Pabau GO app

The new Pabau GO is heredownload on the App Store

Download on the App Store
Book a demo Book a demo
Compliance and security

Data protection for aesthetic clinics: 5 steps to compliance

Avatar photo Monika Lazarevska
Last Updated: August 12, 2026
Reviewed by: Avatar photo Lucy Galloway
Key Takeaways

Key Takeaways

A privacy policy needs your lawful basis, retention periods and data protection officer’s details, written so clients can actually understand it.

Store client data in one secure system with need-to-know access controls, and clear it off personal phones, cameras and paperwork.

Use separate, unticked consent boxes for treatment, marketing and before-and-after photos, since bundling them into one box is a common compliance mistake.

Train staff on data protection at least once a year and for every new starter, since it’s the first thing regulators ask about after a breach.

Audit your data protection processes every year, since the law, cyber-attack methods and your own practice keep changing.

Charlotte Staples ran data protection at Harrods for nearly eight years before joining Firebird Data Protection, where she now specializes in data protection officer (DPO) services for aesthetic practices.

We sat down with her for a practical walkthrough of data protection for aesthetic clinics, from the laws that apply to the five steps that make the biggest difference.

Why data protection matters

Charlotte’s take: the personal data aesthetic practices collect falls into the most sensitive category under UK data protection law, so there are stricter rules about how it can be used and stored.

Before-and-after photos are a good example of this in an aesthetic setting: paired with treatment notes and biometric details like facial mapping for filler or Botox, they count as special category data under UK GDPR, which means they need the same highest level of protection as medical records.

Fines for non-compliance reach up to £17.5 million, and that’s before accounting for compensation claims from affected clients.

Lost future business, as clients hear what happened and move elsewhere, adds to that cost.

The Information Commissioner’s Office (ICO), the UK regulator for personal data use, is working on introducing AI to scan websites for non-compliance. The ICO has launched investigations after only a handful of complaints.

What are the main causes of data breaches?

In her experience, the number one cause of a data breach is sending an email to the wrong recipient.

When that email contains health information, it’s likely to meet the threshold for reporting to the regulator. Another leading cause is a cyber attack which often happens as a result of phishing emails being clicked on.

Educating yourself and your staff on both risks significantly reduces exposure.

Can you give some examples of data breaches caused by human error?

We’ve mentioned sending an email to the wrong recipient. Another big one is failing to have the correct access controls in place to a system so that an unauthorized person gains access.

Updating a form in a shared area that contains personal data, rather than downloading and saving it in a private location, is another common error. Sending data to the wrong recipient by post is also common.

Consequences of poor data protection

  • Personal data gets lost or stolen and falls into the wrong hands
  • Identity theft and reputational harm to clients
  • Loss of business
  • Regulatory fines
  • Loss of trust amongst your client base

What are the reasons practices trip up when it comes to data protection? Is it a lack of awareness?

Practices and sole traders are legally required to register with the Information Commissioner’s Office, and a quick look at this shows that many practices and practitioners are not registered.

I think it is a lack of awareness. The data protection terminology can be quite confusing, and it’s not a particularly straightforward area of law. It also changes fairly frequently, so it’s a challenge to stay on top of exactly what you need to do.

Practices often assume a breach won’t happen to them.

However, the stats show breaches and complaints are on the rise. The UK government has named cyber attack as the number one risk affecting all businesses, so the data makes clear a breach will reach most practices eventually.

“The Information Commissioner’s Office (the regulator of personal data use in the UK) is also working on introducing AI to scan websites for non-compliance of data privacy rules.”
Charlotte Staples, Firebird
Charlotte Staples
Firebird Data Protection

None of this is meant to scare you – it’s meant to show why getting the basics right matters. Here’s how Charlotte suggests doing that, in five steps.

How to improve privacy compliance at your aesthetic clinic in 5 simple steps

1. Review your privacy policy

What is a privacy policy, and what should it include?

A privacy notice (sometimes called a privacy policy) is a core part of your compliance.

It’s where you explain to an individual how and why you collect, use, store, and delete their personal data. There are quite a few things that must be included in a privacy notice and they are unique to each business.

