美业开始吧Meiye Kaishiba 中文
English operating record

Measures on Personal Information Protection Compliance Audits Take Effect: What Should Beauty Salons Know About Managing Customer Data?

The Measures for the Administration of Personal Information Protection Compliance Audits are now in effect. When beauty salons handle customer files, facial photographs, transaction records, and employee handovers, they should pay closer attention to limitations on purpose, access, and retention.

Regulation · July 18, 2026

The Measures for the Administration of Personal Information Protection Compliance Audits, issued by the Cyberspace Administration of China, took effect on May 1, 2025. Most beauty salons may not process data on the same scale as large platforms, but they routinely handle customers’ names, contact details, transaction records, skin conditions, facial photographs, and service feedback. If this information is casually forwarded, privately retained, or used for promotional purposes, it can easily create compliance risks and undermine customer trust.

Update Summary

Publication date: February 14, 2025. Effective date: May 1, 2025. Jurisdiction: Nationwide. Current status: Departmental regulation in effect. Primary official source: the Measures for the Administration of Personal Information Protection Compliance Audits issued by the Cyberspace Administration of China.

Key Changes and Rules

The Measures set out requirements for personal information processors to conduct personal information protection compliance audits and include compliance audit guidelines. Beauty salons should not simply assume that the Measures are relevant only to large companies, because managing customer data is itself part of maintaining customer trust. Even without complex systems, a salon should know why each type of information is collected, who may access it, how it is handed over, and when it must be deleted or no longer used.

Practical Impact on Beauty Salon Operations

Customer files can help salons maintain continuity of service, but the more information they hold, the clearer their management responsibilities become. Customer photographs, skin records, prepaid account information, and transaction details should not be scattered across employees’ personal phones, chat groups, or unauthorized spreadsheets. Real customer records used for training or case reviews should, wherever possible, be stripped of unnecessary names, telephone numbers, photographs, and transaction details.

Which Salons Should Pay Particular Attention?

Salons that use CRM systems or shared spreadsheets to manage customers, regularly take customers’ facial photographs for before-and-after comparisons, experience high employee turnover, or use customer cases for promotion on WeChat Moments or in community groups should prioritize reviewing data access permissions and restrictions on use.

What Should Be Reviewed Now?

  • Whether customer data collection is limited to information required to provide services.
  • Whether the purposes for using facial photographs, health information, and other data are clearly defined and access is appropriately restricted.
  • Whether access to customer data is promptly adjusted when an employee leaves or changes roles.
  • Whether customers’ explicit consent has been obtained before cases are displayed or posted on WeChat Moments.

How Can Salon Managers Conduct a Spot Check of Data Access Permissions?

A manager can randomly inspect ten customer files to determine whether they contain unnecessary identity document information, full home addresses, private photographs, or evidence that transaction details have been shared externally. The manager can then inspect employees’ phones, shared spreadsheets, and work-related chat groups to confirm whether customer photographs, contact details, or service records have been retained for extended periods. If problems are identified, the salon should first disable unnecessary access, delete copies that are not required for business purposes, and then incorporate rules specifying “who may access the information, why they may access it, and for how long” into its internal management policies.

What Conclusions Should Not Be Drawn at This Stage?

This update should not be interpreted as requiring salons to purchase complex systems immediately, nor should salons independently establish retention periods that are unsupported by authoritative sources. A more prudent approach is to first clarify the purposes of collection, employee access permissions, records of use, and customer consent procedures. Professional advice should be sought when disputes arise or sensitive information is involved.

Next Operational Steps

A salon can begin by creating a simple access-permission table specifying which customer information the owner, manager, beauticians, and front-desk staff may view, which information may be used only to provide services, and which information must not be shared externally. Customer photographs, service feedback, and membership records should then be transferred from employees’ personal devices to tools centrally managed by the salon. This step does not directly increase sales, but it can reduce operational losses resulting from employee turnover, accidental publication of customer cases, and customer complaints. For employees who have already left, the salon should also check whether they can still access customer data and retain a record of the handover outcome. Salons should not distribute complete customer files directly through employee chat groups for training purposes. If customer cases are genuinely required for training, the salon should first apply the necessary de-identification measures and restrict access. Employees should also be informed whenever new spreadsheet permissions are granted, and permissions should be reviewed regularly.

Related Operational Guides, Tools, and Templates

Salons can first use How Should Beauty Salons Manage Customer Privacy and Information? to review privacy protections and access permissions, and then consult How Should Beauty Salon Customer Management Forms Be Completed? to standardize customer file entries. To turn data management into a long-term operational capability, continue reading How Can a Beauty Salon Build a Customer Management System? If the data relates to prepaid membership accounts, salons should also consult What Should Beauty Salons Know About Prepaid Memberships and Service Contracts?

Official Source

Cyberspace Administration of China: Measures for the Administration of Personal Information Protection Compliance Audits

This English article is connected to the site's published source record. Open the source record for the original reference.

Continue with another operating question.

Return to the English library