Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Can employees reduce their pension contributions?
  • Remember that employees will also be making contributions on any reduced wage under the Coronavirus Job Retention Scheme. The amount contributed may be less, but the contribution rate will be the same, unless the following applies.
  • Employees may reduce their DC employee contributions if their scheme rules allow them to do so, but no further than the statutory minimum if the scheme qualifies as the employer’s auto-enrolment vehicle.
  • Employees might choose to opt-out or cease active membership of their scheme, which might cause a spike in administration at a time when administrators are likely to be understaffed. It is important that employers remember they must not do anything to encourage or induce employees from leaving an auto-enrolment vehicle as this may constitute an offence.
  • Employees who leave their scheme in this way will have to be re-enrolled in due course as and when required by law.
  • For DB schemes, specific considerations apply (see the last section, below).
Are there specific examples given?

The guidance gives numerous examples of the types of performance adjustment which parties should consider. For example this includes:

  • Varying deadlines (e.g. for performance or payment)
  • Varying compensation (e.g. to recognise increased costs)
  • Varying the nature of performance (e.g. allowing substitute goods, allowing pert delivery of services)

The guidance also encourages a reasonable approach to enforcement, which might encourage delaying issuing formal proceedings, increased use of mediation or providing more information to the other party than would be volunteered under normal circumstances.

VIDEO EXPLAINER: Removing healthcare workers from the front line – the dos and don'ts

Specialist healthcare lawyers from Ward Hadaway ran a free webinar looking at the practical and legal considerations if required to treat healthcare workers from a BAME background or other vulnerable groups differently in the fight against the Covid-19 pandemic.

Can you require an employee to tell their employer whether they have been tested for coronavirus/the results of that test?

Yes, this is very likely to amount to a reasonable management instruction which is put in place for public health reasons. Employers should make it clear to their employees that this is something they are required to do and that if they fail to do so this may lead to disciplinary action.

What does the guidance suggest?

The guidance asks parties to act responsibly and fairly in performing and enforcing contracts. They are encouraged to act in a spirit of cooperation to achieve practical, just and equitable outcomes. In essence, rather than sticking strictly to the contract as agreed, they are encouraged to give each other leeway to deliver performance differently than they are required to do under the contract.