Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Can I make a claim under my cancellations/abandonment insurance?

Cancellation insurance usually covers certain expenses and loss of profit, as long as the reason for cancellation is not excluded. These exclusion clauses are often quite wide and exclude avian, swine flu, quarantine, and restrictions of movement as a result of communicable disease. This means that you may not be entitled to compensation under this cover.

I submitted my online visa application but couldn't book an appointment, what should I do?

Normally, once you have submitted the online visa application and paid the fee, you have to attend an appointment to enrol your biometrics and verify your passport within 45 days. This requirement has been relaxed due to the visa application centres being closed.

Now that application centres have mostly reopened, you must book and attend an appointment to complete the application process. However, the Home Office has recently introduced the IDV app which allows applicants who previously gave their fingerprints as part of a previous application since July 2015, to upload a photo electronically. There will then be no need to attend a Visa Application Centre to submit their biometrics. Applicants who are eligible to use this electronic option will be contacted by UKVI.

What is a small company?

The changes will not apply to end users who are a small company. If you meet two out the following 3 conditions, you will meet the small company definition and are therefore exempt from the changes to IR35:

  1. Annual turnover is no more than £10.2 million
  2. Balance sheet total is no more than £5.1 million
  3. No more than 50 employees

Companies will always be classified as small in their first financial year. Public companies will always be considered to be medium or large businesses and cannot fall under this exemption.

For a group company to be a small company its parent company must also meet the small company definition.

Can employees with caring responsibilities be placed on Flexible Furlough?

Employees who are unable to work because they have caring responsibilities resulting from the coronavirus can continue to be furloughed. For example, employees that need to look after children can be furloughed, as you have previously submitted a claim for them in relation to a furlough period of at least 3 consecutive weeks taking place any time between 1 March 2020 and 30 June.

As more people return to work, there is an increased chance of more parents having childcare issues until Schools are fully open. However, they can’t be placed on furlough unless they had been on it before. So it would likely be unpaid leave, unless the government amends the scheme to grant an exemption.

Can I be fined for failing to take steps to try to ensure that my staff comply with the requirements to self-isolate?

Yes.

An employer which is aware that a worker or agency worker is or ought to be self-isolating, should not knowingly allow that worker or agency worker to leave the place that they are self-isolating in (“the designated place”).  To do so without reasonable excuse would amount to an offence which could result in the employer being issued with a fixed penalty notice.

The value of the fixed penalty varies depending on if it is the first or subsequent fixed penalty notice to be issued:

First fixed penalty notice £1,000
Second fixed penalty notice £2,000
Third fixed penalty notice £4,000
Fourth, and any subsequent fixed penalty notice £10,000