What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
Changing to shift working may give employers the opportunity to change hours / pay whilst also focusing work when it is needed. Like the other provisions, this should be done fairly, either across the board or by selecting teams/individuals based on objective business reasons. Imposing without agreement would create significant risk, therefore would require fair selection and consultation.
The basics of health and safety law requires that employers take “all reasonably practicable steps” to ensure workers’ safety and that a suitable and sufficient assessment of risk is undertaken. It is the individual assessment of Covid-19 risk in each workplace that will be central. Employers will be required to conduct a robust risk assessment and then, following the hierarchy of controls, put robust processes and safeguards in place to address those risks.
UK government guidance and HSE advice is continually evolving, which in practice means that any risk assessment will need to be reviewed very regularly as that guidance develops. There is flexibility for individual businesses within the overall government framework and there will need to be a process of evaluation to ensure that the measures in place continue to meet the requirements.
The starting point of avoid, eliminate and control means looking at individuals continuing to work from home where possible (the fewer the number of people back in the workplace the lower the risk), and if not look at risk management, which leads to administrative controls – i.e. changing work practices before ending up at PPE. PPE is generally seen as control of last resort but in practice – facemasks, disposable gloves and constant prompts to wash hands for example.
In terms of changing working practices, employers should be thinking about:
- the workspace and how this is laid layout
- how do we make sure it is kept clean and hygienic
- how do we keep people apart
- how can we use toilets, canteens or other shared spaces/facilities safely
- how do we promote and enable higher levels of workplace hygiene
- if we are going to rely on PPE – can we get it, and is it suitable
- what about limiting customer interactions
- will there be enough first aiders on site
- can we manage fire safety, deliveries etc
- what about higher risk workers
- should work tools and equipment be allocated on an individual basis to employees.
These decisions need to be recorded and clearly communicated to staff members.
Many policies will only provide business interruption cover if it arises from property damage. The FCA has acknowledged that insurers are entitled to reject claims in relation to such policies, notwithstanding the success of the FCA’s test case in the Supreme Court, and which was generally favourable to policyholders [Insert a link here to our update on the test case]. In other cases the policy wording will be less clear and businesses may legitimately feel that their insurer is wrongly withholding payment.
One route of challenge to an insurer’s decision is via one of the well-publicised class actions. Another route of challenge is by a complaint to the Financial Ombudsman Service (FOS). This service is open to consumers and small and medium-sized businesses, ‘micro-enterprises’, charities and trusts. The service will be an attractive option for many businesses, as it is free and relatively quick (although it remains to be seen how the service keeps up with an increase in demand as a result of the pandemic). You will need to have complained to your insurer before bringing a complaint with the FOS.
Further details can be found here.
It is a theoretical possibility that “anti-vax” beliefs could be a philosophical belief under the Equality Act 2010 and therefore anti-vaxers have the right not to be discriminated against for their beliefs. Much will depend on why the individual is against the vaccine. Conspiracy theorists (the vaccine is being used as an opportunity to monitor you or it’s all because of 5G) are highly unlikely to be treated as having a philosophical belief!
If your 30-day visa to travel to the UK (vignette) has expired or is about to, you can request a replacement free of charge until the end of 2020 by contacting the Coronavirus Immigration Help Centre. This can be granted with new and extended validity dates to allow travel once you are able to.