A tattoo studio may only store client data for a defined purpose, sparingly and securely. Health answers from the consent form count as a special category and belong in an access controlled system, not in a WhatsApp chat. Photos for your portfolio need their own consent that can be withdrawn at any time, and accounting records are kept for 10 years in Switzerland, 8 years in Germany and 7 years in Austria.
- A studio processes health data, so stricter rules apply than for an ordinary client list.
- The GDPR applies in the EU, the revised data protection act in Switzerland since 1 September 2023. The principles are practically the same.
- Portfolio photos need separate consent that can be withdrawn. A quiet yes in conversation is not enough.
- WhatsApp and Instagram are communication channels, not a client database. Lose the phone and the history is gone or in someone else's hands.
- Without a deletion plan you collect data forever, and that is the single most common mistake in studio life.
Contents
- What data does a tattoo studio actually hold?
- Which rules apply in the EU and in Switzerland?
- Health data and photos: the two sensitive areas
- Why WhatsApp and Instagram are not a client database
- How long do you have to keep client data?
- The eight point checklist for your studio
- Template: a privacy note for your booking form
Data protection sounds like paperwork for large companies. In a tattoo studio it is very concrete: you know who has which allergy, who was pregnant, what somebody's thigh looks like and who never paid their deposit. That is exactly the kind of data whose loss really hurts, for your clients and for you.
What data does a tattoo studio actually hold?
Almost every studio underestimates the amount. Write down once where client data sits and you quickly reach six or seven places.
- Contact details: name, phone, email, Instagram handle, sometimes a postal address.
- Appointment data: motif, placement, size, price, deposit, who was where and when.
- Health answers from the consent form: allergies, medication, existing conditions, pregnancy.
- Photos: before, after, healed, sometimes with a face, often with recognisable features such as scars or other tattoos.
- Payment data: amounts, payment methods, receipt numbers, and whatever sits with your payment provider for online payments.
- Chat threads: WhatsApp, Instagram DMs, emails, often with health details buried in the text.
Which rules apply in the EU and in Switzerland?
The GDPR applies in the EU, and in Switzerland the revised data protection act has been in force since 1 September 2023. For daily studio work both come down to the same principles. You do not need a data protection officer to meet them, you need order.
- Purpose limitation: you store data for the appointment, the treatment, documentation and billing, not just in case.
- Data minimisation: what you do not need, you do not ask for. Date of birth yes, blood type no.
- Security: access only for those who need it, devices locked, data encrypted, backups in place.
- Transparency: clients have to know what you collect and why. That is what the privacy policy is for.
- Access and deletion: clients may ask what you hold about them and request deletion, as long as no retention duty stands in the way.
Health data and photos: the two sensitive areas
Health answers are a special category of personal data. In practice that means they belong in a system with access control, not in a spreadsheet on the studio desktop and certainly not as a photo of the filled in form in a WhatsApp chat. In a studio with several artists, ideally only the person doing the appointment sees them.
Photos are the second area where things regularly go wrong. For your portfolio and Instagram you need consent that is voluntary, clear and revocable. Ask separately whether the face may be recognisable, because for many clients that is the real question. And remember that image files can carry metadata, including the location where they were taken.
Why WhatsApp and Instagram are not a client database
The chat is the most convenient place and the worst storage. If your phone goes missing, the client history is either gone or in someone else's hands, depending on how well it was locked. An account can be suspended, a chat thread cannot be searched properly, and health details in a DM are visible to anyone glancing at the screen.
The answer is not to ban the channel but to separate it: keep communicating in the chat, and keep the data in a system you can export, protect and clear out. What that looks like is in the article on client management in the studio.
How long do you have to keep client data?
| Data | Purpose | Basis | Retention |
|---|---|---|---|
| Contact and appointments | Fulfil the contract | Contractual relationship | As long as the client relationship lasts |
| Consent form with health answers | Prove you informed the client | Legal duty, legitimate interest | Austria sets 10 years, Switzerland and Germany follow liability periods |
| Receipts and invoices | Accounting | Statutory retention | Switzerland 10 years, Germany 8 years, Austria 7 years |
| Portfolio photos | Marketing | Consent | Until withdrawn |
| Newsletter addresses | Marketing | Consent | Until unsubscribed |
| Chat threads | Communication | Pre contractual contact | Clear out regularly, no collecting without a purpose |
The accounting numbers are fixed: Switzerland requires business records and receipts to be kept for 10 years, Germany 8 years for booking records and invoices and 10 years for books and annual accounts, Austria 7 years. Everything else is a decision you make once and then apply consistently.
The difference between must and may matters here. You must keep accounting records even if a client asks for deletion. Marketing data you may only keep for as long as the consent stands. Throw both into one pot and you end up deleting either too much or nothing at all.
The eight point checklist for your studio
- Privacy policy on your website and linked from the booking form, in plain language.
- Data processing agreements with your software providers, meaning your booking tool, newsletter service and payment provider.
- Check the data location: client data belongs in the EU or Switzerland, and you should be able to say where it sits.
- Access rights in the team: who needs which data? A guest artist does not need the history of every client.
- Lock your devices: passcode or Face ID on phone and tablet, screen lock on the studio computer, no shared passwords.
- Deletion plan: one sentence per type of data saying when it disappears. Without that sentence you never delete anything.
- Answer access requests: when somebody asks what you hold, it should take you an hour, not a week.
- Newsletter only with consent: a separate checkbox, never pre ticked, an unsubscribe link in every email. More in the newsletter article.
Template: a privacy note for your booking form
We store your details in order to arrange your appointment, document the tattoo and handle payment. Health answers from the consent form are treated as a special category of data and are not passed on to third parties. Accounting records are kept for as long as the law requires, everything else is deleted once we no longer need it. We only use photos of your tattoo if you agree separately. You can withdraw that agreement at any time, and it will not affect your appointment in any way. You can ask at any time what data we hold about you and request correction or deletion. Write to us at [email address]. The full privacy policy is available at [link].
Frequently asked questions
Do I need a privacy policy as a tattoo artist?
Yes, as soon as you have a website or a booking form where clients enter data. It explains which data you collect, what for, how long you keep it and what rights your clients have. Link it from the form and the footer so it is visible before anyone types anything in.
Can I post photos of my clients on Instagram?
Only with their consent, and it should be written and voluntary. Record it separately from the treatment consent and ask explicitly whether the face may be recognisable. If somebody withdraws consent, they are entitled to have the image removed from the channels you control.
How long may a tattoo studio keep client data?
As long as you need it for the appointment, documentation or accounting. Records have fixed periods: 10 years in Switzerland, 8 years for booking records in Germany, 7 years in Austria. Anything without a fixed period, such as old chats or marketing data, goes as soon as the purpose is gone.
Is WhatsApp allowed for client communication in a studio?
Many studios use it to arrange appointments. It becomes a problem when health answers, ID photos or entire client lists end up there and stay forever. Use the chat as a channel, keep the data in a system with access control, and clear out old threads regularly.
What do I do if a client asks for a copy of their data?
You have to tell them which data you hold, what for and for how long, and give them a copy on request. Answer promptly, in the EU one month is the usual limit. A system you can export a client and their history from turns this into a matter of minutes.
By the Taddoo team, built by artists and booking managers for artists. Published September 9, 2026, last updated September 9, 2026.




