GDPR and Client Consents

Client Data Breach - When to Report to UODO in 72 Hours [2026]

Client Data Breach - When to Report to UODO in 72 Hours [2026]

A lost phone with your client base, a hacked booking account, a client card in the wrong hands. When a breach register entry is enough, and when you have 72 hours to report to UODO.

Client Data Breach at Your Salon - When to Report to UODO Within 72 Hours [2026]

A lost phone with your client contact list, a hacked booking system account, a notebook with appointments left at the front desk, a client card photo sent to the wrong person. Each of these is a potential personal data breach, and the GDPR gives you very little time to react. This article walks you through the first hours after an incident: when you must report the breach to UODO (the Polish data protection authority), and when an entry in your internal breach register is enough. The basics of handling client data are covered in our guide to GDPR-compliant client records.

What counts as a data breach in a beauty salon

A data breach is not just a spectacular hacking attack. In the daily life of a nail, brow or lash salon it is usually a small, everyday slip involving your clients' personal data: names, phone numbers, e-mail addresses, visit history, and sometimes health information from the pre-treatment interview.

  • Loss of a device: a lost or stolen phone with client contacts and messages, a laptop with your booking spreadsheet, a USB stick with copies of client cards.
  • Unauthorized access: a break-in to your booking system account, a hijacked salon social media profile, a former employee who still has access to the client base.
  • Human error: a message with one client's data sent to another, a client card left on the counter in view of other people, a photo with visible personal data published in a story.
  • Loss of paper documents: a soaked or lost binder with client cards and consents, documents thrown into a regular bin without shredding.

The common denominator is simple: your clients' personal data ended up where it should not be, or you lost control over it. Whether the incident must be reported depends on the risk to the people affected - and that risk assessment is exactly what you need to be able to carry out and document.

The 72-hour rule - how the clock runs

The GDPR requires a personal data breach to be reported to the supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it - unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

The key phrase is "becoming aware". The clock does not start when your phone falls out of your bag, but when you learn about the incident and have enough knowledge to conclude a breach occurred. That does not mean you can delay verification - if you suspect a problem, you must check it promptly. The 72 hours include weekends and public holidays, so a Friday evening incident does not push the deadline to Wednesday.

Three scenarios: register, UODO report, notifying clients

The GDPR provides three levels of reaction depending on risk. The table below shows typical salon situations and the usual level of response. Treat it as a starting point for your own assessment, not an automatic rule - every case is assessed individually and the conclusions are written down.

Salon example Breach register entry Report to UODO Notify clients
Lost phone protected by a passcode and encryption, remote wipe available Yes Usually not, if the data stayed inaccessible Usually not
Stolen unprotected laptop with client cards and health interviews Yes Yes Yes, if the risk to clients is high
Message with one client's data sent to another client Yes Depends on the scope of data and possible consequences Contacting both people is usually enough
Booking system account hacked with the full contact base Yes Yes, if the data may have been copied Yes, where there is a high risk of misuse

Remember the rule: you always keep the breach register, regardless of whether the incident qualifies for reporting. You also record the events you did not report, together with the reasoning why you assessed the risk as low. That register is your shield during a possible UODO inspection - it shows you manage incidents consciously instead of ignoring them.

The first 24 hours - an action plan

Step 1: stop the leak

Before you document anything, limit the damage. Change the passwords to your booking system and mailbox, trigger a remote wipe of the phone, revoke a former employee's access, delete the accidentally published photo. Every hour of delay increases the risk and weakens your position when the incident is assessed.

Step 2: establish the facts and assess the risk

Write down: what happened, when, what data is involved, how many clients, whether the data was protected (password, encryption), and who could have accessed it. When assessing the risk, consider the nature of the data - a phone number is one thing, a health interview from the client card, with notes on allergies or skin conditions, is another. Health data is a special category, and its leak almost always means higher risk.

Step 3: decide about the report

If your assessment shows a risk to clients, you report the breach to the President of UODO. The report is submitted electronically through the authority's website. You describe the nature of the breach, the categories and approximate number of people affected, the possible consequences, and the measures you have taken. If you do not have all the information yet, you can submit a preliminary report and complete it later - better than missing the deadline.

Step 4: inform clients if the risk is high

Where the risk is high (for example a leak of health data or data enabling impersonation), you must notify the people affected. Use plain language: what happened, what data leaked, what you are doing, and what the client can do herself, such as watching out for suspicious messages. A difficult message sent quickly and honestly builds more trust than silence that comes out later.

How to reduce the risk before anything happens

  • Secure your devices: a passcode and encryption on the phone and laptop, a separate salon account instead of a private one, two-factor login for the booking system and e-mail.
  • Limit the data you collect: gather only what you genuinely need for the treatment and contact. Less data means less harm in an incident.
  • Organize paper documents: keep client cards and consents in a lockable cabinet, not at the front desk. Shred old documents instead of binning them whole.
  • Control access: each employee has her own login, and access is revoked the same day cooperation ends. Put the data-handling rules in writing, just like consents for publishing photos on social media.
  • Prepare a breach procedure: one page with an action plan and a breach register template means you do not have to invent anything under stress.

Frequently Asked Questions

Do I always have to report a lost phone with client numbers to UODO?

Not always. If the phone was protected by a passcode and encryption, and you triggered a remote wipe quickly, the risk to clients may be low and an entry in the internal breach register with your reasoning is enough. If the phone was unprotected and contained correspondence and health data, a report will usually be necessary.

Who reports the breach if the leak happened on the booking platform's side?

The booking system usually acts as a processor handling data on your behalf, while you remain the controller of your clients' data. The platform must inform you about the breach, but the risk assessment and any report to UODO are your responsibility as the controller. That is why it is worth knowing how quickly your provider notifies about incidents.

What happens if I fail to report a breach on time?

Failing to report a breach that should have been reported can result in an administrative fine and weakens your position in any further inspection. The amount depends on the circumstances, scale and severity of the breach. In practice, losing your clients' trust when they learn about the leak from someone else can hurt just as much.

Do I need a breach register if nothing has ever happened?

You set up the register as part of your GDPR documentation and keep it on an ongoing basis - if there have been no incidents, it simply stays empty. What matters is that it exists and that you know what to record when something happens. During an inspection it shows you have an incident management process in place instead of improvising.

Want your salon's GDPR documentation ready for every scenario? NailsReady packages include GDPR consent templates, client cards, registers and procedures tailored to nail, brow and lash salons - including the documents inspectors ask about. Save time and avoid costly mistakes.

See NailsReady packages

Monthly email with updates

What changed in Sanepid, RODO and OSH - one email per month. No spam, no course pitches.

How we process your data is described in the Privacy Policy.