Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Can you require an employee to tell their employer whether they have been tested for coronavirus/the results of that test?

Yes, this is very likely to amount to a reasonable management instruction which is put in place for public health reasons. Employers should make it clear to their employees that this is something they are required to do and that if they fail to do so this may lead to disciplinary action.

I submitted my online visa application but couldn't book an appointment, what should I do?

Normally, once you have submitted the online visa application and paid the fee, you have to attend an appointment to enrol your biometrics and verify your passport within 45 days. This requirement has been relaxed due to the visa application centres being closed.

Now that application centres have mostly reopened, you must book and attend an appointment to complete the application process. However, the Home Office has recently introduced the IDV app which allows applicants who previously gave their fingerprints as part of a previous application since July 2015, to upload a photo electronically. There will then be no need to attend a Visa Application Centre to submit their biometrics. Applicants who are eligible to use this electronic option will be contacted by UKVI.

What happens if a patient is admitted to hospital during the pandemic?
How do I apply for CBILS?

CBILS is made available through the British Business Bank’s 40+ accredited lenders and partners, which are listed on their website (https://www.british-business-bank.co.uk/ourpartners/coronavirus-business-interruption-loan-scheme-cbils/accredited-lenders/).  

 Businesses should initially approach their own lender and only consider other lenders if they are unable to access the finance they need. Note, not every accredited lender can provide every type of finance listed.   

 Some banks/lenders are not included in the list of accredited lenders which appears to mean that they cannot provide support through the Scheme. We understand from the British Business Bank that further lenders are applying to be accredited but that this may take a little time to process. If the provider of your senior debt is not on the accredited list you should consider approaching the bank which provides your day to day account banking services.

 If you wish or need to access the Scheme via an alternative funder the process may take longer as usual on-boarding and KYC processes will need to be undertaken.  

What should I be mindful of in relation to pregnant workers? Is there a right to suspend?

Yes, but as a last resort. In summary, the law requires employers:

  • to assess the workplace risks posed to new or expectant mothers or their babies;
  • to alter the employee’s working conditions or hours of work to avoid any significant risk to them;
  • where it is not reasonable to alter working conditions or hours, or would not avoid the risk, to offer suitable alternative work on terms that are not “substantially less favourable”;
  • where suitable alternative work is not available, or the employee reasonably refuses it, the employer should consider whether it is appropriate to suspend the employee on full pay.