How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
Another obvious cost cutting measure is to reduce working hours, either temporarily or permanently. Again, it should be done fairly, either across the board or by selecting teams/individuals based on objective business reasons. Imposing without agreement would create significant risk, therefore would require fair selection and consultation.
You will be eligible if you are a self-employed individual or a member of a partnership and you:
- have trading profits of up to £50,000
- earn the majority of your income from self-employment
- have submitted a Tax Return for 2019
- have traded in the tax year 2019/20
- are trading when you apply for a grant, or would be except for Covid-19
- intend to continue to trade in the tax year 2020/2021
- have lost trading/partnership profits due to Covid-19
The Government will provide the lender with a partial guarantee (80%) against the outstanding facility balance, subject to an overall cap per lender. Note, the Government guarantee is to the lender only, the borrower will always remain 100% liable for the debt.
We understand that will make an initial claim for recovery against the borrower and will, once its normal recovery procedures have been completed, claim against the Government guarantee.
Employees on any type of employment contract including full-time, part-time, agency, flexible or zero hours and foreign nationals who are eligible to work in the UK on any visa can be furloughed subject to the following excluded categories:
- Anyone who was not employed prior to 30 October 2020
- Anyone for whom you haven’t made a PAYE Real Time Information submission to HMRC between 20 March 2020 and 30 October 2020.
- Employees who are working but on reduced hours or for reduced pay
- Employees currently receiving SSP (see FAQ on SSP and self-isolation below)
- Public sector employees
- Employees of businesses or organisations in receipt of public funding for staff costs (except for those who are not primarily funded by the government and whose staff cannot be redeployed to assist with the Covid-19 response)
If such testing is regarded as a “reasonably practicable step” which has been identified as an appropriate control following a risk assessment then it is something you can do.
Although you can’t physically force someone to have something intrusive done, this is very likely to be a reasonable management instruction and therefore if someone refuses to have this done as a condition of entry into the work place then disciplinary action may follow.
Where this is something that is required of employees, employers should be letting their staff know that this is one of a number of measures that are being introduced into the workplace for their own safety. If the employer can explain, in advance of the return, why temperature checks need to be taken, what the consequences of the results will be- i.e. will they be sent home if over a certain temperature, whether this data will be stored (and if the sole purpose is to determine whether or not they are fit to attend work on a particular day then why are they being stored), and the fact that temperature checks are a requirement of entry to company premises for everyone, then there shouldn’t be significant resistance to this measure.
Large scale temperature checks have in some businesses become part of the “new normal” working environment.