Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

What are my potential liabilities if a customer, supplier or other visitor contracts Covid-19 on my premises?

As an occupier of premises, you owe a duty of care to your visitors to take reasonable care to see that the visitor will be reasonably safe in using your premises.

It is therefore essential that you are taking reasonable steps and strictly adhering to up-to-date Government advice in all aspects of your business to avoid any potential liability.

Failure to follow Government advice could leave you vulnerable to claims for compensation for pain and suffering should a visitor on your premises contract Covid-19.

However, each case will be fact-specific and it would be very difficult for a visitor to establish that they contracted Covid-19 specifically from those premises (as opposed to being exposed to the virus anywhere else).

If someone suggests that they are going to make a claim make sure that you report matters to your insurer or insurance broker immediately.

Can an employee in a public facing role refuse to interact with a customer who is not wearing a face mask?

In some circumstances, visitors and customers are required to wear face coverings, such as those travelling on public transport, shoppers and museum visitors. The government guidance states that:

  • businesses must remind people to wear face coverings where mandated; and
  • premises where face coverings are required should take reasonable steps to promote compliance with the law.

As part of their duty of care to employees and to uphold a relationship of mutual trust and confidence, employers should consider how employees can ensure that visitors and customers comply with the rules and provide their staff with guidance. They must also seek ways to protect their employees both from the risks of those customers not wearing face masks and potential abuse from customers or visitors who decline to wear a face covering. This may include having signs in place requiring customers and visitors to wear a mask and allowing staff to refuse to serve customers if they do not follow the rules.

However, it is ultimately the responsibility of the police, security and public transport officials to remove customers from premises where they are not complying with the rules on face coverings.

The police and Transport for London have been given greater powers by the government to take measures if the public do not comply with the law relating to face coverings without a valid exemption, such as refusing to wear a face covering. This includes issuing fines which have now been increased to £200 for the first offence (and £100 if paid within 14 days). Transport operators can also deny access to their public transport services if a passenger is not wearing a face covering, or direct them to wear one or leave a service.

I’m getting married but have had to postpone the wedding. Should I delay putting a prenuptial agreement in place until a later date?

No. The greater the gap between the completion of a Prenuptial Agreement and the Wedding the more likely it will be upheld by the Court. If such an Agreement is made shortly before the wedding takes place one of the parties to it could claim that they felt under pressure to sign and the Court may decline to follow it.

The employee I need to consider suspending is a doctor – do I have to follow MHPS

Yes probably in our opinion, even if you are not considering taking any formal action against them. Ultimately if a doctor is suspended this could be considered as causing them reputational damage and it therefore is correct that they are afforded the protections (in particular in relation to keeping exclusion/suspension under review) of MHPS. Under Part V of MHPS there is provision for excluding practitioners if they are a danger to patients and they refuse to recognise it or if they refuse to co-operate. It doesn’t refer to a particular risk for the practitioner themselves, but it would appear logical that it would apply.

Can employees with caring responsibilities be placed on Flexible Furlough?

Employees who are unable to work because they have caring responsibilities resulting from the coronavirus can continue to be furloughed. For example, employees that need to look after children can be furloughed, as you have previously submitted a claim for them in relation to a furlough period of at least 3 consecutive weeks taking place any time between 1 March 2020 and 30 June.

As more people return to work, there is an increased chance of more parents having childcare issues until Schools are fully open. However, they can’t be placed on furlough unless they had been on it before. So it would likely be unpaid leave, unless the government amends the scheme to grant an exemption.