleted without making the past appointments attached to it unusable? What a salon record has to hold in the first place is covered in digital client records for hairdressers; a system that only knows how to keep everything turns the tidying into manual labour.
3. The processor contract, the storage location and the sub-processors
As soon as software stores client data for you, the provider is processing it on your behalf. That relationship needs a written contract — under the GDPR a data processing agreement, under the other regimes something with a different name and much the same job. It is not a formality to be supplied later: without it the processing has no contractual basis, and in a review it is the first document anybody asks for.
So ask about three things before you decide. First: does that contract exist, and can it be read without a call to sales? Second: where do the servers stand, and does that location satisfy the law that applies to you? Salon Wizard hosts within Germany, which answers the question for salons that need their data inside the EU — but it is a question you should put to every provider you look at, in exactly that form. Third: which sub-processors are involved? Hardly any provider runs everything itself; hosting, email delivery, SMS delivery and error logging often run through further service providers, and those belong on a list you are able to see.
One point is regularly overlooked: the tools you use yourself around the software process client data too. Sending appointments through a messenger, the client list in a spreadsheet on a private laptop, the photograph in the camera roll of a work phone. In practice those side channels are more often the weak point than the salon software ever is.
Related articles
4. Who on the team may see which client data
In a one-person salon the question barely surfaces; in a team it turns concrete quickly. Does the Saturday assistant on reception need to see the note that a client should not be given a particular treatment after chemotherapy? Do apprentices need access to the full appointment history of every client, or only to the current day?
The basic rule is simpler than it sounds: each person sees what they need for their work, and no more. In practice that means a system has to distinguish roles — reception, team, management — and those roles have to be changeable when somebody takes on a different job.
The case that most often goes wrong in practice is a departure. When somebody leaves the salon their access has to be closed — but the past must not be deleted with it, or old appointments can no longer be attributed to anybody. So settle in advance whether the system can deactivate an account without taking the history along. And decide who performs that step: an account nobody thinks about on the day notice is given often stays open for months.
5. When a client asks for access, correction or deletion
These requests are rare, but they come — usually by email, occasionally spoken at reception. One client wants to know what the salon has stored about them, another wants to be deleted, a third wants a wrong phone number corrected. Most privacy laws put a deadline on the answer; under the GDPR it is a month, extendable in complicated cases. And the salon is the party that has to answer, not the software provider.
So prepare two things while no request is on the table. First: know where this client's data sits — in the client file, in the calendar, in the message history, in the bookkeeping. Second: can you pull a complete disclosure out of the system without writing it up by hand? An export per client record saves the decisive effort here.
On deletion, the caveat from section two applies: not everything may go. Invoice-relevant details fall under tax retention periods and stay, even when the consultation data is removed. How those two requirements fit together in an individual case is exactly the question a qualified adviser or the competent authority can answer bindingly — a guide like this one can only show you where it arises.
Data protection in a hair salon is less a question of the right software than a question of a few settled rules: which fields are collected, how long they stay, who sees them, and how a request is answered. Good salon software makes those four rules workable instead of turning them into manual labour. Responsibility for the rules themselves stays with the salon — and for the binding reading in an individual case, with the authority that supervises you.
Online booking for your salon?
Win more customers and reduce no-shows with your own booking page for hairdressers.