Skip to content

Understanding of the extent of the Covid-19 risk to BAME colleagues is evolving – what does that mean for NHS employers?

In practice this means that any risk assessment will need to be reviewed constantly and adjusted as our understanding of the nature and level of the risk grows.

Some service-providers are instigating special Oversight Groups to keep this issue under review but engagement and consultation with those affected is critical and making sure they feel confident to raise concerns and refuse to work if they believe they are not safe.

Related FAQs

Should I have a homeworking policy?

If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:

  • If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
  • Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
  • Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
  • Ensuring staff lock their devices whenever they are not using them
  • Where possible, working in a separate part of the home to family members
  • Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
  • Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
  • Locking any papers in a safe place
  • Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
  • Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
  • Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
  • Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example

Organisations should also ensure that their remote access systems can cope with increased demand.

Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.

We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.

If an employer identifies that higher PPE spec is required for BAME employees undertaking a particular task, is it necessary to increase the spec for all employees working in that area?

It is. If you assess a risk and identify a control measure then fail to deploy it, then you are breaching your legal duties under HASWA and potentially committing a criminal offence. So if you decide for example that N95 respirators have to be used by everyone, you have a duty to provide them.

So the short answer is yes.

If an employee has had a coronavirus test, can we require them to disclose evidence of their test results?

Obtaining an employee’s Covid-19 test result will amount to processing personal data for the purposes of the General Data Protection Regulation 2016/679 (GDPR) and information about an employee’s health is a special category of data (sensitive personal data under the Data Processing Act 2018 (DPA)).

In accordance with the GDPR and DPA, there must be lawful grounds for processing such information. Most employers rely on employees’ consent to obtain medical information and process sensitive personal data and if the employee is unwilling to give consent, you will not normally be entitled to the information.

Special category data can be processed lawfully if it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. Employers may be able to require an employee to disclose their Covid-19 test if there is a substantial public interest, such as ensuring that the employee self-isolate if they have a positive test. However, there is a risk that this measure could be considered disproportionate particularly if it is enforced on all employees as a blanket measure.

What should I do if the contractor is in suspected financial difficulty?

In the event that the contractor is displaying one or more of the above signs, then it is worth considering the following actions to protect the employer’s position as far as possible:

  • Closely monitor the financial and on-site performance of the contractor in order to assess the likelihood and timing of potential insolvency
  • Ensure all bonds, guarantees and collateral warranties have been obtained under the building contract, and if not take steps to obtain them immediately
  • Consider the terms of any guarantees to ensure that the guarantor’s obligations are not inadvertently discharged
  • Bonds may require adjudication to have been commenced (or even completed) prior to insolvency so as not to be stayed pursuant to insolvency laws
  • Carry out an audit of the on-site plant, equipment and materials, and evidence this (for example with photographs and written records)
  • Ensure that copies of all relevant documentation have been obtained, for example drawings, specifications and anything required to comply with CDM requirements. If not, take steps to obtain these
  • Review the payment position under the building contract, including whether any over payments have been made to the contractor which should be reclaimed, what retention is held or has been released, whether any payment notices may be necessary, and whether there are rights of set-off which should be exercised
  • Check whether the involvement of any third party is required, for example funders, landlords, tenants or purchasers who may have rights in relation to the building contract and how it is administered
  • Review the terms of the building contract relating to contractor insolvency – hopefully the parties will be fully aware of the building contract terms and have been administering it correctly to date, but if it has been hiding in a draw then now would be a good time to dust it off and ensure familiarity with the relevant provisions!

In general. there is often a stick or twist decision.  If the employer chooses to financially support the contractor (for example by agreeing different payment arrangements), this may help to keep the contractor solvent and more likely to complete the project, but it also exposes the employer to greater risk if the approach is not successful.  Conversely, withholding payments  from the contractor may make insolvency a self-fulfilling prophecy.  The precise advantages and disadvantages of the approach will be dependent on the specific circumstances of each case.

What is defined as a redundancy?

It is where the need for a role at a specific site, or the number of people performing a role, has ceased or diminished or the site closes down.