How much data can I gather?
You also need to consider other aspects of data protection.
Be proportionate – only gather and use Covid-19 data where you need to.
Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.
Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).
Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.
Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.
Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.
Related FAQs
Where a development is considered to be “EIA development” (being development where an Environmental Impact Assessment or Environmental Statement is required to be submitted) there are additional statutory publicity and notice requirements over and above the requirements for a standard planning application. Regulations usually require that the environmental statement is to be made available for inspection by the public at all reasonable hours at an address in the locality for a period of at least 30 days. Copies of the environmental statement are also to be made available for people to take away from that address. This clearly requires physical copies to be available at a specified location for a prolonged period of time, which may prove problematic during the current health crisis.
New regulations came into effect on 14 May 2020 which will temporarily suspend the above requirements and will instead require the Environmental Statement to be available for inspection online. The applicant must however provide a certificate to the Local Planning Authority stating what steps have been undertaken to bring the application (and the Environmental Statement) to the attention of people who are likely to have an interest and why it considers that such steps were reasonable.
No. No action need be taken in relation to the demand but we would advise against presentation of a petition based upon any Statutory Demand issued between 1 March 2020 and the end of the restrictions. As you may be aware, with Winding Up there is no requirement to issue a Statutory Demand notice before proceeding so this is unlikely to create too many issues – click here to see whether you should issue petitions on other grounds.
There is nothing to prevent statutory demands being served at this time. However, there may be limited benefit as it cannot form the basis of a future winding up petition.
As we all adjust and adapt in line with the Government’s guidance throughout this uncertain time, we must consider how we can revise current processes and implement new ones to maintain effective and compliant ways of working. We have identified several key issues that all housing providers should consider.
Protocol Compliance
Housing providers will continue to receive new disrepair claims. Throughout the disruption caused by coronavirus, landlords will still be expected to respond to these claims and comply with the Pre-Action Protocol for Housing Conditions Claims whilst doing so. We address the issue of disclosure in particular below.
Letters of claim will continue to be sent by post to your Registered Office, and the deadlines will run from the date of deemed service. Ensure you have systems to enable you to scan correspondence and forward it to the responsible officer who will handle the claim so deadlines are met.
Under the Protocol, the deadline for disclosure is 20 working days from deemed service of a letter of claim (2 working days after it is sent). So, for example, a letter dated 2 March 2020 would be deemed served on 4 March 2020 and disclosure would therefore be due by 1 April 2020. All housing providers must continue to comply with the Protocol and so landlords should begin preparing now.
Failure to meet deadlines often result in the issuing of further applications to court by tenant’s solicitors which in turn will lead to unnecessary costs orders against landlords.
Therefore, all records, particularly relating to customer contact and repair logs, should be held electronically. If required, this will allow for such documentation to be redacted for GDPR purposes remotely and disclosed to the tenant’s solicitor simply and efficiently.
Remember it is possible to request an extension to all Protocol deadlines and it is inevitable in these unusual times, this will need to be utilised, and should not be refused. Request extensions to deadlines at the earliest opportunity to enable an achievable timescale. It would be a difficult lawyer that would not agree to such a request.
Small suppliers (defined by reference to certain financial indicators) are temporarily exempt from these new restrictions until 30th March 2021 in order to account for the difficulties to small suppliers during the Covid-19 pandemic.
There are also certain industries that are exempt from these restrictions (for example financial services). The Secretary of State may also create further exemptions framed by reference to kinds of company, supplier, contract, goods or services or in any other way.
State aid rules are contained in the Treaty on the Functioning of the European Union (previously referred to as the Treaty of Rome). The State aid rules prohibit the use of state resources, or any public support with an economic value, which given selectively has the capacity to distort trade by favouring certain undertakings, or the production of certain goods, and which has the potential to affect trade between Member States. Where aid is present it must not be granted unless it has been specifically approved in advance by the European Commission or benefits from a general exemption to the rules.
In general, the rules apply to all State actions which might assist businesses including:
- Grants
- “Soft” loans
- Selling to business at an undervalue
- Buying from business at an overvalue