Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

What should be included in genuinely self-employed contractor terms?

If you consider the factors used to determine status you can include the following terms that are more in line with a self-employed relationship:

  • The right to provide a substitute of the contractor’s choice in the event the individual is not able to perform the services;
  • The ability to work for other businesses as long as doing so will not affect the services to be provided by the contractor;
  • The contractor should have sufficient control over how, when and where (if possible) they provide the services;
  • A degree of financial risk can be included for unsatisfactory work or failing to complete a project or task

We have terms that cover all of these points that can be tailored to your needs. The consultancy agreement is included in our IR35 toolkit.

What about employees who say they cannot return to work due to childcare issues?

Employers will need to be flexible with employees who are unable to return to work at present due to childcare difficulties. While schools have reopened, a period of isolation may result in employees having to keep children off school/nursery and therefore have childcare issues. Some employees will be able to manage this with their partner and extended family, whereas others will not. Where an employee simply cannot make any other arrangements to care for their children in the short term then they will be unable to return to work until that situation changes. Any dismissals on the basis that someone is unable to return to work as a result of lack of childcare are likely to be unfair, at least in the short term where such employees may well be able to demonstrate that they had no options available to them.

What is my legal position if emergency legislation to tackle the outbreak makes performance of a contract illegal or impossible?

As the coronavirus outbreak continues to develop, we have seen many countries begin to implement emergency procedures and legislation in an attempt to control the spread of the disease.

These have included bans on gatherings and public events, closures of shops, bars, restaurants and public spaces, and full lockdowns which restrict all but key workers to their homes except in certain limited circumstances.

This has a direct impact on businesses and their ability to operate. So what happens if a contract becomes impossible to perform because of emergency legislation?

For example:

  • If you are a hospitality business, you have agreed to host an event, and gatherings are prohibited
  • If you are a manufacturer or service provider, and your staff are required to remain at home, making performance of the contract impossible
How do I go about registering a death at this time?

The Government has introduced legislation to expand the list of those who can register deaths to include Funeral Directors who are dealing with the funeral arrangements and who has been authorised by a relative of the deceased to register the death. Also, the medical cause of death certificate can be emailed to the Registrar’s office and arrangements made to have a telephone appointment to provide the Registrar with information to register the death. The requirement to attend the Registrar in person to sign the Register has been relaxed so that this is not necessary. It will however still be necessary to register the death within 5 days.

What can I do as an employer if employees are known to be breaking the local lockdown rules?

This will depend on the particular facts and the employee’s circumstances but an employee should co-operate with the employer so far as is necessary to enable compliance with any statutory duty or requirement relating to health and safety.

In addition, conduct outside of work can result in an employee’s dismissal if the conduct pertains to the employment relationship. If an employee breaches their lockdown rules and it affects their ability to work, such as it being no longer safe for them to attend work, or the reputation of the employer, these may be grounds for disciplinary action and subsequent dismissal.