Skip to content

What do we need to do?

Privacy policy – You must make sure the relevant privacy policies deal with how you will process Covid-19 data. You should have an employee privacy policy and this may already deal with health data (if it doesn’t, it should). You might also need to look at privacy policies for customers, visitors and suppliers. This ensures that processing is lawful, fair and transparent.

Lawful processing conditions – You will need to consider which processing conditions you are relying on (remembering that you need both an Article 6 condition and an Article 9 condition – this is the part of the GDPR which deals with special category data). As a lot of the data you collect will be about employees, you can’t use consent so you will have to find another lawful reason under GDPR which allows you to process the data.

Appropriate policy document – When you are considering your Article 9 processing conditions, remember you must also have an “appropriate policy document” in place.

Processing record – Finally make sure your processing record is up to date with information on what data you collect and use.

Related FAQs

VIDEO EXPLAINER: Consultation exercises – the why, the who, and the how

This free Getting back to business webinar was held on Thursday 7th May.

On this video, employment partner Edward Nuttman and Graham Vials went through what a consultation exercise is and when you are required to hold one. They then took you step by step through the process, describing all you will need to do to ensure legal compliance whilst at the same time being sensitive to the emotional and motivational impact on your employees and managers.

Can an employee in a public facing role refuse to interact with a customer who is not wearing a face mask?

In some circumstances, visitors and customers are required to wear face coverings, such as those travelling on public transport, shoppers and museum visitors. The government guidance states that:

  • businesses must remind people to wear face coverings where mandated; and
  • premises where face coverings are required should take reasonable steps to promote compliance with the law.

As part of their duty of care to employees and to uphold a relationship of mutual trust and confidence, employers should consider how employees can ensure that visitors and customers comply with the rules and provide their staff with guidance. They must also seek ways to protect their employees both from the risks of those customers not wearing face masks and potential abuse from customers or visitors who decline to wear a face covering. This may include having signs in place requiring customers and visitors to wear a mask and allowing staff to refuse to serve customers if they do not follow the rules.

However, it is ultimately the responsibility of the police, security and public transport officials to remove customers from premises where they are not complying with the rules on face coverings.

The police and Transport for London have been given greater powers by the government to take measures if the public do not comply with the law relating to face coverings without a valid exemption, such as refusing to wear a face covering. This includes issuing fines which have now been increased to £200 for the first offence (and £100 if paid within 14 days). Transport operators can also deny access to their public transport services if a passenger is not wearing a face covering, or direct them to wear one or leave a service.

What options do I have if I have staff with childcare responsibilities but their job cannot be done at home?

If it is not possible to find work for the employee to do at home, you do have the option of putting the employee on furlough.

What are the data protection implications of homeworking?

The Information Commissioner’s Office (ICO) announce new guidance in light of coronavirus.

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

The ICO has stated the following:

Data protection is not a barrier to increased and different types of homeworking. During the pandemic, staff may work from home more frequently than usual and they can use their own device or communications equipment. Data protection law doesn’t prevent that, but you’ll need to consider the same kinds of security measures for homeworking that you’d use in normal circumstances.”

Whether you work from home or in the office, you still need to comply with data protection laws. While you need to process personal data with the same care you use in the office, the home working environment throws up specific data protection concerns particularly in respect of data security. You should make sure you have a home working policy which deals with data protection and these data security issues.

 Organisations must ensure that, for staff who can work from home, their obligations in respect of processing personal data are clearly communicated. Organisations may already have a home working policy – if this is the case, then this should be reviewed to ensure it remains relevant and up-to-date for practices during this pandemic.

Does a sponsor need to report a change in workplace if a Tier 2 visa holder is working from home as a result of Covid-19?

No. The Home Office has confirmed that sponsors do not need to report sponsored workers as working from home, where this is directly related to the coronavirus outbreak.

However any UK employers who sponsor overseas workers, should also ensure that they remain compliant with their other sponsor licence duties, which includes reporting any change to an employee’s salary and duties.