Skip to content

How much data can I gather?

You also need to consider other aspects of data protection.

Be proportionate – only gather and use Covid-19 data where you need to.

Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.

Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to  make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).

Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.

Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.

Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.

Related FAQs

Whilst my creditors have been very understanding so far, I am concerned about how I will pay my existing debts, the ongoing bills as well as finding the money I will need to get the business back on its feet. What should I do?

This is a concern for many businesses at the moment.

Firstly, the directors need to be mindful of their duties to creditors . Click here for further information on those duties and the measures introduced by the government to help support directors during these difficult times.

There is also a raft of funding and grants as well as commercial finance that might be available to you. Click here for further information or contact us if you would like to discuss further.

If you are coming under increasing creditor pressure, there are other options to explore like the new “moratorium” procedure, which allows viable businesses in financial difficulty to work with an insolvency practitioner to obtain at least 20 business days’ breathing space from creditors to allow the business to formulate a plan to deal with its financial problems.

If you have any concerns about the viability of your business you should speak to your advisors, whether that is your lawyers, accountants or an insolvency practitioner who should be able to help you.

What can I do if someone refuses to wear PPE for cultural and/or religious observance reasons?

Again, the primary point must be that an open dialogue is held with that individual to understand their concerns and to properly consider the impact that not wearing PPE will have on their abilities to undertake their duties. Consideration must be given as to whether there are any parts of their duties that they can undertake and whether they can remain in their role. Engage with the individual to ensure that you understand their point of view. What other duties can they do if they cannot do fulfil all the duties of their role?

How should I approach negotiations with my landlord?

Given the impact the Coronavirus is going to have upon the commercial property market, landlords will undoubtedly, as a matter of good commercial sense, will have to seriously entertain approaches from tenants seeking a rent suspension – notwithstanding there is no entitlement to the same under their lease.

Some landlords may decide it is better to waive or suspend rental payments over the short term rather than face their tenants going out of business and leaving them with an empty building in a flat or dead market.

A measure falling short of a rent suspension would be for the tenants to negotiate with their landlord’s monthly payments of rent rather than quarterly and for those monthly payments to be in payments arrears, rather than in advance.

Should volunteers be DBS checked?

There is not currently a requirement for MHFAs to be DBS checked.

What should businesses do now?

Many will have worked collaboratively with their suppliers and customers to deal with the immediate public health crisis. This will have meant offering flexibility as to contractual arrangements, whether in delivery dates, volumes of goods or services supplied, or even in the specification of what has been delivered.

If this is the case, it is important that businesses now do their legal housekeeping and make sure they have a proper record of what has been agreed. Unfortunately, our experience shows that many legal disputes arise out of amendments to contracts, typically where the parties to the contract each have a different view about what exactly they agreed to change.

We would therefore advise businesses to review any amendments that they might have agreed either verbally, by email, or otherwise, and consider whether they need to be captured in a more formal way which will make clear exactly what has been agreed to be varied, and (where appropriate) how long that variation will remain in force.

It’s also important to remember that some contracts contain provisions that set out specific requirements about how amendments are to be made. For example, they might require that amendments are made in writing (rather than verbally). These “No Oral Modification” clauses are commonly found in commercial contracts, and the courts have recently shown that they are willing to enforce them.

Failing to deal with amendments in accordance with contractual requirements could therefore have a serious impact on businesses as they recover from the disruption caused by the lockdown. If they end up in dispute with a customer or supplier, a business could find that the contract has not actually been amended in the way that they think – potentially leading to legal costs and liabilities at the worst possible time.