What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
As an occupier of premises, you owe a duty of care to your visitors to take reasonable care to see that the visitor will be reasonably safe in using your premises.
It is therefore essential that you are taking reasonable steps and strictly adhering to up-to-date Government advice in all aspects of your business to avoid any potential liability.
Failure to follow Government advice could leave you vulnerable to claims for compensation for pain and suffering should a visitor on your premises contract Covid-19.
However, each case will be fact-specific and it would be very difficult for a visitor to establish that they contracted Covid-19 specifically from those premises (as opposed to being exposed to the virus anywhere else).
If someone suggests that they are going to make a claim make sure that you report matters to your insurer or insurance broker immediately.
Those individuals who are already exempt from the existing face covering obligations, will continue to be exempt from the new rules. These include:
- Those unable to put on or wear a face covering because of a physical or mental illness or disability
- People for whom wearing or removing a face covering will cause severe distress
- Anyone assisting someone who relies on lip reading to communicate
The definition of a relevant establishment is a question of fact for an Employment Tribunal. Guidance from case law says that ‘establishment’ should be interpreted very broadly (so as to avoid employers escaping the need to collectively consult), and may consist of:
- A distinct entity
- With a certain degree of permanence and stability
- Which is assigned to perform one or more tasks
- Which has a workforce, technical means and a certain organisational structure to allow it to do so
However, there is no need for it to have the following:
- Legal, economic, financial, administrative or technological autonomy
- A management which can independently effect collective redundancies
- Geographical separation from the other units and facilities of the undertaking
We recommend that ongoing support is provided to all MHFA’s beyond completion of the MHFA training. It is necessary to do refresher training (approx. every 3 years) and ideally ongoing ‘continued professional development’ should be provided as well as regular opportunities for debriefing / seeking support. One way of supporting your MHFAs in the workplace is by creating a buddy system amongst the MHFAs. That way the individuals carrying out the role of MHFAs have a support structure in place amongst themselves. All trained MHFAs can also reach out to management to discuss any concerns they have or to seek any further support they need.
It is almost impossible to completely guard against the risks associated with contractor insolvency, but there are some steps which can assist in mitigating and managing the risks involved. To be in the best possible position, it is worth considering the following at the outset of any project:
- Check the contractor’s financial position – particularly the specific company which will enter into the building contract, as the employer’s rights will be against this company rather than the business as a whole
- Take legal advice to ensure that the building contract is properly drafted with appropriate provisions to deal with an insolvency event
- Consider requiring a performance bond and/or parent company guarantee (each serve slightly different purposes)
- Obtain collateral warranties from the consultants and sub-contractors involved, so that there are contractual rights against other parties if the contractor is no longer able to meet claims
- Consider requiring retention bonds, advance payment bonds or vesting certificates if necessary
- Project bank accounts and escrow accounts can also provide some further assurances for the parties involved