Skip to content
For Dog Salons

GDPR-Compliant Client Directory for Dog Salons

FellDesk Editorial Team Last reviewed Reading time 8 min

Anyone running a dog grooming salon processes personal data every working day: the owner's name and phone number, sometimes an address, plus notes about the animal and the last treatment. That places the business squarely within the scope of the GDPR — whether the records sit in a notebook, a spreadsheet, or a software product. This guide walks through what that means in practice and how to keep the effort small.

1 Abschnitt 1

What data a grooming salon actually holds

The first step is unglamorous and almost always skipped: write down what you actually store. Only then can you judge what is necessary. Art. 5(1)(c) GDPR requires data minimisation — you may store what is needed for the purpose, not what might come in handy.

In a typical salon the list looks like this:

Type of data Example Needed for
Owner name Martina Sölken Assigning appointments, addressing clients
Phone number Mobile for callbacks Cancellations, questions about treatment
Postal address Street, postcode, town Only for invoicing or a mobile service
Email address For appointment confirmations Only if you actually confirm by email
Pet data Name, breed, age, coat type Planning and carrying out the treatment
Grooming notes Clip length, drying behaviour, allergies Quality and safety of the treatment
Behaviour notes "sensitive around the paws" Occupational safety and animal welfare
Treatment history Date, service, price Follow-up appointments, bookkeeping

Two fields deserve particular care. You only need the postal address if you issue invoices or travel to the client; for cash payment on site it is dispensable. And the owner's health data has no place in the file: the note "client has limited mobility, please bring the dog to the door" may be useful, but it is health data under Art. 9 GDPR and subject to far stricter rules. Record the action instead: "hand over at the door".

2 Abschnitt 2

The legal basis: you usually do not need consent

A common misconception holds that every processing operation must be signed off by the client in advance. In practice the opposite is the norm. Booking an appointment forms a contract, and the data needed to perform that contract may be processed under Art. 6(1)(b) GDPR. Name, phone number, pet data, and grooming notes all fall under it.

Consent under Art. 6(1)(a) GDPR is required wherever you leave the purpose of the contract:

  • Newsletters or marketing emails beyond what applies to existing customers under national marketing rules
  • Photos of groomed dogs on Instagram or your own website
  • Passing contact details to third parties, for example a dog training school
  • Reminder text messages, if you did not announce them as part of the booking

The key point is separation: consent must be freely given. It may not be a condition for getting an appointment. An intake form that bundles photo release into the same tick box as the booking is therefore ineffective. Two boxes, two decisions.

3 Abschnitt 3

What clients must be told at the first appointment

Art. 13 GDPR requires you to inform people at the point of collection. That sounds like paperwork, but in a salon it can be handled simply: a notice at reception or a sheet in the intake folder, with a pointer to the privacy notice on your website.

  1. Who is responsible — the salon's name, address, and contact details
  2. What the data is used for — appointments, treatment records, invoicing
  3. On what legal basis — contract performance, and consent where applicable
  4. How long it is stored — or the criteria that determine the period
  5. Who receives the data — for example the software provider or the accountant
  6. What rights people have — access, rectification, erasure, and complaint to a supervisory authority

The information has to be understandable. A copied boilerplate in legalese satisfies the requirement formally, but Art. 12 GDPR explicitly calls for clear and plain language.

4 Abschnitt 4

How long may you keep data — and when must you delete it?

Two things get mixed up constantly in day-to-day salon work: tax retention obligations and data protection erasure duties. An invoice must be kept. The note "does not like the dryer" must be deleted once its purpose has lapsed.

What Period Basis
Invoices and accounting records 10 years § 147 AO, § 257 HGB (Germany)
Received business correspondence relating to a contract 6 years § 147 AO, § 257 HGB (Germany)
Contact details used purely for scheduling While the client relationship lasts Art. 5(1)(e) GDPR
Grooming and behaviour notes While the client relationship lasts Art. 5(1)(e) GDPR
Data processed on the basis of consent Until withdrawal Art. 7(3) GDPR

You decide when a client relationship ends — but the decision has to be traceable. A rule that holds up well in practice: anyone who has not been in for three years gets deleted. Three years because the standard limitation period under German civil law (§ 195 BGB) is three years, so claims arising from the contract remain conceivable until then. Write the rule down once and stick to it; that traceability is precisely what the accountability principle in Art. 5(2) GDPR asks for.

