What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
The government released further clarification on the Coronavirus Job Retention Scheme on 4 April. The wording referred to concerning public sector organisations and organisations receiving public funding remains the same.
The revised guidance does provide a helpful insight into how HMRC will deal with applications made to it for assistance under the scheme. It appears that there won’t be a particularly forensic approach adopted by HMRC. The guidance says you can furlough staff if you cannot maintain your current workforce because your operations have been severely affected by coronavirus.
It goes on to say that all employers are eligible to claim under the scheme and the government recognises different businesses/organisations will face different impacts from coronavirus. The need to demonstrate the impact of coronavirus on your business/organisation is not one of the criteria businesses/organisations are going to need to satisfy, so the government does not appear to intend to set a specific test to determine if a business/organisation is “severely impacted by coronavirus”. It is hoped that this should provide additional comfort to publicly funded organisations facing significant restrictions to their operations during the Covid-19 crisis.
Parties still need to comply with the various Protocols that apply and will be expected to exchange information in the usual way. Court proceedings can be issued electronically.
This will depend on the particular facts and the employee’s circumstances but an employee should co-operate with the employer so far as is necessary to enable compliance with any statutory duty or requirement relating to health and safety.
In addition, conduct outside of work can result in an employee’s dismissal if the conduct pertains to the employment relationship. If an employee breaches the lockdown rules and it affects their ability to work, such as it being no longer safe for them to attend work, or the reputation of the employer, these may be grounds for disciplinary action and subsequent dismissal.
The immediate impact is accounting for payroll purposes for the additional cost of 13.8% employers NIC’s and 0.5% apprenticeship levy on top of the payment to the contactor’s PSC.
Secondary NIC’s cannot be recovered from payments due to employees and the same applies under the new IR35 regime. However, new terms can be agreed with reduced level of fees to reflect this additional cost.
It is possible to review working arrangements for contractors before the new rules come into effect. This will require immediate action.
You could consider terminating current contracts and entering into new terms that reflect working arrangements for a self-employment arrangement.
Another possibility is encouraging contractors to abandon the PSC model and provide services under a compliant umbrella company.
In the event of a determination of employed status you should seek to enter new terms that at the very least reflect the new tax arrangements .