What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
- Do not require them to work
- Continue to communicate with and support them
- Allow them to work from home, is there alternative work for them to do if they can’t do their work from home
- Offer SSP or allow them to take holiday if they want to.
Follow up to date UK Government advice. This can be found at: https://www.gov.uk/government/publications/guidance-to-employers-and-businesses-about-covid-19/guidance-for-employers-and-businesses-on-coronavirus-covid-19
For best practice and more detailed information; consult the HSE’s website at https://www.hse.gov.uk/news/coronavirus.htm
Failing to follow the guidance is likely to be regarded as failing to take all reasonably practicable steps.
- Before any agreed reduction in wages, actual changes to earning patterns (loss of overtime, for example) may impact the pensionable salary as defined under the scheme rules, with knock-on effects to a number of benefit calculations, such as death in service benefits.
- Contractual changes to member salaries may adversely impact accrued benefits as the final salary figure may be reduced to a greater or lesser extent depending on the duration of furlough and the severity of any reductions in wage, and hence reductions may be difficult to agree with staff.
- Reducing employer contributions will be subject to a number of the same considerations applicable to a DC scheme listed above. There will also be a need to change the rules and interact with the trustees, although it may be possible to override the rules with a direct contractual agreement with members.
- Reducing employee contributions will also depend on the scheme rules, particularly as to whether there are any discretionary powers to suspend contributions, or pensionable service.
- The rules will need to be considered for any unexpected consequences of furlough: depending on the wording of the rules, furlough may or may not be considered a leave of absence and may or may not have the effect of terminating pensionable service. This could have far-reaching consequences.
- In particular, if the workforce’s pensionable service is inadvertently terminated as opposed to suspended in accordance with any relevant rule, this could trigger a statutory employer debt on an employer participating in a multi-employer scheme, if pensionable service continues for employees of other employers. This sort of issue is unlikely to be spotted until after the event, and therefore difficult to untangle. However, an employer should be able to take advantage of the “period of grace” provisions by notifying the trustees of its intention to re-admit employees to pensionable service within the next 12 months.
- Clearly the impact of the Coronavirus Job Retention Scheme on DB schemes is complex and legal advice should be sought before any changes are considered.
The Government has introduced legislation to expand the list of those who can register deaths to include Funeral Directors who are dealing with the funeral arrangements and who has been authorised by a relative of the deceased to register the death. Also, the medical cause of death certificate can be emailed to the Registrar’s office and arrangements made to have a telephone appointment to provide the Registrar with information to register the death. The requirement to attend the Registrar in person to sign the Register has been relaxed so that this is not necessary. It will however still be necessary to register the death within 5 days.
In practice this means that any risk assessment will need to be reviewed constantly and adjusted as our understanding of the nature and level of the risk grows.
Some service-providers are instigating special Oversight Groups to keep this issue under review but engagement and consultation with those affected is critical and making sure they feel confident to raise concerns and refuse to work if they believe they are not safe.