How much data can I gather?
You also need to consider other aspects of data protection.
Be proportionate – only gather and use Covid-19 data where you need to.
Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.
Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).
Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.
Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.
Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.
Related FAQs
You should speak to your advisors. We do not know presently how existing petitions will be dealt with by the Court. We do know that if any winding up order is made (based on a petition presented after 27 April), it could be found to be void and a creditor may face challenges. Even for petitions presented before 27th April, there is a risk that the Court will not be keen to make a winding up order so it is important that you look at the facts of your debt and weigh up all of the factors before deciding how to proceed.
The CMA is particularly concerned about certain activities, its guidance highlights:
- Exchange of commercially sensitive information where this is not necessary in response to the crisis
- Collaboration which unfairly excludes third parties
- Abuse of a dominant position (including a dominant position held as a result of the crisis) – particularly to charge excessive prices
- Seeking to maintain prices or prevent reductions in prices
- Cooperation going beyond what is necessary to respond to the crisis in the interests of consumers
The BBC
The national broadcaster’s collated content surrounding the Covid-19 pandemic:
https://www.bbc.co.uk/news/coronavirus
and with regards to business:
https://www.bbc.co.uk/news/business
The Chancellor announced that employers will be given £2,000 to employ apprentices and £1,500 for apprentices over the age of 25 for each apprentice they hire from 1 August 2020 to 31 January 2021. These payments will be in addition to the existing £1,000 payment the Government already provide for new 16-18 year old apprentices.
He also announced that employers would be given £1,000 for taking on trainees in response to the traineeship scheme being extended.
The guidance is helpful and is likely to be useful to businesses as they seek to respond to the crisis and to restart their business activities as lockdown is eased. However, there remain outstanding questions. For example, can collaboration to prevent widespread insolvencies be viewed as in the interest of consumers? Businesses need to remain aware of the extremely high stakes involved in relation to competition law. Businesses contemplating collaboration with competitors should take legal advice before doing so.