Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

How do you manage employees who aren't furloughed and are unhappy that they still have to work?

Although there is no formal selection process that must be followed in order to furlough staff, the basis for selecting who will be furloughed should be explained to all relevant staff. Basing this on work levels, required skills or whether work can in fact be carried out efficiently from home will help this process. Staff can be invited to volunteer to be furloughed or re-furloughed. Any requests can be considered on a case by case basis. It may be that a particular skill set is required which may result in an employee’s request being refused.

VIDEO: Market outlooks – the before, during and after

At 10am on the 21st July, we hosted the fourth of our “in conversation…” webinars, this time featuring the ninth largest private bank in the world, Swiss-based Julius Baer. Ward Hadaway partner Emma Digby once again lead the conversation, this time with Luke Downes and Darren Hirst from their investment and relationship teams on “Market outlooks – the before, during and after”. They were joined by Andrew Evans from our private client team to feed in his perspective. This will be of interest to individuals who are thinking about investment portfolios and pension pots, but also businesses keen to see how investors are viewing their sectors, markets and customers.

Luke and Darren took us through how the markets looked pre-Covid, how they responded to the pandemic, and obviously most importantly what we might expect going forwards. They took a look at the sectors that are seeing the quickest bounce-back, discuss which countries are likely to be the most attractive for investors, and where the long term financial gains are expected to be. They also touched on that imminent event, shrouded in mist recently but no less significant – Brexit! What is the expected effect on the markets, and who are likely to be the winners and the losers?

What are the additional costs for the end user if the contractor is deemed employed?

The immediate impact is accounting for payroll purposes for the additional cost of 13.8% employers NIC’s and 0.5% apprenticeship levy on top of the payment to the contactor’s PSC.

Secondary NIC’s cannot be recovered from payments due to employees and the same applies under the new IR35 regime. However, new terms can be agreed with reduced level of fees to reflect this additional cost.

What does the new Chief Coroner guidance cover?

This guidance from the Chief Coroner applies to reports of death and coroner investigations in England and Wales. It is to assist coroners in continuing to exercise their judicial decisions independently, in accordance with the law, and during the extraordinarily pressured events being faced at present.

I'm self-isolating and understand that it takes some time to get a Lasting Power of Attorney registered. What can I do in the meantime to enable someone else to operate my bank account and pay my bills?

The Office of the Public Guardian is continuing to accept applications to register Lasting Powers of Attorney but their usual estimated timescale of eight to ten weeks is likely to be affected by the current situation.

Consequently, an alternative or interim measure if you need something quickly is to execute a General Power of Attorney to authorise someone to act as your Attorney to undertake day to day financial transactions for you. The General Power of Appointment only needs to be executed by you in the presence of a witness (not the Attorney) to be valid and does not need to be registered with the Court of Protection. However, the Power of Attorney would cease to have effect if you become incapable of managing your affairs. It should be seen as a stop-gap only.