First page of the Client privacy notice template

Client privacy notice

Your plain-English GDPR notice for clients — you as the data controller.

£7 inc. VAT — yours forever, no subscription.Or get it in the Salon & Beauty pack — £29.

Type your business name and the preview updates in seconds — the real PDF, editable on screen or printable to fill in by pen. Nothing about your business leaves your browser.

What you need to know

The plain-English guidance that comes with this document.

  • Salons hold real personal data — this is your GDPR notice for clients. Names, contact details and, importantly, health information (allergies, conditions, patch tests) are all personal data, and health details are "special category" data with extra protection. UK GDPR says you must tell clients, in plain language, what you hold and why. This notice does that — display it and/or hand it over, and tick the "I've seen the privacy notice" box on the consultation card.
  • You're the "data controller". That's why this notice carries your name and address — a privacy notice has to identify who's responsible for the data. The data contact is usually just you; if you put a name and email in the Builder it's printed, and if you leave it blank there's a line to write it on.
  • "We don't share it with anyone" is rarely true — so the notice doesn't say it. If you use online booking (Fresha, Treatwell and the like), a card machine, or accounting software, those companies process client data for you. That's fine and normal, but the notice has to admit it. Only name them if you want to; "our booking system" is enough.
  • The 3-year retention is deliberate. A client has 3 years to bring a personal-injury claim (longer for a child — until they turn 21), so that's how long your insurer will want the consultation, patch test and treatment records to exist. Keep them that long, then shred or delete them. Contact details for marketing don't need to hang around as long as treatment records.
  • Health data needs a clear basis — usually the client's permission. Because health information is sensitive, be able to show why you hold it (to treat safely) and that the client agreed. The consultation card's "the information I've given is accurate and I'm happy to go ahead" plus this notice covers the everyday case; keep it honest and proportionate — only collect what you actually need.
  • Keep it secure, and don't keep it forever. Lock paper cards away or use a password-protected system, don't leave client details on the reception desk, and clear out records you no longer need. A shoebox of old client cards anyone could read is a breach waiting to happen.
  • Marketing and photos are opt-in. Texting or emailing clients offers needs their consent, and an easy way to opt out. Posting a client's before-and-after on Instagram needs their permission too — the consultation card captures both.
  • Clients can ask to see their data. If a client asks for a copy of what you hold (a "subject access request"), you generally have to provide it, free, within a month. It's rare in a salon, but know it can happen.
  • Applies UK-wide. UK GDPR and the Data Protection Act apply across the whole UK. The ICO has free, small-business-friendly guidance if you want to go further.

Please note: This is a template for guidance only. Adapt it to your business and check it against current law and your insurance requirements. It is not legal advice.