How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
Conduct risk assessments! Your RA must cover every foreseeable risk arising from a return to the workplace, including the impact of reduced staff levels and any operational/administrative changes necessary to ensure social distancing.
Appropriate steps should be taken to manage and mitigate identified risks. Where this is not possible, businesses need to decide whether certain activities are necessary for the business to operate or if they can be temporarily put on hold.
Keep a close eye on the comprehensive Government guidance: https://www.gov.uk/guidance/working-safely-during-coronavirus-covid-19
In particular focus on social distancing and workplace health measures. This guidance will evolve over time and you will need to be sure that your organisation is sticking to it AND reviewing and updating its risk assessment.
There is less guidance in respect of whether an employee can refuse to go into the workplace as a result of health and safety concerns about their commute. An employer’s duties to ensure the health, safety and welfare of its employees only extend to the workplace or where an employee is acting in the course of their employment. This does not include the risks of travelling to and from work by public transport.
As there are various ways in which an employee can travel to work, it will be difficult for them to legitimately refuse to come to work due to their commute. Employers should discuss any concerns with the employee and seek to find an appropriate resolution. The government has published guidance on safer travel for passengers during the Covid-19 pandemic and employers should encourage flexibility as far as possible, such as allowing employees to travel at off-peak times and staggering workers’ hours.
Yes. Government guidance now confirms that employers can be required to take holiday during a period of furlough, so long as they are given minimum notice to do so. The notice required is double the length of the holiday.
Employers are also able to cancel employees’ holidays (or require them not to take holiday) if they are on furlough, for example if they are not in a position to pay the additional 20% top up to their normal wages (or more where they earn in excess of the £2,500 monthly cap on furlough payments). Again, employers are required to provide a minimum period of notice of cancellation, which in this case, is the length of the planned holiday.
Employers can ask employees to take or cancel holiday with less notice but they would need to get their agreement to do so.
Government guidance has been updated to state that “Employees should not be placed on furlough for a period simply because they are on holiday for that period.” If a period of furlough happens to coincide with an employee’s holiday then you should ensure that there are business grounds to support furlough being used in that instance so that it isn’t just being used as a means to fund holiday utilisation.
The Government will provide the lender with a partial guarantee (80%) against the outstanding facility balance, subject to an overall cap per lender. Note, the Government guarantee is to the lender only, the borrower will always remain 100% liable for the debt.
We understand that will make an initial claim for recovery against the borrower and will, once its normal recovery procedures have been completed, claim against the Government guarantee.
During the COVID-19 global pandemic, trials and hearings have been mostly conducted over Skype for Business and various other online platforms. Looking forward to the future, what we have experienced during the lock-down may continue and we believe will make litigation a more streamlined, user friendly experience for litigants.
One example of a regime which has been introduced is hybrid trials for lower value claims. Hybrid trials allow for parties and their witnesses to be linked into the court room by video link, whilst the judge and advocates are present in court. This makes it easier and frees up more time for witnesses, which would otherwise be spent in travel and waiting time, especially for those with other commitments.
With hybrid trials, clients still get a full legal experience and the judge will still apply normal legal principles during the trial. The procedure for the case is the same, both leading up to the trial or hearing and during the case itself; except without the need to physically attend court. It may also mean that there will be less of a backlog arising from the current crisis with cases continuing to be heard, allowing for matters to be listed earlier and a quicker outcome for the parties involved.
The shift to the use of online platforms may prove more practical for all those involved in legal matters. Interim hearings can be heard remotely resulting in a time and cost saving for litigants. Even for the final hearing only the legal representatives need to attend court – again resulting in time and cost savings for all concerned.