Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

What is happening about court and arbitration hearings?

The courts are seeking to adapt to our new circumstances and have urgently been looking to introduce new ways of working. The courts have been testing out different ways of holding court hearings. The advice is changing almost daily and some courts have been developing local practices. Going forward the court, the parties and their representatives will need to be more proactive about all forthcoming hearings.

Everyone involved in the case is to consider as far ahead as possible how future hearings should best be undertaken and work collaboratively. It will normally be possible for all short, interlocutory, or non-witness, applications to be heard remotely. Some witness cases will also be suitable for remote hearings. The parties just need to ensure that everyone involved can use the technology suggested.

The courts have been looking at and held remote hearings using, non-exhaustively, BT conference call, Skype for Business, court video link, BT MeetMe, Zoom and ordinary telephone call. Bundles for the hearing will be prepared and circulated electronically.

If the hearing cannot be held remotely because the parties do not have the requisite technology or the length of the hearing combined with the number of parties or overseas parties, representatives and/or witnesses make it undesirable to go ahead with a hearing in court at the current time, then it may be that the case will need to be adjourned. We are hearing of trials being adjourned and that they will not be re-listed before at least September.

HMCTS has advised that several priority courts will remain open during the coronavirus pandemic to make sure the justice system continues to operate effectively. It publishes a daily operational update from the courts and they aim to update it by 9am. The link is https://www.gov.uk/guidance/hmcts-daily-operational-summary-on-courts-and-tribunals-during-coronavirus-covid-19-outbreak.

Also, the courts have circulated a civil listing priority list with Priority 1 listing work which must be done and which includes injunctions, any applications in cases listed for trial in the next three months, any applications where there is a substantial hearing listed in the next month and all Multi Track hearings where parties agree that it is urgent.

In the Priority 2 list, which consists of hearings which could be done, are enforcement of trading contracts, trial involving the survival of a business or the insolvency of an individual, small and fast track trials where the parties say they are urgent, and appeal in these kinds of cases.

Similarly, in arbitration proceedings, the parties and arbitrators are being encouraged to utilise technology to make sure that hearings take place. We have heard of Zoom being used very successfully for multi-party proceedings.

What amounts to a dismissal?

For the purposes of collective consultation, making someone redundant and/or changing terms and conditions of employment, by termination and re-engagement, is also classed as a dismissal by reason of redundancy and so has the exact same consultation requirements.

How much data can I gather?

You also need to consider other aspects of data protection.

Be proportionate – only gather and use Covid-19 data where you need to.

Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.

Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to  make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).

Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.

Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.

Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.

Do the usual publicity requirements for planning applications still apply?

The Government has introduced new regulations, which took effect on 14 May 2020, to relax the publicity requirements in respect of planning applications.

Planning applications are usually required to be publicised by way of site notices and local newspaper notices and applications are to be made available for public inspection. The Government has recognised that these actions may not always be possible in accordance with social distancing guidelines and in order that Councils do not delay applications as a result of an inability to comply with the publicity requirements, the Government has relaxed the requirements.

A Local Planning Authority is now required to “take reasonable steps” to publicise a planning application, which may be through use of online newspapers, social media, or other electronic measures. What is considered reasonable will depend upon the circumstances of an individual application and will be proportionate to the scale and impact of the development. A large development that has previously generated significant interest will require more steps to bring the application to the attention of all of those with an interest than a householder application. The guidance emphasises the role of the publicity requirements, namely to enable those with an interest to make representations and to effectively participate in the decision making process and therefore community engagement remains key. It is recommended that the officer’s report refers to the steps taken where a Council has relied upon the temporary publicity arrangements.

The requirement to make planning applications available for public inspection has also been temporarily suspended providing that the applications are available for online inspection. In reality most LPAs already provide such an online facility. Where individuals are unable to access an application online LPAs should make alternative arrangements, for example providing information over the phone or providing a hard copy set of documents by post.

The regulations however only amend the statutory publicity requirements. In addition to these, all LPAs are required to have a Statement of Community Involvement which may provide for additional publicity requirements and the LPA will be bound by these regardless of the temporary relaxation of any statutory requirements. Where a Statement of Community Involvement does go beyond the statutory requirements, the Government guidance suggests that LPAs update these to ensure that local communities can continue to be consulted in the current climate.

The regulations are currently due to expire on 31 December 2020.

What are the current planning restrictions on supermarkets, food retailers and distribution centres concerning deliveries?

On 13 March 2020 the Secretary of State for Housing, Communities and Local Government issued a Written Statement in respect of delivery restrictions.

In this respect, many supermarkets, food retailers and distribution centres in England operate under planning restrictions (conditions and/or obligations) which limit the time and number of deliveries from lorries and other delivery vehicles which can take place particularly at night primarily to protect the residential amenity of nearby residential property.

Key points in the Statement include;

  • Given the exceptional challenges facing the UK from the coronavirus, it is vital that deliveries of food, sanitary and other essential products over the coming weeks can be made as quickly and safely as possible, minimising disruption to the supply chains. The likely pressures on driver capacity mean additional flexibility is needed so that retailers can accept deliveries throughout the day and night where necessary.
  • That planning enforcement is discretionary and that local planning authorities should act proportionately in responding to suspected breaches of planning control.
  • That local planning authorities should not seek to undertake planning enforcement action which would result in unnecessarily restricting deliveries of food and other essential deliveries during this period having regard to their legal obligations.

The Statement acknowledges that the increased frequency of deliveries particularly at night could have a temporary impact on residents. It therefore concludes that the Government will review the need for the flexibility outlined in the Statement after the pressure from the coronavirus has reduced and that it is the intention to withdraw it once the immediate urgency has subsided.

A link to the Written Statement is below.

https://www.parliament.uk/business/publications/written-questions-answers-statements/written-statement/Commons/2020-03-13/HCWS159/