What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
It is envisaged that employees of organisations falling into the first two categories set out above and won’t be eligible for the job retention scheme in relation to the majority of their employees. It is envisaged that NHS Trusts for example are going to require their staff to be working at full capacity where possible. However, the guidance doesn’t definitely exclude public sector organisations from furloughing employees and notably the government expects such organisations to use public money to continue to pay staff and not furlough them, rather than say requires. In reality, it is difficult to see how such an organisation will be able to rely on the scheme, but the guidance doesn’t completely rule it out.
Local government legislation formerly stipulated that councillors must be physically present to vote and this requirement has already led to the widespread cancellation of Council meetings. There is a limit to what can be achieved under the chair’s emergency powers and delegation to officers.
The Government has now legislated to allow for remote voting until 7 May 2021. The secondary legislation required was issued in draft on 2 April and has been in force since Saturday 4 April.
The legislation allows for committee meetings to go ahead where members and any members of the public attending remotely can all times “hear (and where possible see) and be heard (and where possible be seen) by the other members in attendance”.
It remains to be seen how many local authorities take up the opportunity to hold a virtual committee meeting. Concern has been expressed that the demographic of local councillors may mean that members have difficulty with the technological mechanisms for holding such meetings. However, the message from the Secretary of State is clear that wherever possible, the planning system should keep moving in these current times.
- It is important to have a clear paper trail for any agreed reduction in salary, and hence any reduction in the amount of contributions. However, the contribution rates (as opposed to the amounts) should be the same as normal, and hence all processes and software should function as per normal and, amongst other things, remain compliant with auto-enrolment employer duties.
- However, if the period of affected contributions does not overlap precisely with the period of reduced salary, for example because of different cut-off dates, there may well be instances of non-compliance with auto-enrolment employer duties at the beginning as well as at the end of the period covered by the Coronavirus Job Retention Scheme.
- Accordingly, where an employer takes advantage of the Coronavirus Job Retention Scheme, good communication with the persons responsible for pensions administration and detailed record-keeping are essential to prevent non-compliances in the short-term and confusion in the long term.
It is unlikely that an employer can place such a requirement on staff without infringing the employee’s privacy. If the employee is acting in accordance with the rules, limiting their activity would likely be considered unreasonable.
As we move to look at re-opening businesses and getting people back into the workplace there is work to be done by employers, firstly in planning how they are going to do this, and secondly, communicating those plans to staff. The only way in which businesses are going to be able to manage the transition back to some form of normality is by speaking to their staff and re-assuring them about the measures that will be put in place to safeguard their health and safety in order to enable them to return. Any successful return to work will need to based on carefully thought out plans and providing re-assurances to employees that necessary action is being taken.
Employers will be focusing on:
- How do I get my workforce back safely, and
- How do I give my workforce the confidence to return.