Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

Can employees on Flexible Furlough work as union or non-union representatives or as pension trustees?

Employees who are union or non-union representatives may undertake duties and activities for the purpose of individual or collective representation of employees or other workers. However in doing this, they must not provide services to or generate revenue for, or on behalf of your organisation or a linked or associated organisation.

Employees who are pension scheme trustees or trustee directors of a corporate trustee may also undertake trustee duties in relation to the pension scheme. However, a professional, independent pension scheme trustee who has been furloughed by the independent trustee company cannot undertake trustee work that would provide services to or generate revenue for, or on behalf of, the independent trustee company or any organisation linked or associated with that independent trustee company during hours when they are recorded as being on furlough.

VIDEO: An update from cashflow.co.uk expert Chris Silverwood about access to finance

Partner at Ward Hadaway Adrian Ballam catches up with corporate finance expert and CBILS specialist Chris Silverwood (CorpFin and cashflow.co.uk) a month after their initial conversation to talk about what the last couple of months have taught us about access to finance.

Sections of the video and their timings are as follows:

(01.06) – example of continuing appetite for certain businesses (e.g. tech sector)

(02.06) – conflict between incumbent bank and different CBILS lenders, plus brief discussion of CBILS II

(05.36) – bounce back loans have been a distraction

(06.27) – muted impact of fintech CBILS lenders

(07.52) – discussion about invoice discounting

(11.59) – looming insolvency environment

(12:52) – emerging themes

 

Do you have to collectively consult for the minimum period of time before you can issue notice?

These periods are often mistakenly referred to as minimum lengths of consultation (especially by Trade Unions). That is not correct. Consultation can commence, conclude and notices of dismissal be issued within the 30 and 45 day periods. The expiry of the notice would just have to be outside of those restricted periods.

Can I ask my employees to stay away from home overnight during the national lockdown?

As above, employees must not leave their home unless they have a ‘reasonable excuse’.

How do I apply for an extension to Companies House?

The application is made via the Companies House website, and only takes a few minutes to complete. Companies House have indicated that the extension is “automatic and immediate” and will be for three months.

Having said that the extension is “automatic”, their website also says that Companies that have already extended their filing deadline, or shortened their accounting reference period, may not be eligible for an extension.

If an extension is granted, it will not affect the due date for filing accounts in future years – so the deadline will revert to the usual date for the next accounting period.