How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
The Coronavirus Statutory Sick Pay Rebate Scheme will repay employers the SSP paid to current or former employees and will be available from 26 May 2020. See here.
The scheme covers all types of employment contracts and employers will be eligible to claim if they:
- Are claiming for an employee who is eligible for sick pay due to coronavirus
- Had a payroll scheme that was created and started on or before 28 February 2020
- Had fewer than 250 employees on 28 February 2020
The repayment will cover up to 2 weeks starting from the first qualifying day of sickness, if an employee is unable to work because they either:
- have coronavirus (COVID-19) symptoms
- cannot work because they are self-isolating because someone they live with has symptoms
- are shielding and have a letter from the NHS or a GP telling them to stay at home for at least 12 weeks
- have been notified by the NHS or public health bodies that they’ve come into contact with someone with coronavirus
- they have been notified by the NHS to self-isolate before surgery
You can claim for periods of sickness starting on or after:
- 13 March 2020 – if your employee had coronavirus or the symptoms or is self-isolating because someone they live with has symptoms; or
- 16 April 2020 – if your employee was shielding because of coronavirus.
- 28 May 2020 – if your employee has been notified by the NHS or public health bodies that they’ve come into contact with someone with coronavirus
- 26 August 2020 – if your employee has been notified by the NHS to self-isolate before surgery
Employees do not have to give you a doctor’s fit note for you to make a claim. But you can ask them to give you either:
- an isolation note from NHS 111 – if they are self-isolating and cannot work because of coronavirus
- the NHS or GP letter telling them to stay at home for at least 12 weeks because they’re at high risk of severe illness from coronavirus
- the evidence from the NHS or public health body requiring them to self-isolate
You must keep the following records in relation to a claim you make under the scheme for three years:
- The reason for the employee’s absence
- Details of each period the employee could not work, including start and end dates
- Details of the SSP qualifying days when the employee could not work
- National insurance numbers for each employee you have paid SSP to
You’ll need to print or save your state aid declaration (from your claim summary) and keep this until 31 December 2024.
The application has to be made before the date on which the accounts should have been filed, so this process can’t be used if you are already late. If you don’t make the application before your filing deadline, then a fine will automatically be generated if your accounts are filed late. Whilst you could appeal against such a fine on the grounds that the delay was caused by coronavirus issues, this is likely to be a much more time consuming and uncertain process that applying in advance.
It does not appear that the process applies to Confirmation Statements or other returns.
Safeguarding issues are relatively uncommon, however, if they do occur, the normal safeguarding procedure of the organisation should be followed.
Changing to shift working may give employers the opportunity to change hours / pay whilst also focusing work when it is needed. Like the other provisions, this should be done fairly, either across the board or by selecting teams/individuals based on objective business reasons. Imposing without agreement would create significant risk, therefore would require fair selection and consultation.
The Government has produced and published three new Procurement Policy Notes as a direct result of the ever changing Covid-19 environment.
PPN 01/20: Responding to COVID-19
The purpose of PPN 01/20 is to ensure that contracting authorities are able to procure goods, services and works with extreme urgency, to allow them to respond to the pandemic efficiently.
This PPN provides guidance for the following circumstances:
- Direct award due to extreme urgency (regulations 32(2)(c)) (click here to read our article regarding regulation 32)
- Direct award due to an absence of competition or protection of exclusive rights
- Call off from an existing framework agreement or dynamic purchasing system
- Call for competition using a standard procedure with accelerated timescales
- Extending or modifying a contract during its term
PPN 02/20: Supplier relief due to COVID-19
PPN 02/20 focuses predominantly on the supplier to assist in keeping supply chains open and ensuring that suppliers are kept financially sound during these unpredictable times.
This PPN provides guidance for the following circumstances:
- Urgent reviews of contract portfolios and to update suppliers if they believe they are at risk
- Put in place appropriate payment measure to support supplier cash flow
- Where contract payments are based on ‘payment by results’ make payments based on previous invoices
- Ask suppliers to act on a ‘open book’ basis and make cost data available to the contracting authority during this period
- Ensure invoices submitted by suppliers are paid immediately on receipt
PPN 03/20: Use of Procurement Cards
The third guidance note PPN 03/20 relates to the use of procurement cards to increase efficiency and accelerate payment to suppliers.
This PPN provides the following advice and urges organisations to arrange with their procurement card provider to:
- Increase a single transaction limit to £20,000 for key card holders
- Raise monthly limits on spending with procurement cards to £100,000 for key card holders
- Spend on procurement cards each month in excess of £100,000 should be permissible to meet business needs
Although the above advice has been provided, should these limits not be necessary, organisations should seek an appropriate transaction limit or monthly limit.
The PPN also advises that by 30 April 2020, in scope organisations should:
- Ensure that a number of appropriate staff have the authority to use these cards
- Open all relevant categories of spend to enable these cards to be used more widely