GDPR for barbers: what you actually need to know
If you keep a list of clients, you are processing personal data. It makes no difference whether it lives in a notebook or an app.

The first thing worth clearing up is that the GDPR is not only about large companies. It applies to anybody who collects data about identifiable people for work, and a barber with a list of phone numbers is squarely inside that. The good news is that the obligations scale: nobody expects of a barbershop what they expect of a bank.
The data you hold, probably without thinking about it
- The name of whoever booked.
- A phone number, and sometimes an email address.
- Appointment history, meaning when they came and who cut their hair.
- Service notes, for example the colour used or a flagged allergy.
- Before and after photos, if you take them.
Two entries on that list deserve extra care. Notes about allergies or scalp conditions can count as health data, which carries stronger protection. And client photos, once published, need explicit and separate consent: somebody sitting in your chair has not thereby agreed to appear on your Instagram.
Consent, without the jargon
You do not need consent for everything. To manage the appointment and send the booking reminder you need the data in order to deliver the service the client asked for, and that is enough on its own. You do need clear, separate consent for two things: sending promotions, and publishing photos.
Separate means they cannot share a tick box. Somebody booking must be able to say yes to the appointment and no to the newsletter without one blocking the other.
What you need to have in place
- A privacy notice saying what you collect, why, how long you keep it and who you pass it to.
- Consent collected separately for marketing and for photos, with the date it was given.
- A way to delete a client's data on request, and to hand them a copy of it.
- A list of the suppliers who process data on your behalf, such as your software or your messaging provider.
- A rule for how long you keep the history of clients who stopped coming.
Suppliers are processors, you stay the controller
When you use a booking system, that data sits on servers that are not yours. The supplier acts as a processor and has to sign an agreement with you saying so. You, though, remain the controller: it is on you to know where your clients' data ends up and to answer for it if something goes wrong.
Two questions are worth asking before picking any tool: which country the servers are in, and what happens to the data if you stop using it.
If something goes wrong
If data is lost or ends up in the wrong hands, the breach has to be reported to the supervisory authority within seventy two hours of you becoming aware of it, and in some cases the affected clients have to be told as well. Having that written down somewhere, with the number to call, is the difference between handling it and improvising.
Laid out like this it reads as a lot, but for a barbershop it comes down to sorting four documents once and then keeping the right habits.
In short
- A client list is already personal data processing, paper included.
- Appointments and reminders need no consent, marketing and photos do.
- Marketing consent has to be collected separately from the booking.
- Ask suppliers where the servers are and what happens to the data if you leave.
- A breach is reported to the authority within seventy two hours.
Found it useful? Pass it on to another barber.