Is my salon client data safe and GDPR compliant?
Last updated by the LushLane editorial team.
Short answer
Under UK GDPR a salon must have a lawful basis for holding client data, collect explicit consent for marketing, keep data only as long as needed, keep it secure, and be able to export or delete a client's record on request. Your booking software should make consent flags, export and deletion one-click actions.
Marketing consent is separate
A client giving you their number to book is not consent to be marketed to. Record marketing consent separately, with a date, and honour opt-outs immediately.
Right of access and erasure
Clients can ask for a copy of their data or its deletion. You need to be able to do both without contacting your software provider.
What to check in your software
UK/EU data hosting, role-based staff permissions, per-client export and delete, and a clear data processing agreement. LushLane provides all four.
Try LushLane free for 60 days. £22/month after that, 0% commission, no contract, no card needed to start.
Start 60 days freeIn short
Is my salon client data safe and GDPR compliant?
Under UK GDPR a salon must have a lawful basis for holding client data, collect explicit consent for marketing, keep data only as long as needed, keep it secure, and be able to export or delete a client's record on request. Your booking software should make consent flags, export and deletion one-click actions.