How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
Many will have worked collaboratively with their suppliers and customers to deal with the immediate public health crisis. This will have meant offering flexibility as to contractual arrangements, whether in delivery dates, volumes of goods or services supplied, or even in the specification of what has been delivered.
If this is the case, it is important that businesses now do their legal housekeeping and make sure they have a proper record of what has been agreed. Unfortunately, our experience shows that many legal disputes arise out of amendments to contracts, typically where the parties to the contract each have a different view about what exactly they agreed to change.
We would therefore advise businesses to review any amendments that they might have agreed either verbally, by email, or otherwise, and consider whether they need to be captured in a more formal way which will make clear exactly what has been agreed to be varied, and (where appropriate) how long that variation will remain in force.
It’s also important to remember that some contracts contain provisions that set out specific requirements about how amendments are to be made. For example, they might require that amendments are made in writing (rather than verbally). These “No Oral Modification” clauses are commonly found in commercial contracts, and the courts have recently shown that they are willing to enforce them.
Failing to deal with amendments in accordance with contractual requirements could therefore have a serious impact on businesses as they recover from the disruption caused by the lockdown. If they end up in dispute with a customer or supplier, a business could find that the contract has not actually been amended in the way that they think – potentially leading to legal costs and liabilities at the worst possible time.
The government introduced The Working Time (Coronavirus) (Amendment) Regulations 2020 to amend the Working Time Regulations 1998 to allow for the change.
- Trusts should allow for telephone advice rather than face-to-face review from critical care when clinically appropriate.
- Hospitals should discuss the sharing of resources and the transfer of patients between units, including units in other hospitals, to ensure the best use of critical care within the NHS.
Please note, the above is intended to provide a summary of the key recommendations which emerge from this guidance. Access to the full guidance can be found here.
During these unusual times, we are all having to adapt to what has become the ‘new normal’ and implement changes in how we carry out civil cases. If you are to give evidence in a remote hearing, whether this is by Microsoft Teams, Skype for Business or the Cloud Video Platform, we have pulled together a quick and useful guide below on what would be expected by the courts:
Before the hearing
- Make sure that you have access to the video-conferencing software that will be needed for the hearing. We will tell our clients and their witnesses in advance which platform will be used. The courts have increasingly been using Skype for Business to conduct the hearings (but you may find other platforms being used)
- Test that your camera and microphone are working and it is clear to see/hear you.
- Dress appropriately, as if it was an in-person hearing, and use the same formalities.
- Ensure that the background which is visible on your screen is appropriate and allows for your face to be clearly seen. A ‘blur background’ option may also be available on your settings which you may prefer.
- Make sure that your mobile phone is on silent and you are in a location where there will be no/minimal distractions. You should be on your own in a room when giving evidence, however, as we have all experienced with working from home, sometimes interruptions such as children appearing cannot be avoided.
- Join the call ahead of the allocated time, in order to allow for any small technical difficulties.
During the hearing
- Have a copy of the hearing bundle to hand, so that you can follow the proceedings (this may be in hard copy or soft copy). You are not allowed any other notes or papers, whether hard copy or electronic, in front of you when giving evidence.
- Unless addressing the Judge or you have been directly asked a question, keep your microphone muted.
- When giving evidence, you must make sure both your camera and your microphone are switched on.
- Remote hearings can be difficult and if you do not understand or you do not hear a question properly, then do ask for the question to be repeated/re-framed.
- You should not move away from the screen without permission from the Judge. The Judge will allow time for breaks.
- Address the judiciary and other advocates the same way as you would if you were in a physical courtroom.
- It is permitted to drink water throughout the hearing, but mugs of tea and/or coffee are probably best avoided. It is also not permitted to eat food during the hearing.
- Don’t panic if someone walks into the room or the dog starts barking because there is a knock at the door. Judges are only too aware about what might happen. Communication is key and if the interruption has interfered with your train of thought or the evidence you are giving then do say so.
- Be aware that all evidence is recorded and that a transcript of all evidence can be obtained at a later date.
As their employer, you have an overriding duty to provide a safe system of work. The Trust would not be able to run a defence to say that an employee “waived their rights” and chose to continue to work. Provided the decision around restricting duties has been carefully thought out, a full risk assessment undertaken and the employee has been truly consulted about the impact on them, then the decision taken will be a reasonable management instruction. Failing to follow that reasonable management instruction could amount to a disciplinary offence.