Confidential Dispatch
At a glance

A salon, spa or wellness studio collects personal data at a volume most owners underestimate — a phone number logged at nearly every visit, birthdays kept for promotional offers, and for some treatments, before/after photos and an allergy history edging into more sensitive territory. None of this needs a dramatic compliance overhaul, but the habits around high-frequency, low-formality customer contact — a shared appointment book anyone can see, WhatsApp used for booking and photo-sharing alike — are exactly what the DPDP Act’s basic notice-and-security expectations are written against.

Educational resource only. This explains how India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to salons, spas and wellness studios; it is not formal legal advice.

The situation

A salon or spa’s data footprint accumulates almost invisibly — a phone number taken at first booking and used for every appointment reminder since, a birthday noted for a promotional discount, a preference list built up over years of visits. None of it looks like “data collection” from the front desk; all of it is exactly that under the DPDP Act, at a volume that scales with how loyal and frequent the client base actually is.

Does DPDP apply to a salon or spa?

Yes — a single-chair salon and a multi-branch spa chain are both Data Fiduciaries the moment they decide why and how client data is used, which happens at first booking. Size doesn’t create an exemption; a solo stylist taking bookings over WhatsApp carries the same baseline duties — notice, a lawful basis, reasonable security, the ability to answer a client’s data request — as a large chain, scaled to what the business actually processes.

The client data a salon or spa actually handles

  • Contact and booking data — name, phone number, sometimes email, collected at first visit and reused for every subsequent booking and reminder.
  • Preference and history data — service history, product preferences, sometimes allergy or sensitivity notes relevant to treatments.
  • Birthday and promotional data — commonly collected specifically for loyalty offers and marketing.
  • Before/after and treatment photos — for hair, skin and body treatments where visual progress is part of the service or its marketing.
  • Payment data — card or UPI details processed at checkout, sometimes stored for repeat-client convenience.

The obligation that actually bites: before/after photos and treatment history

Photos and treatment-history notes are where a salon’s data crosses from routine contact information into something needing a more deliberate consent step. A before/after photo taken for a client’s own reference is a different processing activity from the same photo used in the salon’s marketing or social media — the two need separate consent, the same distinction that applies to event photography generally. Treatment-history notes that touch allergy information, skin conditions or medical-adjacent detail (relevant for certain laser, chemical or dermatological-adjacent treatments) deserve the same handling care as any other personal data, even though the DPDP Act doesn’t put them in a distinct “sensitive” legal tier — the practical sensitivity is real even where the statutory category isn’t special.

Common mistakes salons and spas make

  • Before/after photos used in marketing or social media without a separate, explicit client consent beyond the general service booking.
  • Client phone numbers and birthdays used for promotional messaging with no clear opt-out, often collected as a routine intake step with no notice about the marketing use.
  • The appointment book or client list visible to any staff member, including sensitive treatment-history notes, with no access limitation.
  • WhatsApp used for both booking and sharing treatment photos, mixing convenience with an uncontrolled channel for what can be sensitive images.
  • No defined retention point for former clients’ contact details and treatment history, kept indefinitely as a running database.

Collecting client data compliantly

A short notice at first booking, a separate opt-in for marketing use of photos and promotional messaging, and basic access control covers most of a salon’s real exposure. Tell clients plainly what’s collected (contact details, treatment history, photos where relevant) and why at their first visit; keep marketing consent (birthday offers, promotional messages, social-media photo use) as a distinct, opt-out-able choice from the core booking relationship; and move client photo-sharing off personal staff devices and WhatsApp into whatever booking or client-management system the business already uses for appointments.

Booking through Urban Company, Fresha and similar platforms

A salon taking bookings through a third-party platform is receiving client data the platform collected under its own notice and consent — a different starting point from a client who booked directly, and worth treating as such rather than assuming it arrived “pre-cleared.” Booking and scheduling platforms (Urban Company for at-home services, Fresha and similar booking-management tools for in-salon appointments) typically pass the salon a client’s name, contact number and appointment detail as part of enabling the booking — a legitimate, expected data flow for fulfilling that specific appointment. Where it needs its own thought is anything beyond that one booking: a salon that wants to add a platform-referred client to its own direct marketing list, or start contacting them outside the platform for future bookings, is going beyond what the client agreed to when they booked through the platform’s own notice — that’s a fresh use needing the salon’s own separate consent, not an assumed extension of the platform relationship. The safer default is treating platform-referred bookings as scoped to that platform and that appointment, unless the client separately opts into the salon’s own direct contact.

FAQ

Can a salon add a client who booked through Urban Company or a similar platform to its own WhatsApp marketing list?

Not without the client’s own separate opt-in — data received through a booking platform is scoped to fulfilling that platform booking; using it for the salon’s own direct marketing is a different purpose the platform’s notice to the client likely didn’t cover.

Can a salon post a client’s before/after photo on Instagram without asking separately?

Not defensibly — using a treatment photo for the salon’s own marketing is a distinct use from taking it for the client’s own reference, and needs its own clear, opt-in consent.

Does a small, single-owner salon need to worry about the DPDP Act the same way a chain does?

Yes, proportionately — the core duties (notice, a lawful basis, security, respecting a client’s request) apply regardless of size; a solo operation runs a lighter version, not none of it.

Is treatment-history data (allergies, skin conditions) treated as more sensitive under the DPDP Act?

Not as a separate legal category — the Act applies one baseline to all personal data. The practical sensitivity is still real, which is why the same access-control and photo-consent discipline matters even without a special statutory tier requiring it.

Can a salon keep sending promotional messages to a former client indefinitely?

Not without a working opt-out and a genuine ongoing basis — the DPDP Act’s purpose-and-consent principles expect marketing use to be something a client can actually decline, and continuing after no engagement for years is worth revisiting against a defined retention policy.

Reviewed by Confidential Dispatch Editorial Team
Last updated 19 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →