Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

My reserved matters application is due to be submitted, can I delay this?

The Business and Planning Act 2020 entered the statute books on 22 July 2020. Section 18 of the Act includes provisions for the extension of the date by which a reserved matters application must be submitted where the original date falls between 23 March 2020 and 31 December 2020. Where the original time limit for the submission of reserved matters is on or after 19 August 2020, the relevant conditions will be automatically read as requiring the reserved matters application to be submitted by 1 May 2021.

Where the original time limit for the submission of reserved matters is before 19 August 2020, an application will need to be made to the LPA for an Additional Environmental Approval (“AEA”), which the LPA must determine within 28 days otherwise the approval is deemed to be provided. The purpose of the AEA is to consider whether the environmental assessments carried out at the time of the original outline determination remain valid and up to date, and where that is not the case, the AEA will be refused. In such circumstances a new planning application will be required where an application is now out of time to comply with the original date for submission of reserved matters.

What type of agreements are we talking about?

To respond to the crisis businesses might need to exchange information to a greater extent than they would usually. They might need to discuss capacity and to coordinate supply chains (both upstream and downstream). They might need to purchase or sell jointly to ensure vital supplies are maintained. In general agreements or collaboration which:

  • Avoid a shortage, or ensure security, of supply
  • Ensure a fair distribution of scarce products
  • Continue essential services
  • Provide new services such as food delivery to vulnerable consumers
What are the new Procurement Policy Notes (PPN)?

The Government has produced and published three new Procurement Policy Notes as a direct result of the ever changing Covid-19 environment.

PPN 01/20: Responding to COVID-19

The purpose of PPN 01/20 is to ensure that contracting authorities are able to procure goods, services and works with extreme urgency, to allow them to respond to the pandemic efficiently.

This PPN provides guidance for the following circumstances:

  • Direct award due to extreme urgency (regulations 32(2)(c)) (click here to read our article regarding regulation 32)
  • Direct award due to an absence of competition or protection of exclusive rights
  • Call off from an existing framework agreement or dynamic purchasing system
  • Call for competition using a standard procedure with accelerated timescales
  • Extending or modifying a contract during its term

PPN 02/20: Supplier relief due to COVID-19

PPN 02/20 focuses predominantly on the supplier to assist in keeping supply chains open and ensuring that suppliers are kept financially sound during these unpredictable times.

This PPN provides guidance for the following circumstances:

  • Urgent reviews of contract portfolios and to update suppliers if they believe they are at risk
  • Put in place appropriate payment measure to support supplier cash flow
  • Where contract payments are based on ‘payment by results’ make payments based on previous invoices
  • Ask suppliers to act on a ‘open book’ basis and make cost data available to the contracting authority during this period
  • Ensure invoices submitted by suppliers are paid immediately on receipt

PPN 03/20: Use of Procurement Cards

The third guidance note PPN 03/20 relates to the use of procurement cards to increase efficiency and accelerate payment to suppliers.

This PPN provides the following advice and urges organisations to arrange with their procurement card provider to:

  • Increase a single transaction limit to £20,000 for key card holders
  • Raise monthly limits on spending with procurement cards to £100,000 for key card holders
  • Spend on procurement cards each month in excess of £100,000 should be permissible to meet business needs

Although the above advice has been provided, should these limits not be necessary, organisations should seek an appropriate transaction limit or monthly limit.

The PPN also advises that by 30 April 2020, in scope organisations should:

  • Ensure that a number of appropriate staff have the authority to use these cards
  • Open all relevant categories of spend to enable these cards to be used more widely
One of my employees has contracted Covid-19, should I report it under RIDDOR?

You must only make a report under RIDDOR (The Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013) when:

  • An unintended incident at work has led to someone’s possible or actual exposure to coronavirus. This must be reported as a dangerous occurrence
  • A worker has been diagnosed as having COVID 19 and there is reasonable evidence that it was caused by exposure at work. This must be reported as a case of disease
  • A worker dies as a result of occupational exposure to coronavirus.
Would you suggest using a different name for a MHFA, maybe a MH champion, to encompass the wider pro-active role?

This may be a good idea – whatever name they are given, it is essential that MHFAs are empowered to take a proactive approach to organisational mental health and that they have the bandwidth to be able to discharge their responsibilities.  The name should reflect the culture of the organisation, the key aspect is awareness and accessibility – identifying a name for your company that supports this is key.