Will the golden thread requirements in relation to maintaining a central record of building info be retrospective?
The golden thread requirements will be retrospective, so will apply to existing buildings as well as new build. This is part of the reason for the Building Safety Regulator’s ‘get to know your building’ guidance referred to in the talk, with the link in the Powerpoint presentation. While the details of the golden thread requirement are still to be confirmed, now is a good time to start to gather as much information as can be obtained about existing buildings as possible in preparation. The Government guidance anticipates that the Principal Accountable Person will be responsible for developing and coordinating the golden thread for existing buildings.
Related FAQs
It is almost impossible to completely guard against the risks associated with contractor insolvency, but there are some steps which can assist in mitigating and managing the risks involved. To be in the best possible position, it is worth considering the following at the outset of any project:
- Check the contractor’s financial position – particularly the specific company which will enter into the building contract, as the employer’s rights will be against this company rather than the business as a whole
- Take legal advice to ensure that the building contract is properly drafted with appropriate provisions to deal with an insolvency event
- Consider requiring a performance bond and/or parent company guarantee (each serve slightly different purposes)
- Obtain collateral warranties from the consultants and sub-contractors involved, so that there are contractual rights against other parties if the contractor is no longer able to meet claims
- Consider requiring retention bonds, advance payment bonds or vesting certificates if necessary
- Project bank accounts and escrow accounts can also provide some further assurances for the parties involved
In practice this means that any risk assessment will need to be reviewed constantly and adjusted as our understanding of the nature and level of the risk grows.
Some service-providers are instigating special Oversight Groups to keep this issue under review but engagement and consultation with those affected is critical and making sure they feel confident to raise concerns and refuse to work if they believe they are not safe.
The Home Office has not stated when it will end these temporary measures, albeit it has stated that it will provide a warning. Where employers have carried out checks using the temporary measures, the Home Office has confirmed that it will require employers to carry out retrospective checks on any of the following:
- Employees who started working for you when the temporary measures were in place
- Employees who required a follow up check during the temporary measures (for example because their previous leave was coming to an end).
It is not explicit from the guidance but these retrospective checks must require you to have in your possession the physical ID in its original form. When carrying out the retrospective check, employers must record this using the following wording “the individual’s contract commenced on [insert date]. The prescribed right to work check was undertaken on [insert date] due to Covid-19.”
These further checks must be made within eight weeks of the temporary measures ending, and employers must keep records of both checks undertaken. Where the employer discovers that the employee does not have the right to work during the retrospective check they should stop employing them.
Hosted by NewcastleGateshead Initiative, Partners Damien Charlton and Jane Garvin discussed in this webinar contracts, managing supply chains and the role of directors, with a particular focus on cancellation of events and businesses in the tourism and hospitality sector.
You can find a recording of the webinar from NGI here.
If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:
- If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
- Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
- Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
- Ensuring staff lock their devices whenever they are not using them
- Where possible, working in a separate part of the home to family members
- Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
- Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
- Locking any papers in a safe place
- Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
- Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
- Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
- Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example
Organisations should also ensure that their remote access systems can cope with increased demand.
Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.
We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.