GDPR for salons and clinics, without panic
Artikkelit kirjoitetaan tällä hetkellä tanskaksi ja englanniksi. Tämä on englanninkielinen versio.
GDPR sounds like something for lawyers, but the core is four questions any salon can answer. If you can, you are ahead of most.
1. What do you store about your clients?
Name, phone number, history, and in clinics often treatment notes. Write the list down. What is not on the list, you should not store. A rule of thumb: keep what you use to give good treatment, and leave the rest.
2. Where does it live?
In a drawer, a spreadsheet, your booking system? Paper and spreadsheets are hard to protect and impossible to tidy properly. One system with access control means an employee only sees what their role allows, and you can answer who sees what.
3. Where in the world does it live?
Data in the EU is the simple answer to a whole chapter of the rules. If your client data sits with a provider outside the EU, paperwork follows that no salon wants to own. Ask your provider where data is hosted. The answer should be one word.
4. Can you delete and hand over?
A client has the right to see their data and have it deleted. With a proper system that is two clicks. With three-year-old spreadsheets it is a weekend. That is the whole difference between having it under control and hoping nobody asks.
None of the four answers requires a lawyer. They require a system built for the rules, so everyday life just takes care of itself.