Short answer
Under UK law, GDPR means you must collect, store, and use client personal data securely. You're required to obtain explicit consent for sensitive information like skin tests, provide clients access to their files on request, and delete records when asked, unless insurance policies require you to retain the files.
Client data and consent
Sensitive data requires explicit consent. In a hair salon, this includes allergy alerts, scalp conditions, and skin test records. You can't assume consent through silence or a pre-ticked box on a form; the client must actively opt in. Under UK rules, you need a clear record of when and how they agreed.
Luminate has GDPR tools that help you track and flag skin test records. If you migrate from another system, the support team can transfer your colour test records and signed consent signatures to ensure you keep your historical records intact.
The right to access and export
Under GDPR, clients can ask to see the personal information you hold on their files. This is called a Subject Access Request, and you have one calendar month to hand over the files without charging a fee. If your salon software makes this difficult, you'll end up copying and pasting notes into documents for hours. Luminate makes it simple. Owners and administrators can export a single customer's record as a ZIP file containing JSON or CSV data, making it easy to send the files straight to the client. All of your salon data is hosted securely in the UK and EU, using encryption and regular backups to protect customer details.
The right to erasure versus insurance
A client has the right to ask you to delete their personal details from your system, which is known as the right to erasure. But in a salon, you can't always delete everything immediately. Salon insurance policies in the UK require you to keep skin test records, colour history, and treatment dates for several years to protect you against future injury claims. If a client asks to be deleted, check with your insurer or a professional adviser first. You'll need to keep their chemical and skin test history for insurance purposes, even if you delete their phone number, email address, and marketing preferences from the active database.
Marketing and communication consent
Sending marketing campaigns or birthday messages requires clear, active permission. You're only allowed to send marketing texts or emails to clients who have specifically opted in to receive those messages. Pre-ticked boxes are illegal, and you can't assume consent just because someone booked a haircut last week. You must also give clients a simple way to opt out of future marketing. Ensure your records are updated immediately when a client changes their preference, so you don't send unwanted messages by mistake.
What this means for your salon
To keep your salon compliant, review your client forms and make sure you're getting active consent for skin tests and marketing. Check with your insurer to find out exactly how long you need to keep chemical treatment cards, and use software that makes exporting or updating data simple. If you're switching from another system, the Luminate support team can safely import your customer records and existing consent history to keep things running smoothly.