Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

What suggestions do you have to raise the profile of the MHFA group in an organisation, particularly with agile working?

Details of your MHFAs should be posted somewhere that everyone can access easily – a specific area on an intranet or whatever alternative exists. Regular comms involving the MHFAs, webinar sessions, Q&A sessions and mental wellbeing drop in sessions are all ideas that may work well.

Do leaseholders who have more than three properties in the UK have to pay the full contribution for building safety works and is there a way of finding out how many properties out leaseholders have in the UK?

The first point to note is that it is the position as at 14 February 2022 which is relevant, as whether or not a lease is a ‘qualifying lease’ for the purposes of recovering costs under the Building Safety Act was effectively frozen at that time.

If a leaseholder owned more than three properties in the UK (and the property in question was not their principal home) at that time, then the lease will not be a qualifying lease. The protections under the Act which prevent or restrict the landlord’s ability to recover the cost of remedial works through the service charge will not therefore apply to that lease (save potentially for the provision that costs cannot be recovered where the landlord is responsible for the defects, which does not expressly refer to qualifying leases).

The lack of a searchable database to assess how many properties a leaseholder has in the UK is however one of the difficulties to be resolved in this regard, as there is currently no way of searching the Land Registry to obtain a list of properties owned by one individual. The guidance appears to rely on the leaseholder completing the leaseholder deed of certificate being open and honest in this regard, and that deed of certificate being passed onto subsequent owners. Making false representations or failing to disclose required information in the deed of certificate may be a criminal offence, although reliance on this to discourage mis-reporting is clearly less satisfactory than having a searchable register.

How do I reduce employment costs? Are we talking about redundancy?

The obvious option to reduce the cost of your workforce is redundancy. However, that also reduces the number of employees and therefore your capacity.

Can a Tier 2 sponsored worker start working before their visa has been granted?

Ordinarily, no but during the pandemic, yes.

You can start employing a Tier 2 or 5 worker who is in the UK before their visa application has been decided if the following conditions have been met.

  • You have assigned the worker a Certificate of Sponsorship
  • They have made an in time visa application (i.e. they made their new visa application before their current leave expired) and they have provided you with evidence of this
  • The job you employ them in is the same as the one stated on their Certificate of Sponsorship.

Sponsors should be aware that they should carry out right to work checks before the individual starts undertaking work for them and if their visa application is eventually rejected, they must stop employing them.

Although sponsors will not be able to record migrant activity on the SMS about these workers, the Home Office has confirmed that any necessary reports should still be made on the sponsor’s internal systems.

If the worker is outside the UK, they may be able to start work for you remotely subject to the relevant employment, tax and immigration requirements in that country.

What should I do if I think this is relevant to my contracts?

It would be prudent to take legal advice early in relation to any issue you foresee in performing a contract. This will allow you to:

  • Ensure that initial contact with your counterparty is framed in the correct way
  • Ensure that any variations are fully documented so that both parties are fully protected