It must include your lawful basis (or justification) for collecting and using the data, and how long you’ll keep it for. You must also give details of who your data protection officer is and how to find out more information.

You’re responsible for making sure your audience can easily understand your privacy notice and explaining everything clearly. If you’re using cookies or tracking technologies on your website, you must also have a cookie policy that explains how they’re used.

Where should it be published?

The best place is on your website although you should include instructions on how to find it on every form that you use to collect people’s information.

Can you just download a template online?

The Information Commissioner’s Office, the regulator for data protection in the UK, offers a free tool that lets organizations generate a privacy policy.

However, whilst templates exist they often rely on specific information to be inputted and can come out fragmented and difficult to understand. It’s a good idea to get a review from a specialist even if you do choose to use a template, so they can check that it’s accurate.

For practices wanting more reassurance, I’ve created a unique template to use. I can also create a bespoke privacy notice for complete peace of mind that you’re meeting your obligations.

I don’t have a privacy notice, should I be worried?

Failing to have a privacy notice would amount to a breach of your obligation to be transparent about how you use personal data. If the regulator became aware it could issue a fine or you could face legal claims.

In fact, some of the biggest fines in Europe for non-compliance with data protection laws have been for lack of transparency about how personal data is being used.

Of course, you could take the risk and go unnoticed but with the regulator looking at AI to scan websites in the near future, it’s possible you’d be found out sooner rather than later.

“A privacy policy must include your lawful basis for collecting and using the data, and how long you’ll keep it for. You must also give details of who your data protection officer is and how to find out more information.”
Charlotte Staples
Firebird Data Protection

Once your privacy policy is in order, the next question is what actually happens to the client data it describes once you’ve collected it.

2. Keep your client data safe

What is the best way to keep client data safe?

All client data should be stored in one secure storage system.

Practice management software like Pabau lets you centralize all client data, set need-to-know access controls, and keep a full audit trail of who viewed what. It works this way for every specialty, as you can see from who Pabau is for.

If you capture before-and-after photos or store data on personal devices, move it into a central system like Pabau and delete it from the original source. Going paperless helps too.

Is there anything else to be aware of in the practice regarding client data?

Lots! Too much to cover in one question, but my top three tips are to make sure that you have separate consent tick boxes for:

  • Permission to complete the treatment
  • Permission to send marketing communication
  • Permission to use before and after photos on your marketing materials

Other things to be aware of are making sure you lock your computer if you work in an area that clients can access and making sure you do not leave any paperwork lying around.

Also, look out for phishing emails (scam emails where the sender pretends to be genuine) and voice phishing attempts. There has been an increase in attempts made to access health information via cyber attacks. For a full overview, practices should introduce data protection training to their staff and have them complete it at least once a year.

At Pabau we advocate for practices being paper-free – is this essential to keeping client data safe?

It’s not essential but it certainly helps. Any paperwork you do use should be securely stored and destroyed using a cross-cut shredder as soon as it is no longer needed.

data protection and privacy compliance in practices
Keeping client records, photos, and consent in one secure system like Pabau keeps sensitive data off personal devices and paper.

Storing data safely is only useful if you collected it properly in the first place, which brings us to consent.

At the point of collecting personal data is a good time to ask for consent.

The best way to do this is to use tick boxes that are not pre-ticked. You should also have a separate tick box for email, SMS, and WhatsApp.

There are some limited opportunities for practices to use pre-ticked boxes, but this should only be done on the advice of a data protection professional.

Bundling your consents is a common mistake.

You should have one tick box for the treatment and another tick box for marketing. Also, sending marketing content in an appointment reminder or sending an email suggesting treatment is now due when no marketing consent exists.

Both practices breach GDPR marketing rules, and the ICO takes them seriously. In fact, in 2023 it issued more fines for marketing-rule breaches than for data breaches.

What about your marketing emails?

You should have a clear idea of which of your communications are marketing and which are service-related. If you do not have consent to send marketing, the service emails cannot include marketing material as this could be seen to be an attempt to break the rules.