5 Abschnitt 5

Why paper files and messenger chats are the harder options

Art. 32 GDPR requires measures appropriate to the risk, naming confidentiality, integrity, and resilience explicitly. For a salon that means three things: unauthorised people must not be able to read the data, it must not be changed unnoticed, and a loss must not be final.

The card box on the reception counter regularly fails the first test. It sits where clients stand, and anyone glancing into it while paying sees other people's data. It fails the third test as well: paper has no backup. A burst pipe in the storeroom ends ten years of grooming history.

The messenger route has a different problem. Arranging appointments by chat is convenient and unproblematic as long as the client chooses that channel. It becomes difficult when the messenger turns into the actual client file: data ends up scattered across chat threads on a private phone, an access request under Art. 15 GDPR becomes practically impossible to answer, and after a device change nobody knows where copies still exist.

Neither route is forbidden. Both create work that a structured record simply does not.

6 Abschnitt 6

Processing on your behalf: what applies once software is involved

As soon as a service provider processes data on your behalf — a software vendor, a host, a newsletter service — you need a data processing agreement under Art. 28 GDPR. You remain the controller; the provider may only process on your instructions.

The agreement must cover the subject matter and duration of the processing, the type of data, the processor's obligations, and the technical safeguards. Reputable providers supply it unprompted. If you ask and do not receive one, that is a clear signal.

Two points are worth reading closely: where are the servers, and are sub-processors used? If a server sits outside the EU you also need a basis for the transfer under Chapter V of the GDPR. Within the EU that step falls away.

7 Abschnitt 7

Access and erasure: what to do when someone asks

Two rights are genuinely exercised in practice. Under Art. 15 GDPR someone may request a copy of all data held about them. Under Art. 17 GDPR they may request erasure, provided no retention obligation stands in the way.

Both carry a one-month deadline (Art. 12(3) GDPR), extendable by two further months for complex requests. Access is free of charge as a rule.

The practical core is mundane: you have to know everywhere that person's data sits. With a card file plus a chat history plus an appointment book plus an invoice folder, that is a laborious search. With a record system where each client has one entry, it is a matter of minutes. This is where structure pays off — not because of the rule, but because of the work involved when it matters.

8 Abschnitt 8

Checklist for the salon

  1. Write down what data you store — and strike what you do not need.
  2. Draft a privacy notice under Art. 13 GDPR and display it at reception.
  3. Collect consent for photos and marketing separately, and document it.
  4. Set erasure periods and apply them once a year.
  5. Store the client file where customers cannot see it.
  6. Request the data processing agreement from every service provider.
  7. Check your backup: how would you reach the data if the device vanished tomorrow?
  8. Define a procedure for access and erasure requests.

Sources and further reading

This article reflects the situation as of the last review date and does not replace individual legal advice.

Related

Questions & Answers

Frequently Asked Questions (FAQ)

What fines threaten GDPR non-compliance in a dog salon?
Careless handling of client data or data loss can lead to warnings and substantial fines from data protection authorities. Encrypted digital software like FellDesk protects you from penalties.
Do I need to sign a Data Processing Agreement (DPA) with FellDesk?
Yes, as a commercial user, you conclude a DPA pursuant to Art. 28 GDPR. In FellDesk, this agreement is digitally integrated and valid in just a few clicks.
How long am I allowed to store contact data of inactive clients?
In principle, deletion obligations apply once data is no longer needed for processing purposes. Tax-relevant invoice data, however, must be kept for 10 years.
Can I save special grooming and care notes per dog?
Yes! In the Dog Salon business type, you have specific fields like coat type, coat length, drying behavior, and cutting preferences. At every follow-up appointment, you immediately see what was agreed upon last time.

See for yourself with our free plan

Test FellDesk permanently free with your first five regular clients.

Start for free