Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

The National Lockdown Guidance states that anyone who is clinically extremely vulnerable should not attend work. What options do I have if an employee is in the clinical extremely vulnerable category but cannot do their job at home?

The now defunct Guidance for the Tier system suggested that the clinically extremely vulnerable would be treated in the same way as those who were shielding in Lockdown 1. This means that anyone who is clinically extremely vulnerable and cannot work remotely, will be entitled to SSP. These employees should receive a letter confirming that they are deemed to be clinically extremely vulnerable/shielding and you should ask for a copy of it as evidence to support a claim for SSP. It is likely that the Lockdown 3 Guidance will be the same.

You could also furlough an employee in the clinically extremely vulnerable category. Again we do not anticipate this changing.

What are the contractual issues that businesses need to think about as they get back to business following lockdown?

It is clear that we are emerging from a completely unprecedented period of disruption for many businesses, and this may have had a huge impact on their contractual arrangements both with suppliers and customers.

As the lockdown eases, and we get back to business, it’s important that businesses take stock of what has happened, and ensure they review and address the legal and contractual consequences of what has been happening since the start of the global pandemic.

Employer furlough schemes

Furlough means temporary leave of absence. There is nothing to stop an employer seeking to agree a temporary leave of absence – with or without pay – with its workforce.

This could not be forced on an employee without significant risk. Without agreement, this would need fair selection and consultation – more on that later.

What should I do if I have a hearing scheduled in the COP?

Parties are encouraged to review upcoming matters to assess the viability for there to be any agreement which can be reached in relation to the issues in dispute or to consider whether the case needs to proceed to a remote hearing. If directions or issues can be agreed between the parties, reducing the need for remote hearings, then that is the preferred option.

What are the data protection implications of homeworking?

The Information Commissioner’s Office (ICO) announce new guidance in light of coronavirus.

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

The ICO has stated the following:

Data protection is not a barrier to increased and different types of homeworking. During the pandemic, staff may work from home more frequently than usual and they can use their own device or communications equipment. Data protection law doesn’t prevent that, but you’ll need to consider the same kinds of security measures for homeworking that you’d use in normal circumstances.”

Whether you work from home or in the office, you still need to comply with data protection laws. While you need to process personal data with the same care you use in the office, the home working environment throws up specific data protection concerns particularly in respect of data security. You should make sure you have a home working policy which deals with data protection and these data security issues.

 Organisations must ensure that, for staff who can work from home, their obligations in respect of processing personal data are clearly communicated. Organisations may already have a home working policy – if this is the case, then this should be reviewed to ensure it remains relevant and up-to-date for practices during this pandemic.