What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
The Act should make it easier for residents to obtain relevant information. It includes an obligation for the Principal Accountable Person to prepare a strategy for promoting the participation of residents, including the information to be provided to them and consultations about relevant decisions. The strategy must be provided to residents, and there will be provision for residents to be able to request information and copies of documents from the Principal Accountable Person. The type of information and the form in which it is to be provided will be set out in secondary legislation in due course, but the explanatory notes anticipate that it will include:
- Full current and historical fire risk assessments•Planned maintenance and repair schedules
- The outcome of building safety inspection checks
- Information on how assets in the building are managed
- Details of preventative measures
- Details of fire protection measures and the fire strategy for the building
- Information on the maintenance of fire safety systems
- Structural assessments
- Planned and historical changes to the building
The Government has produced and published three new Procurement Policy Notes as a direct result of the ever changing Covid-19 environment.
PPN 01/20: Responding to COVID-19
The purpose of PPN 01/20 is to ensure that contracting authorities are able to procure goods, services and works with extreme urgency, to allow them to respond to the pandemic efficiently.
This PPN provides guidance for the following circumstances:
- Direct award due to extreme urgency (regulations 32(2)(c)) (click here to read our article regarding regulation 32)
- Direct award due to an absence of competition or protection of exclusive rights
- Call off from an existing framework agreement or dynamic purchasing system
- Call for competition using a standard procedure with accelerated timescales
- Extending or modifying a contract during its term
PPN 02/20: Supplier relief due to COVID-19
PPN 02/20 focuses predominantly on the supplier to assist in keeping supply chains open and ensuring that suppliers are kept financially sound during these unpredictable times.
This PPN provides guidance for the following circumstances:
- Urgent reviews of contract portfolios and to update suppliers if they believe they are at risk
- Put in place appropriate payment measure to support supplier cash flow
- Where contract payments are based on ‘payment by results’ make payments based on previous invoices
- Ask suppliers to act on a ‘open book’ basis and make cost data available to the contracting authority during this period
- Ensure invoices submitted by suppliers are paid immediately on receipt
PPN 03/20: Use of Procurement Cards
The third guidance note PPN 03/20 relates to the use of procurement cards to increase efficiency and accelerate payment to suppliers.
This PPN provides the following advice and urges organisations to arrange with their procurement card provider to:
- Increase a single transaction limit to £20,000 for key card holders
- Raise monthly limits on spending with procurement cards to £100,000 for key card holders
- Spend on procurement cards each month in excess of £100,000 should be permissible to meet business needs
Although the above advice has been provided, should these limits not be necessary, organisations should seek an appropriate transaction limit or monthly limit.
The PPN also advises that by 30 April 2020, in scope organisations should:
- Ensure that a number of appropriate staff have the authority to use these cards
- Open all relevant categories of spend to enable these cards to be used more widely
If a contract contains a force majeure clause this may become operative due to the coronavirus pandemic and related emergency legislation. Such clauses exist to ensure that if some unforeseen event prevents a party from being able to perform their obligations under a contract, either on time or at all, they will be excused from their obligations and not be held liable for non-performance.
The clause must actually be written into the contract to have effect – a force majeure clause cannot be implied into a contract. Whether it can be relied on by a party will depend on the wording of the clause itself as it may only be applicable in certain limited circumstances.
You should seek legal advice at an early stage if you think that force majeure is relevant, because a number of potentially complex issues must be addressed, many of which will turn upon the exact wording of the force majeure clause in the contract in question:
- Has a force majeure event actually arisen?
- What notification process do you have to follow to rely on the provision?
- What mitigation steps do you have to take?
- What is the effect of the force majeure event – is the contract suspended, or can it be terminated (which might not be what you want)?
The Flexible Furlough Scheme was introduced from 1 July 2020 and is due to come to an end on 30 September 2021.
Yes. With respect to employees you have an obligation to protect their health so you can gather information to do that. You might gather information from your employees on who has the virus, who has had it and recovered and also who has tested negative. You might also want to know if individuals have been in contact with someone who has it or if they are in a vulnerable group. It is reasonable to want to know where individuals have travelled. In the future it may also be reasonable to know if they are planning to travel to a virus hot spot, as the impact of the virus around the world is likely to continue for some time even after the outbreak has been contained in the UK.
It is reasonable to gather some information about visitors to your site, be they customers or suppliers, as this information will also help protect your staff. However, you should keep what you gather to a minimum. For visitors, it’s unlikely that you need to know anything more than they have Covid-19, are displaying symptoms or have recently been in contact with someone who has the virus.