The Booking System Is the Risk
Most beauty salons and aesthetics clinics in the UK do not think of themselves as businesses with significant digital security exposure. The website has a gallery, a price list, a contact form, and a booking button. That booking button is the risk.
Online booking systems for salons collect names, email addresses, phone numbers, and payment card details. For aesthetics clinics — botox, fillers, chemical peels, laser treatments — they may also collect medical history, allergy information, and contraindication questionnaires. Under UK GDPR, that health information is special category data, subject to stricter processing rules than ordinary personal data.
A compromised booking system is a data breach. A data breach involving special category health data is one of the categories the ICO takes most seriously in enforcement decisions.
The Platforms Most UK Salons Use
The majority of UK beauty businesses book through one of a handful of platforms: Treatwell, Fresha (formerly Shedul), Vagaro, Timely, or Shortcuts. These are third-party SaaS platforms, and their security is largely outside your control — the platforms themselves are responsible for their own infrastructure security.
What *is* in your control: the credentials you use to access those platforms, the data you export from them and store elsewhere, whether you have MFA enabled on your platform account, and how you handle customer data that comes through your own website (contact forms, consultation forms hosted on your site rather than the booking platform).
If you use Treatwell or Fresha exclusively for bookings and process no card data yourself, your direct card data liability is lower — the platform handles PCI DSS compliance. But you still hold personal data (names, contact details, booking history, health notes) that requires protection.
The Aesthetics Clinic Angle: Special Category Data
A beauty salon collecting name, email, and phone number is processing ordinary personal data. An aesthetics clinic collecting pre-treatment consultation forms — asking about blood thinners, pregnancy, previous filler treatments, skin conditions, allergies — is collecting health data, which is special category under UK GDPR Article 9.
Special category data processing requires explicit consent (not just a tick box — the consent must be freely given, specific, informed, and unambiguous), a documented lawful basis, and stronger security measures than ordinary personal data.
Specific implications: - Pre-treatment consultation forms emailed as attachments or stored in Google Drive folders are not adequate security for health data. They should be in an access-controlled system. - Photos taken for before/after records are biometric data if processed to identify individuals, and medical records if they document clinical outcomes. Both have special category implications. - A data breach involving a client's aesthetic treatment history is not the same as a breach involving their haircut appointment. It is more sensitive and the ICO will treat it as such.
What Attackers Want from Salon Websites
Salon websites are not typically targeted for sophisticated attacks — the value is not high enough to justify bespoke intrusion. The risk is automated, opportunistic:
**Card skimmers on custom checkout pages** — if you process deposits or sell products directly through your website (WooCommerce, Shopify) rather than exclusively through a booking platform, Magecart-style JavaScript injection can harvest card numbers entered on your checkout. This is the same attack used against retail e-commerce, and it does not require a sophisticated attacker.
**Contact form spam and phishing infrastructure** — contact forms are frequently abused for spam distribution. More relevantly, a compromised salon website can be used to host phishing pages targeting other businesses' customers. Your site becomes collateral damage in an attack aimed at someone else.
**SEO poisoning** — hidden links injected into your site's content to boost rankings for unrelated (often pharmaceutical or gambling) sites. Damages your own Google ranking over time.
**Credential stuffing against booking accounts** — if staff use weak or reused passwords for your booking platform admin account, automated credential stuffing attacks using breach databases can result in account takeover. A competitor or a disgruntled former staff member with admin access to your booking system can access client data, cancel appointments, or export contact lists.
UK GDPR: What Salon Owners Actually Need to Do
The practical requirements are more manageable than the legislation's language suggests:
**Privacy policy** — you need one, it needs to be on your website, and it needs to explain what data you collect, why, how long you keep it, and how customers can request its deletion or a copy. The ICO has a free tool for generating basic privacy notices.
**Retention limits** — decide how long you keep client records and stick to it. "We retain booking and treatment records for 3 years" is a documented policy. Indefinite retention is a liability.
**Subject Access Requests** — if a client asks what data you hold on them, you have one month to respond. Having your data in one place (your booking platform) rather than scattered across email, Google Sheets, and physical consultation forms makes this far easier to comply with.
**Data Processing Agreements** — if your booking platform processes data on your behalf (Treatwell, Fresha, etc.), they should have a DPA available. Most major platforms have these in their terms or available on request. Make sure you have accepted them.
**Breach notification** — if client data is compromised, you have 72 hours to notify the ICO if the breach poses a risk to individuals. Health data breaches almost always meet that threshold.
The Simple Things That Actually Help
MFA on your booking platform admin account — set this up today, takes five minutes, prevents credential stuffing.
A strong unique password for your website admin (WordPress, Squarespace, Wix) — different from any other service you use. A password manager (Bitwarden is free) makes this painless.
If you use WordPress with online booking plugins, keep them updated — booking plugins (Bookly, Simply Schedule Appointments, Amelia) have had notable vulnerabilities in recent years.
An annual review of who has admin access — former staff members who still have login credentials to your booking system or website are a common security gap in salons with staff turnover.
Yrzo AI scans the technical security of your website — authentication weaknesses, form injection vulnerabilities, missing HTTPS configuration, insecure session management — in under 20 minutes. Starts at £99 at yrzoai.dev.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →