Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

Is there a cap on the number of employees on Flexible Furlough?

Be careful, there is now a cap on the number of employees you can have on furlough at one time.

The number of employees you can claim for in any claim period starting from 1 July cannot exceed the maximum number of employees you claimed for under any claim ending by 30 June 2020. So this cap is going to be specific to each employer.

It may catch out, in particular, employers who had been rotating employees on furlough.

Is there anything else I should consider from a health and safety perspective?

Increased hygiene measures should be introduced to limit the spread of infection. Increase the frequency of cleaning, particularly higher risk contact points such as door handles. Avoid the use and sharing of hardcopy in favour of electronic documents; avoid sharing of tools and work equipment; increase the availability of handwashing facilities and hand sanitisers; issue anti-bacterial wipes and tissues to staff, and remind everyone to maintain good personal hygiene practices, including regular hand washing. Prominent and repeat signage will be vital in reminding workers of these steps they can take to protect themselves.

PPE – e.g. disposable gloves and face masks – are not currently legally required in the UK, but especially where social distancing might not be possible, it may be necessary to make appropriate PPE available to staff. If so, you will need to make sure there is enough available train everyone so it used properly and provide for safe disposal of used items.

MOST IMPORTANTLY – communicate with your people; invite their input and suggestions and act on them. Communication and participation in the process of a safe return to work are going to be crucial to its’ success.
Monitor for illness: train managers how to spot the symptoms of COVID-19 and have a clear process if someone is potentially infected. Continue to remind staff to only come into work if they are well and not experiencing any symptoms. A number of businesses are planning on using testing and screening methods, such as temperature checks. Remember, these steps create data privacy considerations which you will need to consider.

Do not forget existing health and safety obligations, such as maintaining sufficient numbers of fire marshals and first aiders on-site. Employers should also be aware that the Health and Safety Executive must be notified under RIDDOR of any workplace incidents that lead to exposure to COVID-19 and any cases where there is “reasonable evidence” that it was caused by exposure in the workplace. Be aware that workers are being encouraged to report to HSE failures of their employers to keep them safe from the threat of the virus.

What other financial resources are available for charities?

Charities can also take advantage of the existing measures the Government has already put in place including deferring their VAT bills, paying no business rates for their shops next year and furloughing staff where possible with the Government paying 80% of their wages under the Coronavirus Job Retention Scheme – see our People and Employment FAQ’s and our Premise and Property FAQ’s.

Can I offer credits or re-booking as an alternative to a refund?

The financial implications of having to repay all deposits and advance payments could be very serious for some businesses. As an alternative to a refund, many are offering customers the opportunity to re-book at a later date, or a voucher that can be redeemed against a subsequent booking.

The CMA’s view on this practice is that consumers can in many situations be offered alternatives of this type, but they should not be “misled or pressured” into accepting this. Their view is that a refund should be an option that is just as clearly and easily available. The CMA also points out that any restrictions that apply to credits, vouchers, re-booking or re-scheduling, such as the period in which credits must be used or services re-booked, must also be fair and made clear to consumers.

The full CMA guidance re “The Coronavirus (Covid-19) pandemic, consumer contracts, cancellation and refunds” can be found here.

Can employees who are self-isolating or on sick leave be placed on Flexible Furlough?

Employers had the ability to furlough extremely vulnerable employees who needed to shield.

If your employee is on sick leave or self-isolating as a result of Coronavirus, including as a result of track and trace, they’ll be able to get Statutory Sick Pay, subject to other eligibility conditions applying.

There is no special exemption for them, so they would need to meet the usual requirements to be placed on Flexible Furlough after 1 July 2020. i.e. They had to have been placed on furlough for at least 3 weeks before 1 July. Otherwise, they could not be furloughed.