What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
Yes. Government guidance now confirms that employers can be required to take holiday during a period of furlough, so long as they are given minimum notice to do so. The notice required is double the length of the holiday.
Employers are also able to cancel employees’ holidays (or require them not to take holiday) if they are on furlough, for example if they are not in a position to pay the additional 20% top up to their normal wages (or more where they earn in excess of the £2,500 monthly cap on furlough payments). Again, employers are required to provide a minimum period of notice of cancellation, which in this case, is the length of the planned holiday.
Employers can ask employees to take or cancel holiday with less notice but they would need to get their agreement to do so.
Government guidance has been updated to state that “Employees should not be placed on furlough for a period simply because they are on holiday for that period.” If a period of furlough happens to coincide with an employee’s holiday then you should ensure that there are business grounds to support furlough being used in that instance so that it isn’t just being used as a means to fund holiday utilisation.
Undeniably and understandably BAME staff, as well as those staff who are identified as being at a higher risk, are going to have high levels of stress and anxiety. For some, this may become of such severity that those staff should be considered to be disabled under the Equality Act 2010. The question as to whether someone is disabled is one that should be answered in conjunction with appropriate medical advice. But the question about how to support any staff suffering with stress and anxiety should not be left until that stage. Proactive steps need to be taken and expert advice obtained on what support measures should be put in place. We know that many NHS organisations are already giving the mental wellbeing of their staff the highest priority.
From our perspective, we would ask managers to be mindful that stress and anxiety is likely to feature in how an individual reacts to questions about the level of risk to their health and the impact on their duties. The conversations with some staff may not be easy to have and may be met with challenge.
For those staff who’s stress and anxiety is such that it would qualify as a disability, reasonable adjustments will need to be considered to the processes that you are applying.
An additional point to consider – it might be worth writing to all staff, asking them to come forward if they have any health conditions that they think you ought to be aware of, assuring them that such information is being given in the strictest confidence. You want to make sure that you are taking the appropriate measures to ensure their health and safety.
Privacy policy – You must make sure the relevant privacy policies deal with how you will process Covid-19 data. You should have an employee privacy policy and this may already deal with health data (if it doesn’t, it should). You might also need to look at privacy policies for customers, visitors and suppliers. This ensures that processing is lawful, fair and transparent.
Lawful processing conditions – You will need to consider which processing conditions you are relying on (remembering that you need both an Article 6 condition and an Article 9 condition – this is the part of the GDPR which deals with special category data). As a lot of the data you collect will be about employees, you can’t use consent so you will have to find another lawful reason under GDPR which allows you to process the data.
Appropriate policy document – When you are considering your Article 9 processing conditions, remember you must also have an “appropriate policy document” in place.
Processing record – Finally make sure your processing record is up to date with information on what data you collect and use.
Head of Commercial, Colin Hewitt, speaks with the team at NewcastleGateshead Initiative about the complexities of event cancellations and the associated legal implications.
Click here to listen to the full podcast.
If it is not possible to find work for the employee to do at home, you do have the option of putting the employee on furlough.