Booking Software and GDPR Responsibilities
Accept bookings while maintaining a clear process for personal data. SchedulingKit provides booking records and a Data Processing Addendum; your business remains responsible for its lawful basis, privacy notices and responses to client rights requests. SMS opt-in is separate from the legal basis for processing an appointment.
Booking software supports your data-protection process; compliance depends on your use and obligations. Accept bookings while maintaining a clear process for personal data. SchedulingKit provides booking records and a Data Processing Addendum; your business remains responsible for its lawful basis, privacy notices and responses to client rights requests. SMS opt-in is separate from the legal basis for processing an appointment.
What GDPR Requires
The GDPR sets requirements for processing personal data where the regulation applies. Appointment processing needs an appropriate lawful basis, which may be a contract, consent or another applicable basis; consent is not the only option. Businesses must give appropriate notices, protect data and respond to applicable access, erasure and portability requests. Portability and erasure have conditions and exceptions. Processing health data or other special-category data also requires an applicable Article 9 condition; an ordinary appointment-processing lawful basis alone is not enough. Software features support these responsibilities but do not establish compliance by themselves.
How SchedulingKit Supports GDPR
Consent Management
Booking forms include configurable consent checkboxes for data processing, marketing communications and cookie usage, with timestamped consent records. Document the lawful basis and notices appropriate to each purpose separately.
Right to Erasure
Process client erasure requests through an authorized dashboard workflow covering personal information, booking records and intake data. Apply retention exceptions and legal holds, and record the outcome; the Data Processing Addendum describes assistance with individual rights requests.
Data Portability
Export applicable client personal data and booking history in machine-readable JSON or CSV through the dashboard. Review each request: GDPR portability applies to data the person provided, processed automatically on consent or contract grounds. Access rights have a different scope; the Data Processing Addendum describes assistance.
Data Processing Agreement
SchedulingKit provides a DPA describing processor obligations, subprocessors, security responsibilities and assistance with rights requests. Review the separate GDPR/privacy information for international-transfer safeguards and confirm the arrangements applicable to your account.
Cookie Consent Integration
Embedded booking widgets include configurable cookie-consent controls. Assess cookies and storage used by the host site and embedded services and provide the notices and consent settings required for your deployment.
Data Minimization
Configure booking questions to collect the information needed for the service, and avoid collecting unrelated sensitive information. Review optional fields, staff access and retention as part of your data-minimization process. Form configuration alone does not establish an automatic retention or deletion schedule.
Industries Handling Booking and Client Data
Frequently Asked Questions
Explore More Resources
Compliance
Plan Your Booking Data Responsibilities
Configure your booking process and review the Data Processing Addendum, privacy notices and safeguards that apply to your business.
Free forever plan available • No credit card required
When this isn't for you
This is not for you if GDPR compliance doesn't apply to your business. Generic compliance content doesn't substitute for legal advice tied to your specific operation. Skip and consult counsel if regulatory risk is your priority.