Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

What type of agreements are we talking about?

To respond to the crisis businesses might need to exchange information to a greater extent than they would usually. They might need to discuss capacity and to coordinate supply chains (both upstream and downstream). They might need to purchase or sell jointly to ensure vital supplies are maintained. In general agreements or collaboration which:

  • Avoid a shortage, or ensure security, of supply
  • Ensure a fair distribution of scarce products
  • Continue essential services
  • Provide new services such as food delivery to vulnerable consumers
How does salary sacrifice affect the Government's Coronavirus Job Retention Scheme?
  • Employee pensions contributions are often paid by way of salary sacrifice arrangements.
  • Use of such arrangements may reduce the amount of wage an employer can claim under the Coronavirus Job Retention Scheme, as the reimbursement is calculated by reference to an employee’s actual pay as at 28 February 2020, hence post sacrifice pay.
  • Using the Coronavirus Job Retention Scheme does not in itself bring a salary sacrifice arrangement to an end, but where an employer wishes to maximise the amount of an employee’s pay that will be covered by the CJRS, the employer and employee(s) concerned may agree to terminate the salary sacrifice arrangement as part of furlough. HMRC has recently announced that the Covid-19 pandemic will be considered a “life event” (i.e. one of the permitted reasons to break a salary sacrifice arrangement mid-term), if the employment contract is updated accordingly.
Do I need to give a personal guarantee to access finance under the Coronavirus Business Interruption Loan Scheme (CBILS)?

A number of our clients and networks raised issues in the early stages of the Scheme around the requirement for personal guarantees to access finance under the Scheme. The Scheme has now been updated so that:

  • For facilities under £250,000, personal guarantees cannot be taken to support lending under the Scheme.
  • For facilities above £250,000, personal guarantees may still be required by a lender but the amount which can be recovered under these guarantees is capped at a maximum of 20% of the outstanding balance of the CBILS facility after taking into account any other recoveries from business assets.
How are civil hearings being conducted?

The majority of hearings are taking place by video or phone.

Court guidance has been issued on telephone and video hearings during the coronavirus outbreak:

https://www.gov.uk/guidance/hmcts-telephone-and-video-hearings-during-coronavirus-outbreak

Where a Judge orders “teleconferencing”, it will take place using BTMeetMe, or video conferencing using Skype for Business or Cloud Video Platform.

All hearings are subject to the relevant jurisdictional rules and practice directions and usual court etiquette, including wearing appropriate attire and not eating or drinking during a hearing.

Electronic bundles of documents and authorities (if required) need to be prepared, indexed and paginated and sent to the Court well in advance of any hearing.

Can I dismiss someone who refuses to wear PPE?

Potentially, yes. If someone refuses to follow the health and safety measures that have been put in place to protect them, colleagues and possibly their customers, including (where appropriate) the use of PPE then this is a disciplinary issue and should be dealt with as such. Repeated failure to comply with the requirement to follow these measures, or a one off significant failure, may be sufficient to justify dismissal, depending on the circumstances.