You must include an unsubscribe link in every marketing message, and this includes text messages and WhatsApp too if you use these for marketing.

In short – yes! This should also explain exactly where you’d like to use them: Instagram for a one-off post, your leaflets, a billboard, and so on.

“Bundling your consents is a common mistake. You should have one tick box for the treatment and another tick box for marketing.” – Charlotte

Getting consent right on paper counts for little if your team doesn’t understand why it matters day to day – which is where training comes in.

4. Educate your staff on handling data

What’s the best way to train your staff about data protection?

Make it fun. It’s important that the message sticks. Training is one of my favorite things to do because I really enjoy changing people’s minds about a topic traditionally seen as dull.

When you have a data breach, the first thing the regulator asks is whether you provide data protection training. You should provide it at least once a year and for every new starter. As the law is constantly changing, the content of the training should be updated too.

Rapid advancements in technology and an increase in cyber-attacks mean that sometimes training is not enough and general awareness is just as important. Adding data protection as a standing agenda item in team meetings builds ongoing awareness without requiring formal training every time. You can also follow Firebird’s Instagram @firebird.dp, which we recently launched as a way of providing free advice.

Charlotte also runs webinars and training sessions tailored to practices of different sizes and budgets, for owners who want to be sure their team is properly trained.

How often should you train your staff?

At least once a year, but you may choose to train them more frequently. It’s about embedding awareness and a culture whereby the client’s (and employee’s) personal data is recognized for the value it holds and appropriately protected.

Do you need documentation in place for data breach incidents?

As Charlotte explains, you’re legally obliged to record every data breach and document what happened and what you’re doing to prevent it from happening again. You also need to assign a risk rating of what the breach means to those whose data has been lost or stolen.

If the risk is high, as it often will be if the data lost or stolen includes health data, you’re legally obliged to report it to the regulator without delay and within 72 hours of becoming aware.

As you can imagine, this can all be quite stressful if you’re not used to dealing with data breaches and you’re panicked about how to handle the regulator.

This is where the specialist experience of an external DPO can really calm your nerves and minimize the impact of a regulatory investigation.

Is there anything practices need to be aware of in terms of social media and data protection?

Charlotte is clear on this: your practice is responsible for the personal data you hold regardless of where it’s stored.

This means if you interact with clients on social media you will still be responsible for the protection of their personal data there. It’s a good idea to move conversations off social media and delete the data from there as soon as possible.

Best practice tips for managing data protection in aesthetic clinics
With Pabau, client conversations and records stay inside one auditable system instead of scattered across social media and phones.

With policies written, data secured, consent sorted, and staff trained, the last step is making sure it all keeps working – which means checking it regularly.

5. Audit compliance processes at your aesthetic clinic

Compliance laws are always changing – do aesthetic practices need to be aware of that?

Absolutely. Because of the risk of cyber attack, changes in technology, and the updates to data protection laws it means the risk is always changing. A comprehensive audit is a good place to start but it should be regularly repeated to stay on top of things.

What’s the best way to stay up to date?

Follow Firebird on Instagram and LinkedIn for specific updates for the wellness and aesthetic sectors. For more detailed updates you can visit the Information Commissioner’s Website.

How often should you take a look at your processes and carry out audits?

At least once a year. Once a framework is established, the yearly updates are unlikely to take long. Investing in compliance now, especially while your practice is growing, pays back significantly as it scales.

Who should ‘own’ the process – the owner, the manager, or someone else?

The practice manager is best placed to own the process. They work with the data and will understand how it’s used. However, the practice owner will want to remain accountable.

In some instances, failure to comply with the data protection laws has resulted in criminal convictions, so the owner will want to see the assurance that their practice is meeting the requirements.

It can seem overwhelming to do this all on your own, which is part of the reason I launched the service at Firebird. An outsourced Data Protection Officer who also understands your business can take the stress away from understanding your obligations and making sure you comply.

We have a package to suit practices of all sizes and would love to hear from you.

