How much data can I gather?
You also need to consider other aspects of data protection.
Be proportionate – only gather and use Covid-19 data where you need to.
Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.
Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).
Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.
Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.
Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.
Related FAQs
If a business has been provided with a loan from 23 March on commercial terms, providing the borrower meets the CBILS eligibility criteria, lenders have been asked to bring these facilities onto CBILS wherever possible (e.g. where the lender is accredited to offer the same facility through CBILS) and changes retrospectively applied as necessary. Please contact us if this applies to you and we can review facilities and advise upon the potential changes that may be made retrospectively to the benefit of the business.
Many charities have money that are considered restricted funds which are given to the charity or raised for a specific purpose. The Charity Commission gives guidance on this, please see the link below. Depending on the circumstances in which these monies have been given to a charity or raised you may or may not be able to use them.
Monies raised in an appeal or specific fund raising campaign are unlikely to be available as it is likely to be impossible to get the permission of the donor to change the use. If however you have had monies donated for a specific purpose and you can identify the donor you can use these funds for general overheads and to pay wages etc. if you receive the donor’s specific permission to do so.
Yes, but as a last resort. In summary, the law requires employers:
- to assess the workplace risks posed to new or expectant mothers or their babies;
- to alter the employee’s working conditions or hours of work to avoid any significant risk to them;
- where it is not reasonable to alter working conditions or hours, or would not avoid the risk, to offer suitable alternative work on terms that are not “substantially less favourable”;
- where suitable alternative work is not available, or the employee reasonably refuses it, the employer should consider whether it is appropriate to suspend the employee on full pay.
Local government legislation formerly stipulated that councillors must be physically present to vote and this requirement has already led to the widespread cancellation of Council meetings. There is a limit to what can be achieved under the chair’s emergency powers and delegation to officers.
The Government has now legislated to allow for remote voting until 7 May 2021. The secondary legislation required was issued in draft on 2 April and has been in force since Saturday 4 April.
The legislation allows for committee meetings to go ahead where members and any members of the public attending remotely can all times “hear (and where possible see) and be heard (and where possible be seen) by the other members in attendance”.
It remains to be seen how many local authorities take up the opportunity to hold a virtual committee meeting. Concern has been expressed that the demographic of local councillors may mean that members have difficulty with the technological mechanisms for holding such meetings. However, the message from the Secretary of State is clear that wherever possible, the planning system should keep moving in these current times.
As an occupier of premises, you owe a duty of care to your visitors to take reasonable care to see that the visitor will be reasonably safe in using your premises.
It is therefore essential that you are taking reasonable steps and strictly adhering to up-to-date Government advice in all aspects of your business to avoid any potential liability.
Failure to follow Government advice could leave you vulnerable to claims for compensation for pain and suffering should a visitor on your premises contract Covid-19.
However, each case will be fact-specific and it would be very difficult for a visitor to establish that they contracted Covid-19 specifically from those premises (as opposed to being exposed to the virus anywhere else).
If someone suggests that they are going to make a claim make sure that you report matters to your insurer or insurance broker immediately.