What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
The MHFA training makes this clear, it should be made clear in the MHFA role specification and procedures and discussed during regular MHFA peer support and MHFA surgery sessions. It is important to ensure that where an Employee Assistance Programme is in place, all MHFAs have details of that scheme available so they are able to instantly share details of the scheme with those who require support. If in doubt due to serious concerns then using 999 or Samaritans is an option.
The basics of health and safety law requires that employers take “all reasonably practicable steps” to ensure workers’ safety and that a suitable and sufficient assessment of risk is undertaken. It is the individual assessment of Covid-19 risk in each workplace that will be central. Employers will be required to conduct a robust risk assessment and then, following the hierarchy of controls, put robust processes and safeguards in place to address those risks.
UK government guidance and HSE advice is continually evolving, which in practice means that any risk assessment will need to be reviewed very regularly as that guidance develops. There is flexibility for individual businesses within the overall government framework and there will need to be a process of evaluation to ensure that the measures in place continue to meet the requirements.
The starting point of avoid, eliminate and control means looking at individuals continuing to work from home where possible (the fewer the number of people back in the workplace the lower the risk), and if not look at risk management, which leads to administrative controls – i.e. changing work practices before ending up at PPE. PPE is generally seen as control of last resort but in practice – facemasks, disposable gloves and constant prompts to wash hands for example.
In terms of changing working practices, employers should be thinking about:
- the workspace and how this is laid layout
- how do we make sure it is kept clean and hygienic
- how do we keep people apart
- how can we use toilets, canteens or other shared spaces/facilities safely
- how do we promote and enable higher levels of workplace hygiene
- if we are going to rely on PPE – can we get it, and is it suitable
- what about limiting customer interactions
- will there be enough first aiders on site
- can we manage fire safety, deliveries etc
- what about higher risk workers
- should work tools and equipment be allocated on an individual basis to employees.
These decisions need to be recorded and clearly communicated to staff members.
A reduction in hours or salary or changes to hours or patterns of work is a contractual change – you can’t just impose it without significant risk. The same applies for lay-off or short-time working where there is no existing contractual right to impose these.
In summary, the process that an employer should follow to implement these measures is as follows:
- Communicate the Company’s position clearly and the urgent need to achieve temporary cost-saving to ensure the ongoing financial viability of the organisation
- Explain the proposed changes in detail and seek the employee’s agreement, and
- Record the agreed changes in a letter which is counter-signed by the employee.
If employees will not agree then employers will be at substantial risk of claims for unlawful deduction of wages, breach of contract and/or constructive unfair dismissal if they seek to impose these changes unilaterally. Employers should be mindful that this approach is likely to cause significant employee relations issues and dissatisfaction if only some employees agree to a reduction in pay. Employers should have a clear strategy for what their approach will be if this is the case – for example, they may wish to instead explore a different measure such as redundancies. This may form part of the employer’s communication when explaining the reason for the changes and seeking the employee’s agreement.
Unions: Employers should also be aware that where there is a recognised trade union in respect of any part of the workforce which is being asked to agree to a change to terms and conditions, the recognition agreement or collective agreement will require the employer to consult and/or negotiate with the trade union in the first instance.
Collective consultation: Where 20 or more dismissals are proposed at one establishment in any 90-day period, there are stringent collective consultation rules which apply (regardless of whether the employees have two years’ service or not). All dismissals count towards this total unless the dismissal is “not related to the individual concerned” – therefore dismissals for things such as conduct or capability do not count, but most other dismissals will count. This will include where you are imposing changes to the contract such as reduced hours or pay.
The rules on collective consultation set out a prescriptive and time-consuming process which must be followed, and minimum timescales before any redundancies can take effect. The cost of any claims relating to failure to follow collective consultation requirements are substantial, and specific advice should therefore always be sought before seeking to implement collective redundancies. We will be publishing further guidance on this on the Hub shortly.
- The Pensions Regulator has published regularly-updated guidance for employers.
- It will take “a proportionate and risk-based approach towards enforcement decisions … with the aim of supporting both employers and savers”. In other words, the law remains the same, but the Regulator will show restraint in enforcement against breaches.
Crucially the phrase “force majeure” has no specific meaning in English law. As a result, there is scope for complex legal argument, including as to whether the effects of the coronavirus outbreak can amount to force majeure in the first place. If the coronavirus crisis deepens, force majeure provisions could become relevant in the following ways:
- suppliers to your business might seek to invoke force majeure
- you may need to invoke force majeure under your own contracts
Each of these will need careful analysis of the relevant contract against the applicable factual background. Unfortunately, the position is unlikely to be clear cut.