How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
As their employer, you have an overriding duty to provide a safe system of work. The Trust would not be able to run a defence to say that an employee “waived their rights” and chose to continue to work. Provided the decision around restricting duties has been carefully thought out, a full risk assessment undertaken and the employee has been truly consulted about the impact on them, then the decision taken will be a reasonable management instruction. Failing to follow that reasonable management instruction could amount to a disciplinary offence.
Those who are eligible will be contacted directly by HMRC based on tax returns they have received. If you are eligible you will be asked to fill out an online application. HMRC will pay applicants directly.
If you are running a business, yes you can. Please see our Funding and Finance FAQ’s.
We are hearing that Banks are more likely to advance monies on the basis of known income, so for example notified legacies, where there may be a time lag in them being received or against investments where, if they were realised now, would crystallise a loss. Asking for a loan which will need to repaid from future services or trading income should be carefully considered in particular where the charity does not operate to create a surplus which would allow this.
Undeniably and understandably BAME staff, as well as those staff who are identified as being at a higher risk, are going to have high levels of stress and anxiety. For some, this may become of such severity that those staff should be considered to be disabled under the Equality Act 2010. The question as to whether someone is disabled is one that should be answered in conjunction with appropriate medical advice. But the question about how to support any staff suffering with stress and anxiety should not be left until that stage. Proactive steps need to be taken and expert advice obtained on what support measures should be put in place. We know that many NHS organisations are already giving the mental wellbeing of their staff the highest priority.
From our perspective, we would ask managers to be mindful that stress and anxiety is likely to feature in how an individual reacts to questions about the level of risk to their health and the impact on their duties. The conversations with some staff may not be easy to have and may be met with challenge.
For those staff who’s stress and anxiety is such that it would qualify as a disability, reasonable adjustments will need to be considered to the processes that you are applying.
An additional point to consider – it might be worth writing to all staff, asking them to come forward if they have any health conditions that they think you ought to be aware of, assuring them that such information is being given in the strictest confidence. You want to make sure that you are taking the appropriate measures to ensure their health and safety.
The NHS Test and Trace service is operated by the NHS in England to track and help prevent the spread of COVID-19. Where an individual displays symptoms of coronavirus they can be tested to determine whether or not they have the disease. Those with the disease will then be contacted by NHS contact tracers and asked who they have come into close contract with.
Close contact is defined as:
- Face to face (within 1 metre)
- Spent more than 15 minutes within 2 metres of another person
- Travelled in a car or on a plane with another person
The contact tracer will then contact those people with whom the individual has come into close contact and tell them to self-isolate for 14 days.