How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
We have developed a Toolkit to help with these issues. The Toolkit contains:
- LO1 How to Guide: Lay off and short time working
- LO2 Letter directing employee to take annual leave
- LO3 Letter confirming lay off (contractual right)
- LO4 Letter confirming short time working (contractual right)
- LO5 Letter proposing lay off (no contractual right)
- LO6 Letter proposing short time working (no contractual right)
- LO7 Counter notice disputing entitlement to claim redundancy payment
- LO8 Script for announcing lay off or short time working (contractual right)
- LO9 Script for announcing lay off or short time working (no contractual right)
- LO10 Letter proposing reduction in working hours and pay
The cost of this Toolkit is £500 plus vat. If you would like to find out more about the Toolkit, please speak to your usual Ward Hadaway employment contact, or get in touch one of the contacts at the bottom of this page.
The vast majority of disputes settle without ever reaching a final hearing with something in the region of 2-5% of all cases actually ending up in court at a final trial. So whilst it is very unlikely you would need to attend a court hearing, it is always a possibility.
If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:
- If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
- Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
- Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
- Ensuring staff lock their devices whenever they are not using them
- Where possible, working in a separate part of the home to family members
- Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
- Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
- Locking any papers in a safe place
- Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
- Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
- Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
- Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example
Organisations should also ensure that their remote access systems can cope with increased demand.
Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.
We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.
The Government has announced a £750 million funding package for charities to ensure they can continue their vital work during the coronavirus outbreak. This is for a 3 month period and further specific funding may be made available.
Charities which are businesses can also access the Government’s Coronavirus Business Interruption Loan Scheme (CBILS) – Please see our Funding and Finance FAQ’s.
Solicitors can be authorised to sign contracts for their clients – a signed letter of authority should be scanned and sent to avoid posting potentially contaminated documents.
Solicitors should exchange supplemental agreements on behalf of their clients to agree to postpone exchange and completion dates if it has been agreed to push these back.
The Law Society advises that electronic signatures be used as much as possible for contracts, to avoid possible contamination. However, the Land Registry confirms that the legal transfer document cannot be validly executed with an electronic signature. Solicitors should agree a completion undertaking that the original transfer document will be sent when received and after the restrictions have been lifted.
The Land Registry’s latest guidance https://www.gov.uk/guidance/coronavirus-covid-19-impact-on-hm-land-registrys-services published on 14 May states:
We accept deeds that have been signed using the ‘Mercury signing approach’.
For land registration purposes, a signature page will need to be signed in pen and witnessed in person (not by a video call). The signature will then need to be captured, with a scanner or a camera, to produce a PDF, JPEG or other suitable copy of the signed signature page. Each party sends a single email to their conveyancer to which is attached the final agreed copy of the document and the copy of the signed signature page.
Solicitors should be willing to adopt this procedure for completing transactions to enable them to be registered by the Land Registry.
The execution of a transfer is a deed and must be witnessed. Members of the family can witness signatures so long as they are not also a party to the document. A witness will be more credible if they are 18 or over, but this is not a legal requirement. The legal requirement is for the witness “to be present” when the document is signed. It would be possible for a witness to be on the other side of the room or the other side of a window, and validly witness the execution of a deed. The witness does need to take precautions to avoid possible contamination from the document.
A statutory declaration does not need to be witnessed but must be administered by a solicitor or commissioner for oaths. There is no legally prescribed process for this, and there is nothing to suggest that this could not be validly done via a video telephone call if the signature on the declaration can clearly be seen by the person commissioning the oath when the oath is made.