Do employers still have to enrol and reenrol employees?
- Yes, and this includes furloughed employees under the Coronavirus Job Retention Scheme.
- Employers must continue to assess their new employees or newly eligible existing employees and enrol them where required, but can make use of the statutory postponement procedure which allows them to delay for up to three months the assessment of new employees for the purpose of enrolment (see further details here on the Pensions Regulator’s website). Declarations of compliance for new employers must still be completed in the normal way.
- Postponement cannot be used for re-enrolment. The Regulator recommends employers use the re-enrolment date tool on the Regulator’s website to choose a date up to three months after the third anniversary of enrolment to assess staff for re-enrolment. Further information about employers’ obligations about reenrolment from the Pensions Regulator can be found here. Re-declarations of compliance for new employers must still be completed in the normal way.
Related FAQs
As we all adjust and adapt in line with the Government’s guidance throughout this uncertain time, we must consider how we can revise current processes and implement new ones to maintain effective and compliant ways of working. We have identified several key issues that all housing providers should consider.
Protocol Compliance
Housing providers will continue to receive new disrepair claims. Throughout the disruption caused by coronavirus, landlords will still be expected to respond to these claims and comply with the Pre-Action Protocol for Housing Conditions Claims whilst doing so. We address the issue of disclosure in particular below.
Letters of claim will continue to be sent by post to your Registered Office, and the deadlines will run from the date of deemed service. Ensure you have systems to enable you to scan correspondence and forward it to the responsible officer who will handle the claim so deadlines are met.
Under the Protocol, the deadline for disclosure is 20 working days from deemed service of a letter of claim (2 working days after it is sent). So, for example, a letter dated 2 March 2020 would be deemed served on 4 March 2020 and disclosure would therefore be due by 1 April 2020. All housing providers must continue to comply with the Protocol and so landlords should begin preparing now.
Failure to meet deadlines often result in the issuing of further applications to court by tenant’s solicitors which in turn will lead to unnecessary costs orders against landlords.
Therefore, all records, particularly relating to customer contact and repair logs, should be held electronically. If required, this will allow for such documentation to be redacted for GDPR purposes remotely and disclosed to the tenant’s solicitor simply and efficiently.
Remember it is possible to request an extension to all Protocol deadlines and it is inevitable in these unusual times, this will need to be utilised, and should not be refused. Request extensions to deadlines at the earliest opportunity to enable an achievable timescale. It would be a difficult lawyer that would not agree to such a request.
There should be some data collected as to the type and number of interactions MHFA are having, to ensure no one individual or individuals are overloaded. MHFAs should be encouraged to maintain regular self-care practice, to lean in to all support provisions available in their organisation, to engage in peer support, and to take a break from their role as a MHFA to prioritise their own wellbeing as needed. It is also important that those who volunteer to be MHFAs have the support of their managers. So they have the time to do both their core role and their MHFA duties without feeling pressurised to cram work into spare time to make up for time spent on MHFA duties.
Privacy policy – You must make sure the relevant privacy policies deal with how you will process Covid-19 data. You should have an employee privacy policy and this may already deal with health data (if it doesn’t, it should). You might also need to look at privacy policies for customers, visitors and suppliers. This ensures that processing is lawful, fair and transparent.
Lawful processing conditions – You will need to consider which processing conditions you are relying on (remembering that you need both an Article 6 condition and an Article 9 condition – this is the part of the GDPR which deals with special category data). As a lot of the data you collect will be about employees, you can’t use consent so you will have to find another lawful reason under GDPR which allows you to process the data.
Appropriate policy document – When you are considering your Article 9 processing conditions, remember you must also have an “appropriate policy document” in place.
Processing record – Finally make sure your processing record is up to date with information on what data you collect and use.
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Crucially the phrase “force majeure” has no specific meaning in English law. As a result, there is scope for complex legal argument, including as to whether the effects of the coronavirus outbreak can amount to force majeure in the first place. If the coronavirus crisis deepens, force majeure provisions could become relevant in the following ways:
- suppliers to your business might seek to invoke force majeure
- you may need to invoke force majeure under your own contracts
Each of these will need careful analysis of the relevant contract against the applicable factual background. Unfortunately, the position is unlikely to be clear cut.