Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

What should be included in genuinely self-employed contractor terms?

If you consider the factors used to determine status you can include the following terms that are more in line with a self-employed relationship:

  • The right to provide a substitute of the contractor’s choice in the event the individual is not able to perform the services;
  • The ability to work for other businesses as long as doing so will not affect the services to be provided by the contractor;
  • The contractor should have sufficient control over how, when and where (if possible) they provide the services;
  • A degree of financial risk can be included for unsatisfactory work or failing to complete a project or task

We have terms that cover all of these points that can be tailored to your needs. The consultancy agreement is included in our IR35 toolkit.

Who is eligible for CBILS?

To be eligible for CBILS, the British Business Bank has confirmed that businesses should be able to answer YES to the following points:

  • Your application must be for business purposes
  • You must be a UK-based SME with an annual turnover of up to £45m. This includes sole traders, freelances, body corporates, limited partnerships and limited liability partnerships. For sole traders to be eligible it is expected that sole traders will need to have a business account with its funders and not be operating via a personal account
  • Your business must generate more than 50% of its turnover from trading activity
  • Your CBILS-backed facility will be used to support primarily trading in the UK
  • You wish to borrow up to a maximum of £5m.

Businesses meeting these criteria from all sectors can apply save for Banks, Building Societies, Insurers and Reinsurers (but not insurance brokers), the public sector including state-funded primary and secondary schools, employer, professional, religious or political membership organisation or trade unions which are not eligible.

Your borrowing proposals must be considered viable by the relevant lender under normal circumstances aside from the Covid-19 outbreak, and the lender believes the provision of finance will enable the business to trade out of any short-to-medium term difficulty. Lending decisions are delegated to the accredited lenders and lenders will need further information to confirm eligibility.

The eligibility criteria for CBILS does not require lenders to take into account other forms of Government support that SME’s may already be benefiting from, most notably business rate relief.

We understand that ownership structure is not taken into account when confirming eligibility and that businesses back by a PE funder or a subsidiary of an overseas entity can be eligible if it meets the other criteria.

An update on eligibility – 3 April 2020

Previously, for facilities above £250,000, the lender must establish a lack or absence of security prior to businesses using the Scheme. The requirement for insufficient collateral has been removed allowing those SMEs who are considered to have sufficient collateral to access the Scheme. We would expect that where security is available, a lender will seek to take security over the relevant assets.

What allowances has the Government proposed for company meetings?

The Government’s Corporate Insolvency and Governance Act introduces amendments to the current rules for companies on holding meetings, to address the difficulties companies are facing due to the Covid-19 pandemic.

The new provisions apply to meetings held between 26 March 2020 and 30 September 2020 (referred to as the “Relevant Period”). Subsequent regulations by the Government can be used to shorten this period or extend by up to 3 months but not past 5 April 2021.

The provisions will have retrospective effect, so meetings that were held after 26 March 2020 that may not have met the usual legal requirements due to lockdown, will be validated under these new provisions. These provisions under the Act make amends to relevant legislation and override a company’s articles of association.

For general meetings and certain other meetings of companies, the Act states that:

  • The meeting need not be held in any particular place;
  • The meeting may be held, and any votes may be cast, by electronic means or other means;
  • The meeting may be held without anyone being in the same place
  • Persons attending the meeting no longer have the following rights: the right to attend in person, the right to participate in the meeting other than by voting, or the right to vote by particular means.

The aim of these changes is to facilitate virtual meetings, and remove the need for a physical venue.

Where a company was required to hold its AGM between 26 March and 30 September 2020, it can be held at any time before 30 September 2020.  The Secretary of State has the power to make regulations to further extend the deadline.

Will funding audits continue during the coronavirus pandemic?

Funding audits are being paused and no new audits will be commenced during the lockdown period.

What happens if that means a particular service might need to close?

Ultimately closing a service will be a decision that is taken at the highest level and that decision will depend on risk appetite.  Often these types of higher risk are mitigated by way of insurance but that still depends on an insurer being willing to accept that risk. This decision will depend on accepting a known risk and its consequences.