Client data and GDPR: what a master may keep and for how long

Phone numbers in chats, allergies in a notebook, photos in your gallery. What GDPR means for a master working alone, how long to keep data and what to do when a client asks you to delete it.

Founder of RINDIQ
Published 9 min read
Latviešu versija

In short

  • Contact details and bookings need no consent, but photos, marketing and health data do.
  • GDPR sets no single period: decide your own retention rule and write it down.
  • A client’s request about their data must be answered within one month.
Contents 8 parts
  1. 01A notebook, WhatsApp and 3,000 photos on your phone
  2. 02What personal data is in a master’s work
  3. 03Why you’re allowed to keep it
  4. 04How long to keep it
  5. 05Test yourself: allowed or not
  6. 06When a client asks about their data
  7. 07Your data in order in half an hour
  8. 08How it works in RINDIQ

A notebook, WhatsApp and 3,000 photos on your phone

A client's phone number in a chat, a note saying “allergic to latex” in a notebook, before-and-after photos in the phone gallery among family pictures.That is what almost every master's client data looks like. And the GDPR, the EU data protection regulation, applies to it too, even if you work alone.

That's no reason to panic. Most of the rules are common sense: keep only what you need, for as long as you need it, and so that others can't see it. This article covers what you may keep, for how long, what to do when a client asks you to delete their data, and a list to put it all in order in half an hour.

What personal data is in a master’s work

Anything that identifies a particular person:

  • Contact details: name, phone, email, Instagram profile.
  • Visit history: when, which treatment, how much they paid, whether they came.
  • Notes: “wants shorter nails”, “comes with a child”, “runs late”.
  • Photos: especially if a face or something else recognisable is visible.

A separate, more strictly protected group is health data: allergies, skin conditions, pregnancy, medication. Cosmetologists and lash artists often need it for a safe treatment, but it has special rules, covered below.

The GDPR requires a reason for each kind of data. In a master's work there are usually four:

  1. Providing the service. Name, phone and appointment time are needed to make a booking at all. No separate consent is needed for that.
  2. A legal obligation. Receipts, invoices and payments must be kept for accounting for as long as the law requires.
  3. Consent. For marketing messages, work photos on Instagram where the client can be recognised, and publishing reviews. The client can withdraw consent at any time.
  4. Explicit consent for health data. If you note allergies or contraindications, the client must know and agree, ideally in writing on a form before the first treatment.

And one more principle that solves half the problems: don't ask for what you don't need. An ID number, date of birth or home address isn't needed for a manicure. If the client is under 18, read A client under 18: do you need a parent's consent?.

How long to keep it

The GDPR doesn't set one period. It says: no longer than the purpose needs. So the best approach is to decide a rule yourself and write it down. For example:

  • Contact details and visit history: while the client keeps coming, and for a set time after the last visit, for example two years. Then delete them.
  • Accounting records: as long as the law requires. Check the period with your accountant.
  • Health form: while the client comes for treatments that need it.
  • Photos for publishing: while consent stands. If the client withdraws it, the photo comes down.
  • Instagram and WhatsApp chats:as briefly as possible. They aren't meant for storing data.

The periods here are examples, not legal rules. What matters is that you have a rule, follow it and can explain it if a client asks. Why chats are a poor place for bookings is covered in Bookings through Instagram and WhatsApp: where clients get lost.

Test yourself: allowed or not

Six everyday cases. The answers are based on general GDPR principles:

Quick quiz

Client data: allowed or not?

  1. Noting a client’s phone number so you can remind them about the visit.

  2. Posting a before-and-after photo on Instagram that shows the client’s face.

  3. Writing “allergic to lash glue” on the client card.

  4. Sending all your clients a special offer from your personal phone.

  5. A client asks you to delete their data, but their receipts must be kept for accounting.

  6. A lost phone with no passcode, holding all client contacts and photos.

When a client asks about their data

A client has the right to:

  • Know what data you hold about them, and get a copy.
  • Correct data that is wrong.
  • Ask you to delete data that is no longer needed and that the law doesn't require you to keep.
  • Opt out of marketing messages at any time.

You must reply to such a request within one month. In practice it takes a few minutes if all of the client's data is in one place rather than scattered across a notebook, chats and a gallery.

Ready-to-use message

Reply to a request to delete data

Hello [name], thank you for your message. I have deleted your contact details, notes and photos. Only the payment records the law requires me to keep for accounting remain. They aren’t used for anything else. If you ever want to book again, you can do so as a new client.

Replace the parts in brackets with your own.

Your data in order in half an hour

You don't have to do everything at once. Start with this list and tick off what is already done:

Check yourself

Client data in order

0 of 9

If your client contacts are only on Instagram right now, think about what happens if the account is blocked. That is covered in Your Instagram account is gone. Your clients aren't.

How it works in RINDIQ

If you run your bookings in RINDIQ, you are the data controller and RINDIQ is the processor that stores the data on your behalf. There is a data processing agreement between us, which is part of the terms of use and is publicly available.

  • On the booking form, the client sees a link to the privacy policy and chooses whether to get reminders.
  • Client notes and the photos attached to them are visible only to your team after logging in. They have no public links.
  • The client agrees separately to a review being published, and the consent text lists exactly what will be published: name, number of visits, text and photos.
  • If a client asks for a copy of their data, you can export your client list (on the Professional and Business plans). If a client asks for their data to be deleted, write to us and we'll help, as the data processing agreement provides.
  • Review request emails carry a link that lets the client opt out of them with one click.

Try RINDIQ free for 14 days

No card needed. You can set up your booking page and deposits in about 5 minutes.