How do I ensure my use of video conferencing calls complies with GDPR?
With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.
- Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
- If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
- Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
- You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
- Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
- Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.
The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.
On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.
On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.
Related FAQs
The new rules for wearing face masks/face coverings in the workplace introduced on 23 September 2020 are as follows:
- Staff in retail, including shops, supermarkets and shopping centres, will now have to wear a face covering
- Staff in hospitality will now have to wear a face covering
- Guidance stating that face coverings and visors should be worn in close contact services, such as hairdressers and beauticians, will now become law
- Staff working on public transport and taxi drivers will continue to be advised to wear face coverings
You can take off your mask if:
- You who need to eat, drink, or take medication
- A police officer or other official asks you to
The Government’s guidance says walk, cycle or drive to work and avoid public transport if you can. Businesses will need to support workers in adopting alternative travel methods to reduce exposure to the virus. You could consider staggering start and finish times for shifts to reduce commuting during peak hours, or support cycling with secure storage facilities and a drying room.
Hopefully, further guidance will provide additional clarification on this, but it is difficult to see how a charity whose operations have been significantly curtailed because of the Covid-19 restrictions, cannot furlough employees and access the scheme, in particular where they have several different income streams. For example if a charity’s retail or fundraising operations have been significantly curtailed due to the restrictions, then it would appear unfair for it not to able to rely on the furlough scheme to assist in the funding of the employment costs associated with this part of the charity.
However, it might be prudent, where there are services that are publicly funded and employees working within those services cannot undertake their normal work, to consider if they can do different roles to work on Covid-19 activities. If there is no such work available then the guidance does appear to allow the furloughing of employees and such organisations to access the scheme.
In our experience, the funding streams and work undertaken by the organisations that could fall into the third category identified above can be exceptionally diverse and we would strongly recommend that you take advice before making such decisions about furloughing employees.
With another lock-down in force in England, it has been confirmed that the courts will remain open. This is different to the first lockdown in March 2020, in which the majority of courts were closed and most face to face hearings did not take place. Hopefully, this new lock-down measure will ensure that cases are still being heard at a steady rate, and there should not be a backlog for your case to be dealt with.
Lord Chancellor Robert Buckland QC MP emphasised the importance of maintaining safety during the new measures: “Our courts & tribunals continue to be an essential public service, served by essential workers and meeting Covid-secure standards endorsed by public health officials. With the use of remote hearings wherever appropriate, this vital work can and should continue.”
A large sum of £110m has been spent in recent months to make courts safe and to ensure that trials should go ahead where necessary. As a result of the expenditure, hearings can now still take place both in person, whilst adhering to the rules, as well as remotely. Your case may be heard in court if it is deemed as being “necessary in the interest of justice”.
Precautionary measures, such as social distancing, will still be in place, with Judges and magistrates ensuring that this happens.
Lord Chief Justice, Lord Burnett of Maldon commented: “The next few weeks will present difficulties in all jurisdictions. But as before judges, magistrates, staff, the legal profession and others involved in the system will meet them and ensure that the administration of justice continues to function in the public interest.”
The Government has produced workplace guidance for employers, setting out 2 key messages for employers:
- Continue to make workplaces as safe as possible; and
- Encourage workers to heed any notifications to self-isolate and to support them while they are require to isolate
Government guidance can be accessed here: How it works (an overview) and Workplace guidance for employers.