Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

What should I do if my apprentice is due to finish their fixed-term contract during the pandemic?

Employers who have apprentices on fixed-term contracts due to end during the pandemic should discuss arrangements with the apprentices including whether an extension to the contract can be offered to allow them to complete their apprenticeship.

What happens if a patient is admitted to hospital during the pandemic?
Are there steps to ensure they will have access to an open register (BSR) & building safety assessments etc?

The Act should make it easier for residents to obtain relevant information. It includes an obligation for the Principal Accountable Person to prepare a strategy for promoting the participation of residents, including the information to be provided to them and consultations about relevant decisions. The strategy must be provided to residents, and there will be provision for residents to be able to request information and copies of documents from the Principal Accountable Person. The type of information and the form in which it is to be provided will be set out in secondary legislation in due course, but the explanatory notes anticipate that it will include:

  • Full current and historical fire risk assessments•Planned maintenance and repair schedules
  • The outcome of building safety inspection checks
  • Information on how assets in the building are managed
  • Details of preventative measures
  • Details of fire protection measures and the fire strategy for the building
  • Information on the maintenance of fire safety systems
  • Structural assessments
  • Planned and historical changes to the building
What will happen to patent, trade mark and design registration applications that are currently being processed or which I want to file?

In recognition of the problems that the current situation is causing, the UK IPO classed the 24th March and all subsequent days as “interrupted days” which means that deadlines that fall within this period will be extended until the UK IPO declares that the interrupted days have ceased. As lockdown has begun to be eased, the IPO has now reviewed its position and has confirmed that the “interrupted days” period will come to an end on the 29 July 2020. This means that Thursday 30 July 2020 will be the first normal day of operation, therefore all “interrupted days” deadlines will expire on this day. Similarly, if your deadline falls after the period of interruption ends, this deadline will not be automatically extended.

The IPO is conscious that many businesses may still be in challenging positions when the period of “interrupted days” end. They will endeavour to continue to provide flexibility and support to assist businesses with their applications. They hope to temporarily remove fees for requests for extensions of deadlines, and will give further updates when this fee exemption is in place.

The IPO continues to encourage applicants to meet original deadlines where they are able.  As their offices are closed, the UK IPO is not currently processing paper forms (i.e. hard copy) and faxes. However, they are processing forms which have been submitted electronically, or via email and have made a new email address available for the submission of forms.

Intellectual Property Offices covering other territories have made their own announcements about the extension of deadlines. The EUIPO’s period of extension of deadlines came to an end on the 18th May. However, they have published a Guidance Note and accompanying webinar on the EUIPO website, detailing options for parties who may struggle to meet deadlines and remedies for those who may have missed deadlines.

Alternatives to redundancy toolkit

We have developed a Toolkit to help with these issues. The Toolkit contains:

  • LO1 How to Guide: Lay off and short time working
  • LO2 Letter directing employee to take annual leave
  • LO3 Letter confirming lay off (contractual right)
  • LO4 Letter confirming short time working (contractual right)
  • LO5 Letter proposing lay off (no contractual right)
  • LO6 Letter proposing short time working (no contractual right)
  • LO7 Counter notice disputing entitlement to claim redundancy payment
  • LO8 Script for announcing lay off or short time working (contractual right)
  • LO9 Script for announcing lay off or short time working (no contractual right)
  • LO10 Letter proposing reduction in working hours and pay

The cost of this Toolkit is £500 plus vat. If you would like to find out more about the Toolkit, please speak to your usual Ward Hadaway employment contact, or get in touch one of the contacts at the bottom of this page.