How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
The Coronavirus pandemic will have impacted businesses in many different ways, but some of the most likely impacts that could have a legal implication are as follows:
- Services were not performed in accordance with contract during the period of disruption. This could be a reduction in volume of services performed, a suspension of services, or performance in a way that does not comply with contractual KPIs
- Late delivery or non-delivery of goods because of factory closures, or disruption in the supply chain
- Changes being agreed between parties to contracts to deal with the consequences of the Covid-19 outbreak
The financial implications of having to repay all deposits and advance payments could be very serious for some businesses. As an alternative to a refund, many are offering customers the opportunity to re-book at a later date, or a voucher that can be redeemed against a subsequent booking.
The CMA’s view on this practice is that consumers can in many situations be offered alternatives of this type, but they should not be “misled or pressured” into accepting this. Their view is that a refund should be an option that is just as clearly and easily available. The CMA also points out that any restrictions that apply to credits, vouchers, re-booking or re-scheduling, such as the period in which credits must be used or services re-booked, must also be fair and made clear to consumers.
The full CMA guidance re “The Coronavirus (Covid-19) pandemic, consumer contracts, cancellation and refunds” can be found here.
As an occupier of premises, you owe a duty of care to your visitors to take reasonable care to see that the visitor will be reasonably safe in using your premises.
It is therefore essential that you are taking reasonable steps and strictly adhering to up-to-date Government advice in all aspects of your business to avoid any potential liability.
Failure to follow Government advice could leave you vulnerable to claims for compensation for pain and suffering should a visitor on your premises contract Covid-19.
However, each case will be fact-specific and it would be very difficult for a visitor to establish that they contracted Covid-19 specifically from those premises (as opposed to being exposed to the virus anywhere else).
If someone suggests that they are going to make a claim make sure that you report matters to your insurer or insurance broker immediately.
Homeworking can cause work-related stress and affect people’s mental health and being away from managers and colleagues could make it difficult to get proper supervision and support.
Encourage your employees to keep in touch. Put procedures in place so you can keep in direct contact with home workers and can recognise signs of stress as early as possible. Use group chat and video chat tools imaginatively.
Have an emergency point of contact and share this so people know how to get help if they need it.
People are much more anxious than usual and may be less productive as a result – recognise this and try to be patient.
There is less guidance in respect of whether an employee can refuse to go into the workplace as a result of health and safety concerns about their commute. An employer’s duties to ensure the health, safety and welfare of its employees only extend to the workplace or where an employee is acting in the course of their employment. This does not include the risks of travelling to and from work by public transport.
As there are various ways in which an employee can travel to work, it will be difficult for them to legitimately refuse to come to work due to their commute. Employers should discuss any concerns with the employee and seek to find an appropriate resolution. The government has published guidance on safer travel for passengers during the Covid-19 pandemic and employers should encourage flexibility as far as possible, such as allowing employees to travel at off-peak times and staggering workers’ hours.