What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
If the debts owed to you pre-date Covid-19 and your debtor seemed unable to pay well before the Covid-19 pandemic took place, it is entirely possible that you will be able to present a petition on the grounds that the debtor would have been unable to pay its debts even if the Covid-19 had no effect on its financial position. We do not yet have any reliable precedent as to how the Courts are likely to deal with such cases. Whether you are likely to succeed will depend on the exact circumstances of the debt and your debtor. There has been one case decided in August 2020 where the Court concluded that Covid-19 did not have a financial effect upon the debtor and that the circumstances which gave rise to the petition had arisen long before Covid and would have occurred in any event. A winding up order was made in that case. What we do know about the court’s approach is that the purpose of the Act is to allow viable companies to trade through the current times and the Court is likely to set the bar high.
Please contact us if there a debt you would like to discuss. Even if presenting a winding up petition is not available for now, there may still be other forms of legal proceedings that you can use to collect money owed to you, like county court proceedings.
The Flexible Furlough Scheme was introduced from 1 July 2020 and is due to come to an end on 30 September 2021.
Privacy policy – You must make sure the relevant privacy policies deal with how you will process Covid-19 data. You should have an employee privacy policy and this may already deal with health data (if it doesn’t, it should). You might also need to look at privacy policies for customers, visitors and suppliers. This ensures that processing is lawful, fair and transparent.
Lawful processing conditions – You will need to consider which processing conditions you are relying on (remembering that you need both an Article 6 condition and an Article 9 condition – this is the part of the GDPR which deals with special category data). As a lot of the data you collect will be about employees, you can’t use consent so you will have to find another lawful reason under GDPR which allows you to process the data.
Appropriate policy document – When you are considering your Article 9 processing conditions, remember you must also have an “appropriate policy document” in place.
Processing record – Finally make sure your processing record is up to date with information on what data you collect and use.
Employers had the ability to furlough extremely vulnerable employees who needed to shield.
If your employee is on sick leave or self-isolating as a result of Coronavirus, including as a result of track and trace, they’ll be able to get Statutory Sick Pay, subject to other eligibility conditions applying.
There is no special exemption for them, so they would need to meet the usual requirements to be placed on Flexible Furlough after 1 July 2020. i.e. They had to have been placed on furlough for at least 3 weeks before 1 July. Otherwise, they could not be furloughed.