You are allowed to store personal information when it’s essential to providing an ongoing service. It’s when clients leave and you still have their data 3 years later that it can become a problem. However, for insurance and tax purposes, you still need to store a certain amount of client data for a specific time.
According to nhf you need to keep colour records and patch test records for 4 years