Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

What is the risk if I insist that my employees have the vaccine?

If you do not have a justifiable reason for insisting that your employees have the vaccine (see FAQ above) your employee could resign and bring a claim of constructive unfair dismissal if they have more than 2 years’ continuous employment. This would be on the basis that you have breached trust and confidence.

If the vaccine includes pig gelatine (as many do), and the employee refuses on religious or because they are vegan, you may face a claim for discrimination under the Equality Act 2010.

Read more about this
What is the Clinical Negligence Scheme for Coronavirus?

The Government has recently passed the Coronavirus Act 2020 in a response to the challenges posed by the pandemic, especially in relation to those facing the NHS during this time of crisis.  NHS Resolution worked closely with the Department for Health and Social Care to draft a clause within the Coronavirus Act providing indemnity for clinical negligence for any coronavirus related activity not currently covered by an existing arrangement.  In order to implement this clause, NHS Resolution has launched the Clinical Negligence Scheme for Coronavirus (“CNSC”).

It is intended that the CNSC will cover new contracts put in place for healthcare arrangements to respond to coronavirus, such as organisations supporting testing arrangements or Independent Contractors making agreements with NHS England and NHS Improvement to release capacity to the NHS.  Membership is not required for this scheme and the contracts entered into will automatically provide indemnity under the scheme.

The CNSC will not replace existing indemnity provisions made under the Clinical Negligence Scheme for Trusts (“CNST”) and it has been confirmed that the new Nightingale Hospitals will be covered by CNST rather than CNSC.  Similarly, NHS Resolution have confirmed that those doctors and nurses returning to practice from retirement, or those joining as students will be covered by the CNST or, where applicable the Clinical Negligence Scheme for General Practice (“CNSGP”).  The CNSC will not cover returning midwives to the profession, but the Royal College of Midwives have confirmed that they will extend all of the benefits of membership including Medical Malpractice Insurance to returning retired midwives.

For more information regarding this please click here.

Read more about this
Should you rely upon Statutory Demands issued after 1 March to present a Winding Up petition?

No. No action need be taken in relation to the demand but we would advise against presentation of a petition based upon any Statutory Demand issued between 1 March 2020 and the end of the restrictions. As you may be aware, with Winding Up there is no requirement to issue a Statutory Demand notice before proceeding so this is unlikely to create too many issues – click here to see whether you should issue petitions on other grounds.

There is nothing to prevent statutory demands being served at this time. However, there may be limited benefit as it cannot form the basis of a future winding up petition.

Read more about this
What if you want to terminate the contract completely?

If changed circumstances mean that a business wants to exit from a contractual arrangement, then before trying to terminate it, a careful review should be carried out to see whether a right to terminate actually exists. For example:

  • Not every contract for the sale of goods contains the right for the buyer to terminate in circumstances where the supplier hasn’t done anything wrong. If a business has entered into a contract on the supplier’s standard terms, it is unlikely to contain any such provision
  • A contract for the provision of services is unlikely, if drafted by the customer, to contain a provision that allows the supplier to walk away from the arrangement at short notice, or perhaps at all

If a party tries to terminate a contract when it doesn’t have the right to do so, the other party will likely claim breach of contract and could sue for damages. In the case of a long term or high-value contract, this could amount to a very significant liability.

Even if the right to terminate the contract does exist, there might be particular rules about the following:

  • How much notice has to be given
  • How such notice has to be served (for example, it might have to be in writing to a particular address)
  • When the notice can be served (perhaps on an anniversary of the start of the contract)
  • How much a party has to pay if it cancels (for example, for raw materials, for work done to date, or even the whole contract price)

All of these factors must be taken into account, and any contractual processes for termination are followed.

Read more about this
VIDEO EXPLAINER: Consultation exercises – the why, the who, and the how

This free Getting back to business webinar was held on Thursday 7th May.

On this video, employment partner Edward Nuttman and Graham Vials went through what a consultation exercise is and when you are required to hold one. They then took you step by step through the process, describing all you will need to do to ensure legal compliance whilst at the same time being sensitive to the emotional and motivational impact on your employees and managers.

Read more about this