How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
Employees who are unable to work because they have caring responsibilities resulting from the coronavirus can continue to be furloughed. For example, employees that need to look after children can be furloughed, as you have previously submitted a claim for them in relation to a furlough period of at least 3 consecutive weeks taking place any time between 1 March 2020 and 30 June.
As more people return to work, there is an increased chance of more parents having childcare issues until Schools are fully open. However, they can’t be placed on furlough unless they had been on it before. So it would likely be unpaid leave, unless the government amends the scheme to grant an exemption.
Every company has to file accounts at Companies House every year. If they are filed late, a fine is automatically levied. If there is a long delay in filing them, the directors are at risk of prosecution and the Registrar of Companies might start a process which could ultimately lead to the company being struck from the register.
However, Companies House has recognised that businesses might currently face exceptional problems in preparing and filing their accounts on time and so have posted a notice on their website which says that if immediately before the filing deadline, it becomes apparent that accounts will not be filed on time due to coronavirus, you can make an application to extend the period allowed for filing.
This scheme is specifically aimed at creating jobs for 18-24 year olds who are on Universal Credit and considered most at risk of unemployment because of the economic downturn. The Government has announced that it will pay young people’s wages (equivalent to 100% the National Minimum Wage plus the associated National Insurance contributions and employer minimum automatic enrolment contributions) for up to 6 months, and that this will amount to a grant worth approximately £6,500 per young person.
The jobs that are created must provide a minimum of 25 hours per week and be paid at a minimum of the National Minimum Wage The Chancellor announced that will be no cap on the number of jobs that will be funded under the Kickstart scheme.
Due to the new guidance on social distancing and remote working, the Planning Inspectorate initially stated that site visits, hearings and inquiries would be cancelled. However, there is very much a push from the Secretary of State to keep the planning system moving notwithstanding the requirements to adapt to new ways of working. The Government now expects all hearings to be conducted virtually and where a virtual hearing is not possible, the expectation is that alternative arrangements will be put “speedily” in place and in accordance with social distancing requirements.
The Planning Inspectorate have been exploring ways of conducting hearings and inquiries remotely using technological means and conducted their first “digital” hearing on 11 May .
The Business and Planning Act 2020, which entered the statute books on 22 July 2020, includes provisions which allow more flexibility in relation to how appeals are determined including an ability for the Secretary of State to decide to adopt a procedure which is a combination of written representations, a hearing and/or an inquiry.
Site visits have re-commenced where it is safe to do so. The Inspectorate is looking at whether a site visit is necessary and has conducted a trial of “virtual site visits” where sites are assessed by means of photographs or video evidence.
The Planning Inspectorate have subsequently been scaling up conducting digital hearings, which also includes holding virtual local plan examination hearings.
In making a Traffic Regulation Order (“TRO”) local authorities must follow the regulations, which include provisions relating to publicity requiring publishing the notice in a local newspaper, making the orders available for public inspection at a Council’s offices (which are likely to be closed to the public during this time) and where considered appropriate, posting the notices on the streets.
In recognition of the potential difficulties with complying with the publicity requirements, the Department for Transport has issued guidance as to how a Council may still publicise a TRO. The guidance recognises that not everyone may be able to access local newspapers online and suggests that people and organisations could be adequately informed by means of letter, leaflet drops, or local radio. In respect of making the relevant document available at the Council’s offices, the guidance suggests that notices could be placed online or outside offices with brief details and including a telephone number or email to use to request a hard copy of the documents.
While the guidance is helpful, it is important to note that it is guidance only and that the regulations have not been relaxed. Authorities will still need to demonstrate that they have satisfied all of the publicity arrangements in respect of the TRO.