Skip to content

What is classed as a good ratio of MHFA to staff numbers?

There is not a magic number. It depends on the nature of the organisation, the work carried out, the organisational structure, the geographical spread, working patterns and conditions. We would give specific advice personalised to the organisation and taking all these and other factors in to consideration. There is no such things as too many MHFAs!

Related FAQs

Should I have a homeworking policy?

If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:

  • If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
  • Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
  • Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
  • Ensuring staff lock their devices whenever they are not using them
  • Where possible, working in a separate part of the home to family members
  • Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
  • Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
  • Locking any papers in a safe place
  • Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
  • Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
  • Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
  • Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example

Organisations should also ensure that their remote access systems can cope with increased demand.

Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.

We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.

Is it possible to proceed with a hearing in person for any COP matters?

Any hearings attended in person will need to be approved by the judge hearing the matter, if necessary, in consultation with the regional lead COP judge. Such requests are highly unlikely to be granted during COVID-19 unless there is a genuine urgency. However, it is deemed to be appropriate matters are likely to be adjourned on the basis that a remote hearing is not possible and a hearing in person is not safe or possible.

What first steps would you recommend to creating a strategy to integrate pro-active mental health first aid across the workforce?

The Thriving at Work Report and the recent NICE Workplace Mental Health Guidelines provide a good baseline for what all organisations should be doing on workplace mental health – this includes some guidance on training. There does need to be a plan in place and we recommend taking a holistic view of the integration of mental health first aiders into a business – ie it should be one component in a strategy that also comprises training for line managers, awareness training and education for all staff, peer support, and a documented framework for support and signposting.  It is also worth ensuring you have senior manager sponsorship, strong links with Occupational Health if available and also raising awareness via any works councils or employee forums helps ensure there is buy in at all levels.

How much data can I gather?

You also need to consider other aspects of data protection.

Be proportionate – only gather and use Covid-19 data where you need to.

Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.

Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to  make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).

Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.

Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.

Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.

What should businesses do now?

Many will have worked collaboratively with their suppliers and customers to deal with the immediate public health crisis. This will have meant offering flexibility as to contractual arrangements, whether in delivery dates, volumes of goods or services supplied, or even in the specification of what has been delivered.

If this is the case, it is important that businesses now do their legal housekeeping and make sure they have a proper record of what has been agreed. Unfortunately, our experience shows that many legal disputes arise out of amendments to contracts, typically where the parties to the contract each have a different view about what exactly they agreed to change.

We would therefore advise businesses to review any amendments that they might have agreed either verbally, by email, or otherwise, and consider whether they need to be captured in a more formal way which will make clear exactly what has been agreed to be varied, and (where appropriate) how long that variation will remain in force.

It’s also important to remember that some contracts contain provisions that set out specific requirements about how amendments are to be made. For example, they might require that amendments are made in writing (rather than verbally). These “No Oral Modification” clauses are commonly found in commercial contracts, and the courts have recently shown that they are willing to enforce them.

Failing to deal with amendments in accordance with contractual requirements could therefore have a serious impact on businesses as they recover from the disruption caused by the lockdown. If they end up in dispute with a customer or supplier, a business could find that the contract has not actually been amended in the way that they think – potentially leading to legal costs and liabilities at the worst possible time.