UK GDPR has a reputation for being a corporate problem. It is not. If you hold a client's phone number, you are processing personal data and the rules apply. The good news is that for a small service business the obligations are genuinely manageable.
This is a plain English overview, not legal advice.
Know what you hold and why
Write down, once, what personal data you keep and the reason. Client names and numbers to manage appointments. Card details held by your payment provider, not you. Notes on treatments. For a clinic or tattoo studio, health information, which is a special category and needs more care.
That list is most of the work. You cannot protect data you have not accounted for.
Understand which lawful basis you are using
Managing a booking someone asked for does not need consent. It is necessary to perform a contract with them. That is why you do not need to ask permission to text someone a reminder about an appointment they made.
Marketing is different. Sending promotional messages needs consent, and that consent has to be specific, recorded and as easy to withdraw as it was to give. A tick box that was pre-ticked is not consent. "By booking you agree to marketing" is not consent.
Record consent per channel and per person, with the date. If your system cannot tell you when and how someone opted in, you cannot evidence it.
Do not keep things forever
Holding client records indefinitely because deleting feels risky is itself the risk. Decide how long you keep inactive client records and apply it. Several years after last contact is defensible for most service businesses. Longer is defensible where there is a clinical or safety reason and you can explain it.
The important part is that the deletion actually happens, automatically, rather than being a job nobody does.
Be able to answer a request
Someone can ask what you hold about them, ask for a copy or ask you to delete it. You have one month. For a small business this is rarely difficult, but it is very difficult if the answer is spread across a diary, a phone, a notebook and three WhatsApp threads.
Note that erasure is not absolute. You can keep what you need for legal or accounting reasons, invoices being the obvious example. You delete what you no longer have a reason to hold.
The bits people forget
- Most businesses processing personal data need to pay the ICO data protection fee. For a small business it is a modest annual amount and non-payment is enforceable.
- You need a privacy notice that people can actually find, written in language they can read.
- A personal data breach that risks people's rights has to be reported to the ICO within 72 hours. Know now who would do that, rather than working it out during one.
- Staff access should be limited to what each person needs. A junior does not need to see everyone's clinical notes.
None of this requires a consultant. It requires knowing what you hold, having a reason for it, recording consent honestly and being able to delete on request.
Topics
Keep reading
- Customers
Client notes worth keeping, and ones that will get you in trouble
Good notes make a client feel remembered. Bad ones are a data protection problem sitting in your system waiting for somebody to ask for a copy.
- Payments
What a card payment actually costs you
Card fees are quoted as a percentage plus a fixed pence amount, and the pence part is what hurts on small tickets. Here is the arithmetic on a £40 cut.
- Running a business
Pricing your services without guessing
Most small businesses price by looking at what the shop down the road charges. Here is a better method that takes about an hour.