What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
Almost two thirds of hearings conducted in the Civil Court will occur in person over the next few months as the Civil Court sees an influx in cases.
The Courts
In the Business & Property Courts, cases have been dealt with consistently since the start of the pandemic, except for trials that run for longer than 10 days in the Commercial & Admiralty Court. The Queen’s Bench Division and Administrative Court are also running as normal. If your case is listed for one of these courts, you do not need to be concerned that your case may take longer than anticipated, with conclusions still being reach at the normal rate.
Hearings
Since the start of the pandemic, most hearings have been conducted online through various platforms such as Skype for Business and Cloud Video Platform. The courts are of the view that remote hearings tend to take longer than those that are held in person. As a result, if your case is due to be held in person, the case may be heard in less time. HM Courts and Tribunals Service stated that:
“Wherever possible we will look to facilitate face-to-face hearings, but our expectation is that remote hearings will continue to play an important role for the foreseeable future, given that social distancing will continue to limit courtroom capacity compared to pre-Covid levels.”
More courtrooms have become available since the start of the pandemic, resulting in more facilities for cases to be heard in person, which will have the aim of helping to rid of the backlog of cases, along with remote hearings being conducted too, which is a welcome step forward.
Approximately 300 additional support staff will be employed for remote hearings before the end of 2020, enabling better service with remote hearings. The Government has decided that some civil judges will have the option to extend operating hours for cases to be held in the evenings and on weekends too, which may be most suitable for small and fast-track claims, resulting in a potentially faster outcome. The efficiency of all the new measures are being monitored and changes are being implemented, such as increasing the capacity of the Small Claims Mediation Service.
Small Claims Mediation Service
With claims of a lower value, a high proportion of cases successfully settle outside of court, therefore, if you have a small claim, the mediation service may be suitable for your case. Mediation involves a trained impartial third party, with the parties to the case discuss the dispute with the assistance of the third party, aiming to reach a settlement. Now with the increased capacity, it may make the mediation service more accessible, meaning that an agreement can be reached more swiftly rather than waiting for the matter proceed to a hearing.
The courts have stated that:
“We aim to increase capacity to accommodate 90% of parties who want mediation, rather than the current 40%. We are recruiting additional mediators and restructuring ways of working to achieve this.”
This is a positive shift for those with small and fast-track claims where legal costs ought to be kept to a minimum. Settling by mediation removes the need for trial costs, amongst other costs, and has additional benefits such as the matter being dealt with more amicably.
Read more about thisThe Information Commissioner’s Office (ICO) announce new guidance in light of coronavirus.
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
The ICO has stated the following:
“Data protection is not a barrier to increased and different types of homeworking. During the pandemic, staff may work from home more frequently than usual and they can use their own device or communications equipment. Data protection law doesn’t prevent that, but you’ll need to consider the same kinds of security measures for homeworking that you’d use in normal circumstances.”
Whether you work from home or in the office, you still need to comply with data protection laws. While you need to process personal data with the same care you use in the office, the home working environment throws up specific data protection concerns particularly in respect of data security. You should make sure you have a home working policy which deals with data protection and these data security issues.
Organisations must ensure that, for staff who can work from home, their obligations in respect of processing personal data are clearly communicated. Organisations may already have a home working policy – if this is the case, then this should be reviewed to ensure it remains relevant and up-to-date for practices during this pandemic.
Read more about thisAlthough an employer is obliged to conduct consultation “with a view to reaching an agreement”, it is not required to actually agree to any counter proposals made by the employee representatives. Merely to consider them in good faith.
Read more about thisYou also need to consider other aspects of data protection.
Be proportionate – only gather and use Covid-19 data where you need to.
Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.
Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).
Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.
Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.
Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.
Read more about thisPartner at Ward Hadaway Adrian Ballam talks to corporate finance expert and CBILS specialist Chris Silverwood (CorpFin and cashflow.co.uk) to explore the practical ins, outs, dos and don’ts of CBILS applications, answering the questions:
- How are banks making their assessments of whether a business can afford a CBILS loan when for many they cannot accurately forecast their revenues for at least the next three months?
- What are the red flags that banks are looking for when assessing whether or not to grant a request for a CBILS loan?
- What cost mitigation measures should a business have already implemented prior to applying for a CBILS loan?
- What level of information should a business provide to support a CBILS application?
- What common mistakes are businesses making when applying for funding?
- What general tips do you have for businesses seeking CBILS funding?
Click read more to view the video.
Read more about this