TL;DR:

  • Salons are data controllers under UK GDPR and must register with the ICO — it costs £40-£60 per year and failing to register is a criminal offence
  • The most likely threats are compromised booking system accounts (ex-staff, weak passwords) and phishing emails targeting the business owner’s inbox
  • Enable two-factor authentication on your booking platform and email today, and remove any ex-staff accounts — these two steps eliminate most of your real risk

Hair and beauty salons might not seem like obvious targets for cybercriminals. But think about what a typical salon holds: every client’s full name, mobile number, email address, sometimes home address, appointment history, and in many cases stored card details or payment records. That is a tidy package of personal data, and it is often protected by a single shared password that has not changed in years.

This guide is written for salon owners who are not IT professionals. You do not need technical knowledge to follow it. What you need is about an hour this week and the willingness to act on the specific steps laid out here.

What Data Your Salon Actually Holds

Before you can protect your data, it helps to know exactly what you have. Most salons collect and store:

Client records: names, mobile numbers, email addresses, sometimes dates of birth (for age verification on treatments like intimate waxing or lash extensions). Some salons collect medical information — allergy test results, skin condition notes, patch test dates.

Appointment history: which treatments a client has had, which staff member performed them, any notes left by the therapist. This history builds up over years.

Payment records: if you take card payments through an integrated system, records of transactions. Some booking platforms store card details for no-show protection policies.

Staff records: employee details, payroll information if managed in-house.

Under UK GDPR, holding any of this makes your salon a data controller. That carries legal obligations whether you have one location or ten.

Your GDPR Obligations as a Salon Owner

The Information Commissioner’s Office (ICO) regulates data protection in the UK. Most salons are legally required to register with the ICO as a data controller. Registration costs £40 per year for most small businesses (or £60 if your turnover exceeds £632,000 or you have more than 10 staff). Failing to register when required is a criminal offence, not just a civil matter.

You can check whether you need to register and complete the registration at ico.org.uk/registration. For most salons the process takes about 20 minutes.

Beyond registration, UK GDPR requires you to:

  • Have a privacy notice — a plain-language explanation of what data you collect, why, how long you keep it, and clients’ rights. This can be a page on your website or a sign in reception. ICO has a template.
  • Only keep data as long as you need it — you do not need to keep records of clients who have not visited in five years. Delete old records periodically.
  • Know what to do if something goes wrong — if there is a data breach that is likely to result in a risk to people’s rights and freedoms, you must report it to the ICO within 72 hours of becoming aware of it. A booking system hack that exposes client contact details almost certainly qualifies.

The 72-hour rule catches a lot of business owners off guard. The ICO has an online breach reporting tool at ico.org.uk/report-a-breach. You do not need to have all the details before you report — you can update the report as you learn more.

Booking System Security: Your Biggest Risk

The booking platform — whether that is Treatwell, Fresha, Shortcuts, Salon Iris, or something else — is the most sensitive system most salons operate. It holds client records, appointment history, and often payment details. It is also the system most likely to be compromised.

The ex-employee problem. Staff turnover in hair and beauty is high. When a stylist or therapist leaves, their account on the booking system often stays active. That means someone who no longer works for you can still log in, view client details, export contact lists, or worse. This is one of the most common causes of data breaches in small businesses, and it is entirely preventable.

Action: log into your booking system’s admin panel right now and check the user list. Remove any accounts belonging to people who no longer work for you. Most platforms let you do this under Settings → Staff or Settings → Users. Do not wait until they cause a problem.

Weak and shared passwords. Many salons use a single login shared between all staff. If that password is compromised — through phishing, a data breach at another site, or an ex-employee sharing it — everyone’s access is gone or your data is exposed. Each staff member who needs system access should have their own account with their own password.

Two-factor authentication (2FA). Fresha, Treatwell, and most other platforms offer 2FA. When enabled, logging in requires both the password and a code sent to a phone or generated by an app. Even if someone has your password, they cannot get in without the second factor. Enable this on your booking system admin account today. Check under Security or Account Settings.

Card Payment Security

Taking card payments brings you into scope for the Payment Card Industry Data Security Standard (PCI DSS) — a set of rules set by the card networks (Visa, Mastercard). This sounds intimidating but for most salons it is straightforward.

If you take payments through a chip and PIN terminal provided by your card processor (Sumup, Square, Zettle, Worldpay, etc.) and you never see raw card numbers yourself, your PCI obligations are minimal. Your card processor will walk you through an annual Self-Assessment Questionnaire (SAQ) that takes around 20 minutes.

Never write down card numbers. If a client calls to pay over the phone, take the payment in person or use a payment link — do not write the number on a notepad.

Do not store card details manually. If your booking system has a “store card for no-shows” feature, use the one built into the platform — do not keep a spreadsheet of card numbers.

Be careful with your terminal. Card skimming devices — small attachments fitted to card readers — do exist. Give your terminal a quick visual check periodically, and if anything looks loose or added, contact your provider before taking further payments.

Wi-Fi: Keep Business and Customer Networks Separate

Many salons offer customers a Wi-Fi password. This is fine and expected — but your customer Wi-Fi and your business Wi-Fi (the network used by your POS system, booking tablet, and business laptop) should be completely separate networks.

Most modern routers support a “guest network” feature. Enabling this takes about five minutes in the router settings and means a client who connects to the salon Wi-Fi cannot see or access devices on your business network. If someone on the customer network is running malicious software, it cannot reach your booking system or payment terminal.

If you do not know how to set up a guest network on your router, your broadband provider’s support line can usually talk you through it, or a local IT person can do it in under 30 minutes.

Change your router’s admin password from the factory default — this is usually something like “admin” / “admin”. Log into the router settings (the address is usually printed on the router, often 192.168.0.1 or 192.168.1.1) and set a strong password.

Phishing: The Most Likely Attack on Your Inbox

Phishing emails impersonate trusted senders — your bank, HMRC, Companies House, a booking platform, or a supplier — to trick you into handing over login credentials or making a payment. They are the most common type of cyber attack on UK small businesses by a significant margin.

Signs to look for:

  • Urgency (“Your account will be suspended in 24 hours”)
  • Requests to click a link and log in — always go directly to the site instead of clicking the link
  • Requests for payment to a new bank account, even if the email appears to come from a known supplier
  • Slightly wrong sender addresses (treatwell-support@gmail.com rather than @treatwell.com)

Enable 2FA on your business email account (Gmail: myaccount.google.com → Security; Microsoft 365: mysignins.microsoft.com). This is the most effective protection against phishing, because even if you accidentally hand over your password, the attacker still cannot access your account.

What to Do This Week

You do not need to tackle everything at once. Here is a practical order:

  1. Enable 2FA on your booking platform admin account and business email. Do this today. It takes five minutes each and dramatically reduces your risk.
  2. Audit your booking system user list. Remove any former staff accounts immediately.
  3. Register with the ICO if you have not already. Check at ico.org.uk/registration.
  4. Publish a privacy notice — even a brief one on your website or displayed in reception. ICO has templates.
  5. Set up a guest Wi-Fi network separate from your business network.
  6. Brief any staff on what a phishing email looks like. You do not need a formal training session — a five-minute conversation covers it.

None of these steps require IT knowledge or a significant budget. Most are free. The realistic threat to a UK salon is not a sophisticated hacker — it is a weak password on a booking system, an ex-employee who still has access, or a business owner who clicks a convincing phishing link. Address those, and you have addressed most of your real risk.