How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
The Chief Coroner adopts the approach taken by the Lord Chief Justice in that no physical hearing should take place unless it is urgent and essential business, and it is safe for all involved. If a hearing is to take place, social distancing must be maintained. All hearings that can take place remotely should do so, if it is not possible for social distancing requirements to be met. The expectation is that some hearings will go ahead, most notably Rule 23 hearings. Coroners are reminded that they must however conduct any remote hearings from a court. Decisions as to the most appropriate approach will be left to the senior coroner in that jurisdiction.
As we have already seen, some inquests will be adjourned, most notably those with multiple witnesses and/or a jury.
The guidance stresses the need, when dealing with medical professionals, for coroners to recognise their primary clinical commitments, particularly in these high-pressured times. This could mean avoiding or deferring requests for lengthy reports/ statements and accommodating clinical commitments if clinicians are called as witnesses.
The guidance encourages proactive reviews of outstanding responses to Prevention of Future Death reports and extending timescales for Trusts to respond.
The FCA’s test case in the Supreme Court ruled overwhelmingly in favour of policyholders. However, business interruption cover generally has the prerequisite of physical damage or loss to the property (or in some circumstances, the presence of a notifiable disease at the property or within a certain radius of it), to recover losses caused by the interruption to your business. The onus is on insurers to re-assess those claims which are impacted by the Supreme Court’s judgment and to make contact with the policyholders regarding next steps. If you have not already made a claim, in the first instance the terms of any policy should be checked carefully to see whether business interruption cover is provided.
Ordinarily, no but during the pandemic, yes.
You can start employing a Tier 2 or 5 worker who is in the UK before their visa application has been decided if the following conditions have been met.
- You have assigned the worker a Certificate of Sponsorship
- They have made an in time visa application (i.e. they made their new visa application before their current leave expired) and they have provided you with evidence of this
- The job you employ them in is the same as the one stated on their Certificate of Sponsorship.
Sponsors should be aware that they should carry out right to work checks before the individual starts undertaking work for them and if their visa application is eventually rejected, they must stop employing them.
Although sponsors will not be able to record migrant activity on the SMS about these workers, the Home Office has confirmed that any necessary reports should still be made on the sponsor’s internal systems.
If the worker is outside the UK, they may be able to start work for you remotely subject to the relevant employment, tax and immigration requirements in that country.
Funding audits are being paused and no new audits will be commenced during the lockdown period.
From 8 June 2020, people entering the UK from overseas (excluding those entering from Ireland, the Channel Islands or the Isle of Man) must comply with a mandatory 14 day quarantine period. However, for those travelling to England, a number of country specific exemptions have been introduced.
A full list of the countries excluded from the quarantine provisions can be found on the gov.uk website which change on a regular basis, often on short notice.
Where a quarantine period does apply, a person will not be able to leave the place they are staying in for 14 days, except in some very limited circumstances.
These rules will apply to both British and foreign nationals, however there are some further exemptions to this rule where a person is coming to the UK to undertake a certain role (such as a healthcare professional coming to the UK to provide essential healthcare). A full list of the narrow exemptions can be found on the gov.uk website.
Before travelling, individuals will be asked to provide their contact details and information about their journey and the accommodation that they will be self-isolating in. To do this, individuals will need to fill in an online form on the gov.uk website. Individuals who refuse to fill in this form may be fined £100 and/or denied entry at the UK border should they not be a British citizen or UK resident.
The information provided in the form will ensure that the Government can check that an individual is self-isolating at the address given. Where an individual refuses to self-isolate they can be fined £1,000 if they are staying in England or Wales.
Once visa application centres re-open overseas and UK visa applications are processed, this 14 day period will need to be taken into consideration and may require employment start dates in the UK to be delayed.