Do I legally need to do a patch test?
Yes — for any treatment using chemical products (lashes, tints, perms, certain gel systems). A patch test 24–48 hrs before treatment is an insurance requirement and protects you from liability if a client has a reaction. Your
Patch Test Record documents this properly.
What GDPR data do I need to hold on clients?
Name, contact details, and any health/allergy information are personal data under UK GDPR. You need a lawful basis (legitimate interest or consent), must keep it secure, and should tell clients what you hold. Your
GDPR Consent Form covers all of this.