How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
If a tenant continues to refuse to take heed of the government’s social-distancing guidelines, for example by inviting large groups of people who do not reside there to their property, it can constitute a nuisance. One housing association successfully applied for an injunction. The injunction ordered by the Court stipulated that no persons, other than the children of the tenant, are to attend the property until the current social-distancing restrictions are lifted by the government.
A representative of the housing association highlighted the need for the current guidelines to be followed and the need for housing providers to ensure that all residents living in their communities are kept safe during this time of ‘unprecedented risk’.
This case demonstrates that flouting of the current restrictions is likely to be considered anti-social in the eyes of the courts – a point which all housing providers should bear in mind during this period. Further, it highlights the availability of an alternative remedy to the issuing of possession proceedings (in light of the government’s moratorium on evictions) to deal with anti-social behaviour during the next three months, Covid-19 related or not.
- Remember that employees will also be making contributions on any reduced wage under the Coronavirus Job Retention Scheme. The amount contributed may be less, but the contribution rate will be the same, unless the following applies.
- Employees may reduce their DC employee contributions if their scheme rules allow them to do so, but no further than the statutory minimum if the scheme qualifies as the employer’s auto-enrolment vehicle.
- Employees might choose to opt-out or cease active membership of their scheme, which might cause a spike in administration at a time when administrators are likely to be understaffed. It is important that employers remember they must not do anything to encourage or induce employees from leaving an auto-enrolment vehicle as this may constitute an offence.
- Employees who leave their scheme in this way will have to be re-enrolled in due course as and when required by law.
- For DB schemes, specific considerations apply (see the last section, below).
You cannot include the following payments in a claim:
- Discretionary bonus or commission payments
- Tips
- Non-cash payments
- Non-monetary benefits including taxable benefits in kind
- Salary sacrifice benefits that reduce an employee’s pay (however HMRC has agreed that such arrangements can be stopped by agreement if due to COVID-19 and the contract is changed)
The updated guidance has confirmed that all of the grant claimed should be paid to the employee in the form of money and that none of the grant is to the used to pay for the provision of benefits or a salary sacrifice scheme.
As we all adjust and adapt in line with the Government’s guidance throughout this uncertain time, we must consider how we can revise current processes and implement new ones to maintain effective and compliant ways of working. We have identified several key issues that all housing providers should consider.
Protocol Compliance
Housing providers will continue to receive new disrepair claims. Throughout the disruption caused by coronavirus, landlords will still be expected to respond to these claims and comply with the Pre-Action Protocol for Housing Conditions Claims whilst doing so. We address the issue of disclosure in particular below.
Letters of claim will continue to be sent by post to your Registered Office, and the deadlines will run from the date of deemed service. Ensure you have systems to enable you to scan correspondence and forward it to the responsible officer who will handle the claim so deadlines are met.
Under the Protocol, the deadline for disclosure is 20 working days from deemed service of a letter of claim (2 working days after it is sent). So, for example, a letter dated 2 March 2020 would be deemed served on 4 March 2020 and disclosure would therefore be due by 1 April 2020. All housing providers must continue to comply with the Protocol and so landlords should begin preparing now.
Failure to meet deadlines often result in the issuing of further applications to court by tenant’s solicitors which in turn will lead to unnecessary costs orders against landlords.
Therefore, all records, particularly relating to customer contact and repair logs, should be held electronically. If required, this will allow for such documentation to be redacted for GDPR purposes remotely and disclosed to the tenant’s solicitor simply and efficiently.
Remember it is possible to request an extension to all Protocol deadlines and it is inevitable in these unusual times, this will need to be utilised, and should not be refused. Request extensions to deadlines at the earliest opportunity to enable an achievable timescale. It would be a difficult lawyer that would not agree to such a request.
The duty is to inform and consult appropriate representatives of the “affected employees”.
Note that the term “affected employees” means those who may be “affected by the proposed dismissals or who may be affected by measures taken in connection with those dismissals”. The term extends beyond those immediately at risk of dismissal to include those affected by measures associated with the redundancies.
“Appropriate representatives” can be:
- The Trade Union (if recognised)
- (For any roles not covered by collective recognition) any existing standing body of elected or appointed employee representatives (if already in place)
- Employee representatives, who are elected specifically for redundancy consultation