“If you interact with clients on social media you’re still responsible for the protection of their personal data there. It’s a good idea to move conversations off social media and delete the data from there as soon as possible.” – Charlotte

Finally, is there anything else important to mention?

One last tip is to be aware of new technology and the devices you are using. Any device that connects to the internet could be sending data externally. If you’re looking at using artificial intelligence, this also carries a data protection risk.

You’re required to carry out risk assessments (known as data protection impact assessments) if you’re carrying out a high-risk activity. We are specialists in making sure your client (and employee) data is not put at risk.

Bringing this back to the five steps: a clear privacy policy, secure client data, properly-worded consent, a trained team, and regular audits. Together, these five steps cover the areas where GDPR compliance most commonly breaks down. None of them are one-off jobs. UK GDPR expectations and ICO guidance keep evolving, so treat compliance as an ongoing habit rather than a box you tick once.

For more information on data protection or to schedule a call with Charlotte, head to their website firebirdltd.co.uk. You can also get in touch via email at [email protected].

Keep client data safe in one secure system

See how Pabau centralizes client records, before-and-after photos, and consent, with need-to-know access controls and a full audit trail, so sensitive data stays off personal phones and paper.

Pabau practice management dashboard

Making these five steps stick

None of the breaches Charlotte describes above start with a sophisticated hacker. They start with an email sent to the wrong person, a phone left unlocked on a treatment couch, or a marketing tick box that got bundled in with something else.

That is actually good news: it means the fix is rarely a bigger budget, it is a habit that everyone on the team follows without having to think about it.

That is the piece software can help with. Pabau keeps client records, consent, and staff access levels in one system, so a new starter only sees what their role allows, and nothing quietly ends up saved to a personal phone.

If you want to see it against how your practice actually works, book a demo.

Continue your research

Continue your research

Want the fuller GDPR picture, not just the aesthetic-clinic angle? UK GDPR checklist covers the wider legal requirements every UK practice has to meet.

Wondering where data protection fits into wider governance? The CQC compliance checklist covers the broader inspection standards some practices also need to meet.

Frequently asked questions

What counts as sensitive personal data in an aesthetic clinic?

Before-and-after photos, when paired with treatment notes and biometric details like facial mapping for dermal filler or anti-wrinkle injections, count as special category data under UK GDPR — the most sensitive type. That means they need the same highest level of protection as medical records. Storing them on personal phones or unsecured devices creates serious compliance exposure, so keep everything in one secure system with access set on a need-to-know basis.

What’s the number one cause of data breaches in a practice?

The leading cause is simply sending an email to the wrong recipient. When that email contains health information, it usually meets the threshold for reporting to the regulator. Another common cause is a cyber attack, often triggered when someone clicks a phishing email. Both come down to human error, which is why training and secure systems work best together.

Do I really need a privacy policy for my clinic?

Yes. A privacy notice explains how and why you collect, use, store, and delete someone’s personal data. It must state your lawful basis for using the data, how long you’ll keep it, and who your data protection officer is. Not having one breaches your duty to be transparent, and some of Europe’s biggest fines have been for exactly that. The Information Commissioner’s Office offers a free tool to generate one.

How should I ask clients for marketing consent?

Ask at the point of collecting their data, using tick boxes that aren’t pre-ticked, with separate boxes for email, SMS, and WhatsApp. Don’t bundle treatment consent with marketing consent — keep one box for each. And never slip marketing into an appointment reminder or service email when you don’t have marketing consent. Practice management software like Pabau lets you capture separate consents against each client record.

How often should we train staff and audit our processes?

At least once a year, plus training for every new starter. When a breach happens, the first thing the regulator asks is whether you provide data protection training. Because the law changes often, refresh the content each time. Run a full compliance audit yearly too — once your framework is set up, the annual review usually won’t take long, and putting the effort in now saves time as you grow.

What do I have to do if a data breach happens?

You’re legally required to record every breach, document what happened, and note what you’re doing to stop it recurring. You also assign a risk rating for the people affected. If the risk is high — which it often is when health data is involved — you must report it to the regulator without delay and within 72 hours of becoming aware. An external data protection officer can help you handle this calmly.

×