Guide
Tattoo consent forms and GDPR in the UK: what studios should keep
By Steven Graham, tattoo artist ·
This article is general guidance for tattoo artists and studios in the UK. It is not legal advice. It does not replace advice from your local authority, your insurer or a solicitor. Rules differ by area, so always check what applies to you.
Every tattoo studio collects personal information. Some of it, like health details, is sensitive. Handling it carefully protects your clients and protects you if something is ever questioned. Here is a practical way to think about it.
What a consent form usually records
A consent form is both a legal safeguard and a safety check. Most studios record the following:
- The client's full name, contact details and date of birth
- Confirmation that they are 18 or over and how you checked
- Health questions covering allergies, skin conditions, medication, blood thinners, pregnancy and anything else relevant to healing
- The design, placement and date of the appointment
- A statement that they understand the risks and the aftercare advice
- Their signature or digital signature and the date and time it was given
- The name of the artist who carried out the work
Your local authority or your insurer may ask for more or may have preferences about format. If you are unsure, ask your environmental health team what they expect to see during an inspection.
Health information is special category data
Under UK GDPR, information about someone's health is classed as special category data. That means you need a lawful basis for collecting it and an additional condition for handling it. In practice, tattoo studios usually rely on the client's explicit consent, given clearly on the form, for the health questions they ask. The Information Commissioner's Office (ICO) publishes plain guidance on special category data and it is worth reading once.
The principle to keep hold of is data minimisation. Only ask for what you genuinely need to tattoo someone safely. If a question does not change how you work, remove it.
Tell clients what you do with their information
Clients should be able to find out who you are, what you collect, why you collect it, how long you keep it and how to contact you about it. This is usually a short privacy notice linked from your booking form and consent form. Write it in plain English. A single page is enough for most studios.
How long should you keep records?
UK GDPR says you should not keep personal data for longer than you need it. It does not set a single number of years for tattoo records. Some local authorities, trade bodies and insurers suggest keeping consent forms for a period of years, partly in case of a claim, but the guidance varies. The sensible approach is to:
- Ask your local authority and your insurer what they recommend
- Pick a retention period and write it down
- Apply it consistently, rather than keeping everything forever by default
- Review old records on a regular schedule and delete or anonymise those past their date
If a client was under 18 when a parent or guardian was involved in an enquiry, take extra care with what you hold and why.
Proof of age
You need to check age, but you do not necessarily need to keep a copy of someone's passport or driving licence. Many studios view the ID, record that it was checked and note the type of document, rather than storing an image. Holding fewer copies means less to protect and less to lose.
Keep records secure
Paper forms in an unlocked drawer and photos of forms in a phone camera roll are both common and both risky. Whichever format you use, think about who can see it, how it is protected and what happens if a device is lost or stolen. Use strong passwords, switch on two step verification where it is offered and make sure backups are protected too. If you work in a shared studio, check that other people cannot browse your clients' records.
If you use a booking or forms tool, check where it stores data, whether it is encrypted and whether you can export or delete records when you need to.
Client rights
Clients can ask to see the information you hold about them, ask for mistakes to be corrected and in some cases ask for it to be deleted. You normally have one month to respond to a request. Deletion is not absolute. You may have good reason to keep a consent form for longer if you need it to deal with a claim or to meet a requirement from your local authority. If you decline part of a request, explain why plainly.
Marketing is separate
Consent to be tattooed is not consent to receive promotions. If you want to send marketing texts or emails, ask for that permission separately, make it optional and make it easy to opt out. Do not tick the box for people. Aftercare messages and appointment reminders are a different matter from newsletters, but keep the line clear in your own mind.
Do you need to register with the ICO?
Many businesses that handle personal data need to pay a data protection fee to the ICO, though some are exempt. The ICO has a short self assessment on its website that will tell you where you stand. It takes a few minutes.
If something goes wrong
A lost phone, a misdirected email or a hacked account can all count as a personal data breach. Some breaches must be reported to the ICO within 72 hours, so it helps to know the steps in advance. Write down who you would tell and what you would check.
Making it easier
Digital consent forms can help because they are timestamped, easy to find and kept in one place with the client's booking. StudioBuilder includes signed consent forms stored against each client, with printing for inspections. Whatever you use, the same questions apply. Collect only what you need, tell clients what you do with it, keep it safe and review it regularly.