Training & Career · 23 July 2026 · 7 min read

GDPR for PMU Artists: Client Records, Photos and Marketing

A practical UK GDPR guide for PMU artists covering health details, consultation forms, treatment photos, marketing consent, retention and secure records.

By Powdrr Academy, PMU Education & Business Team

PMU artist securely reviewing a digital consultation record and consented client photographs

A PMU client record can contain contact details, medical history, contraindication answers, medication, photographs, treatment decisions and product batches. That combination is useful for safe care—and requires deliberate data protection.

The central principle: collect what you genuinely need, explain why, protect it, limit access and keep it only as long as you can justify. Treatment consent is not the same as data-processing or marketing permission.

This is a practical starting point, not legal advice. The Information Commissioner’s Office, or ICO, is the authoritative UK source. Requirements depend on your processing, legal structure and circumstances.

Map the client data you hold

List the information entering the business and every place it goes. Include website forms, booking software, paper consultations, email, direct messages, photographs, cloud storage, accounting software, shared salon systems and your phone.

DataWhy you may need itRisk to manage
Contact and booking detailsArrange and administer the serviceOver-sharing, uncontrolled exports and marketing reuse
Health and medication answersAssess suitability and record the decisionSpecial-category data requires additional care and a valid condition
Identity or age evidenceMeet a defined legal, insurer or policy needKeeping a full copy when a limited record would suffice
Treatment notes and batchesContinuity, safety, traceability and complaintsIncomplete records or access by people with no need to know
PhotographsPlanning, records, healing review and—with separate permission—marketingUnexpected publication, facial identification and device backups

Lawful basis and health information

UK GDPR requires a lawful basis for processing personal data. Health information is special-category data, so an additional condition is also needed. Do not select “consent” for every activity merely because a consent form exists. Contract, legal obligation, legitimate interests and consent have different tests and consequences.

Document the basis and special-category condition for each purpose. If you are unsure, use the ICO’s tools or obtain advice. The ICO’s direct-marketing planning guidance also explains that consent must be freely given, specific, informed and indicated by a deliberate action.

Write a useful privacy notice

A privacy notice should be understandable before data is collected. Explain who controls the information, what is collected, the purposes and bases, who receives it, transfers, retention, rights, how to complain and how to contact you. Link it near online forms and make it available during consultation.

A notice is not a waiver. It does not create permission for unnecessary processing and should not hide behind dense terms. If a salon, academy or booking platform is involved, clarify who is the controller for each purpose rather than telling the client that “the system owns the data”.

Separate treatment photos from marketing

You may have a professional reason to take record photographs. Publishing them is a separate purpose. Use distinct choices such as:

  • record photography required for treatment documentation;
  • anonymous close crop for education;
  • identifiable image for website and social marketing;
  • paid advertising or third-party publication.

Do not pre-tick boxes. Explain whether a face, name, voice or distinctive feature will be identifiable. Record the asset, permission version, date and channels. If consent is withdrawn, stop future use where that basis applies and know which live copies you control. Withdrawal may not erase lawful past processing or records held for another justified purpose.

Secure PMU records in real life

  • Use named accounts, strong unique passwords and multi-factor authentication.
  • Avoid shared salon logins and uncontrolled staff access.
  • Keep paper files in locked storage with an access routine.
  • Move client images out of a general personal camera roll into an approved system.
  • Check automatic cloud backups, shared albums and old devices.
  • Encrypt supported devices and keep software updated.
  • Use a secure route for medical details instead of social-media direct messages.
  • Keep a processor list and appropriate contracts with service providers.

If team members need access, give the minimum level their role requires and remove it promptly when duties change. “Everyone needs everything” is rarely a defensible access design.

Set a retention schedule

Do not keep every record forever “just in case”. Set periods by record type and document the reason: legal limitation, insurer condition, tax requirement, safeguarding, complaint handling or continuity. Some periods may need to account for the client’s age or the nature of the service.

Ask your insurer and professional advisers for applicable requirements. Review the schedule annually and apply it to backups and archived systems as well as the active database. Secure deletion is a process, not moving a file to a desktop folder named old clients.

Email, text and direct-message marketing

Marketing a top-up, new service or offer is not the same as sending an appointment reminder. The Privacy and Electronic Communications Regulations, or PECR, add rules for electronic direct marketing. The rules differ by recipient and channel, and a previous client is not automatic permission for every campaign.

Record how and when someone opted in, what they were told and how they can opt out. Honour objections and suppression lists. Read the ICO’s direct-marketing guidance before importing booking contacts into a newsletter tool.

If something goes wrong

A lost paper form, misdirected email, stolen phone or exposed shared folder can be a personal-data breach. Contain it, preserve facts, assess risk, document the decision and follow the ICO notification rules where applicable. Have the process written before an incident happens.

For routine access or deletion requests, verify identity proportionately and use a logged workflow. Do not erase a clinical or business record reflexively if another lawful requirement means it must be retained.

A seven-step PMU data check

  1. Map systems, forms, photos, devices and recipients.
  2. Define each purpose, lawful basis and any special-category condition.
  3. Update the privacy notice and form wording.
  4. Separate treatment documentation from optional marketing permissions.
  5. Restrict access and review suppliers.
  6. Create retention, deletion, request and breach procedures.
  7. Train every team member and review the system annually.

Frequently asked questions

Are PMU consultation forms special-category data?

They often contain health information, which is special-category data. You need both a lawful basis and an appropriate special-category condition for that processing.

Can I use a client’s treatment photo on Instagram?

Only with an appropriate basis and clear permission for that marketing use. Taking an image for the treatment record does not automatically permit publication.

How long should PMU client records be kept?

There is no single period for every record. Build a documented schedule using insurer, legal, tax and professional requirements, the client’s age and the reason for retention.

Can the whole salon access my client forms?

Access should be limited to people who need it for a defined purpose. Shared premises do not automatically justify shared access to health and treatment information.

Your next step

Open your consultation process and trace one fictional client through every system, device and team member. Fix unnecessary collection and access first, then document the remaining purposes. Pair this with the PMU consultation forms guide and PMU marketing rules.

Frequently asked questions

Are PMU consultation forms special-category data?

They often contain health information, so a lawful basis and an appropriate special-category condition are needed.

Can a PMU artist use a client treatment photo on Instagram?

Only with an appropriate basis and clear permission for that marketing use. Record photography does not automatically permit publication.

How long should PMU client records be kept?

There is no single period for every record. Create a documented schedule using applicable insurer, legal, tax and professional requirements.

Can the whole salon access PMU client forms?

Access should be limited to people who need the information for a defined purpose; sharing premises does not justify access to all records.

Related reading

All PMU articles · Find your training route