The short answer
Under Singapore’s Personal Data Protection Act 2012 (PDPA), salons and spas must get consent to collect and use clients’ personal data, use it only for purposes clients would reasonably expect, protect it, keep it only as long as needed, appoint a Data Protection Officer, and notify the PDPC of notifiable data breaches. Marketing to Singapore phone numbers may also be subject to the Do Not Call provisions.
What personal data salons hold
- Names, phone numbers, email addresses and birthdays
- Visit history, purchases and package balances
- Health and contraindication notes, allergies, pregnancy status
- Before-and-after photos
- Payment records
Health notes and photos are particularly sensitive, and deserve tighter access controls.
The checklist
- Appoint a Data Protection Officer (DPO) and make their business contact information available.
- Publish a privacy notice explaining what you collect, why, and how clients can contact you.
- Obtain consent for the purposes you collect data for — and keep a record of it.
- Separate service messages from marketing. Booking reminders are part of the service; promotions need marketing consent.
- Don’t collect full NRIC numbers for routine purposes. The PDPC’s advisory guidelines (effective 1 September 2019) say organisations should generally not collect, use or disclose NRIC numbers unless required by law or needed to verify identity to a high degree of fidelity.
- Limit access. Staff should only see the client data they need for their role.
- Secure your systems. Use individual staff logins, strong passwords, and avoid sharing client lists over personal chats or spreadsheets.
- Handle access and correction requests from clients promptly.
- Retain data only as long as needed, then dispose of it securely.
- Prepare for data breaches. If a breach is notifiable, the PDPC must be notified no later than 3 calendar days after you assess it to be notifiable, and affected individuals may need to be notified too.
Marketing messages and Do Not Call
If you send promotional messages to Singapore telephone numbers — by call, SMS or messaging apps — the PDPA’s Do Not Call provisions may apply. In practice, the safest approach is to obtain clear, recorded consent for marketing, honour opt-outs promptly, and check the DNC Registry where required.
How software can help
Good salon software makes compliance part of everyday work: consent captured at booking, marketing consent tracked per channel, opt-outs respected automatically, role-based access to health notes and photos, and activity logs. Learn how BeautyMatters supports PDPA compliance.
This guide is general information, not legal advice. For authoritative guidance, refer to the Personal Data Protection Commission (PDPC) and seek professional advice for your specific situation.