Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

If an employee refuses to come into work is their absence unauthorised and do I have to pay them?

This would depend on the reason as to why the employee is refusing to come into work. An unauthorised absence is where an employee fails to attend work and they do not have a statutory or contractual right, or their employer’s permission, to do so. An employer will not be obliged to pay employees their normal pay for periods of unauthorised absence.

There are some absences which may be viewed as authorised which would entitle the employee to their full pay. For instance, employees who believe that they are in serious and imminent danger by coming to work would be entitled to stay at home and receive pay if their belief is deemed reasonable.

An employer should always try to discuss any unauthorised absences with an employee. They may then consider whether to take disciplinary action against the employee.

Can I be investigated or prosecuted by HSE if one of my workers contracts Covid-19?

The reality of these unprecedented times is that enforcement of health and safety legislation by the HSE (particularly through the criminal courts) in relation to Covid-19 is an extremely unlikely outcome.

What does information and consultation involve?

There are two stages:

  • Stage 1 – The provision of written information to the representatives.
  • Stage 2 – Consultation on the proposed redundancies “with a view to reaching agreement” about certain matters

Stage 1: Provision of information

The first stage in the collective consultation process is to provide the representatives with written information including details of the proposed redundancies (often called a section 188 letter). This information must be given to the appropriate representatives and the time limit before dismissals can take effect does not start to run until they have received it. It is this information which ‘starts the clock’.

It is possible that there will be changes to the proposals during the consultation process: indeed that is part of the reason for the process. The employer’s obligation is not just to provide the appropriate representatives with the relevant information at the start of the process. It is under a continuing obligation to provide them with information in writing about any developments during the consultation process (although later changes do not ‘restart the clock’ before dismissals can take effect).

Stage 2: Consultation on the proposed redundancies “with a view to reaching agreement” about certain matters

The consultation process must include consultation “with a view to reaching agreement with the appropriate representatives” on ways of:

  • Avoiding the dismissals
  • Reducing the number of employees to be dismissed
  • Mitigating the consequences of the dismissals
Who decides on carrying-over holiday entitlement?

The Regulations do not require any prior agreement between an employer and employee that it was not reasonably practicable for holiday to be taken for it to be carried over.

However, if an employee requests holiday then an employer must have ‘good reason’ for refusing it due to coronavirus. The term ‘good reason’ is not defined so the Government will expect employers, employees and (if necessary on any dispute) the Courts to apply common sense.

The Regulations are not confined to key workers so could, in principle, be used by employers for a wider range of employees.

The Government guidance suggests that the following factors should be taken into account when considering whether it was reasonably practicable to take the leave in the relevant year:

  • Whether the business has faced a significant increase in demand due to COVID-19 that would reasonably require the worker to continue to be at work and cannot be met through alternative practical measures.
  • The extent to which the business’ workforce is disrupted by COVID-19 and the practical options available to the business to provide temporary cover of essential activities.
  • The health of the worker and how soon they need to take a period of rest and relaxation.
  • The length of time remaining in the worker’s leave year.
  • The extent to which the worker taking leave would impact on wider society’s response to, and recovery from, the effects of COVID-19.
  • The ability of the remainder of the available workforce to provide cover for the worker going on leave.
What is the guidance in relation to the Mental Capacity Act 2005 and Deprivation of Liberty Safeguards during the Covid-19 pandemic?

The Department of Health & Social Care has published guidance for hospitals, care homes and supervisory bodies on the Mental Capacity Act 2005 (MCA) and Deprivation of Liberty Safeguards (DoLS) during the coronavirus pandemic.

In many scenarios created or affected by the pandemic, decision makers in hospitals and care homes will need to decide:

  • if new arrangements constitute a ‘deprivation of liberty’ (most will not), and
  • if the new measures do amount to a deprivation of liberty, whether a new DoLS authorisation will be required (in most cases it will not be).

If a new authorisation is required, decision makers should follow their usual DoLS processes, including those for urgent authorisations.

A summary of the key points to be taken from the guidance is outlined below:

Use of the MCA and DoLS due to Covid-19

  • During the pandemic, the principles of the MCA and the safeguards provided by DoLS still apply.
  • It may be necessary to change the usual care and treatment arrangements, for example to provide treatment for people with Covid-19, to move them to a new hospital or care home to better utilise resources or to protect them from becoming infected.
  • All decision makers are responsible for implementing the emergency Government health advice  and any decision made under the MCA must be made in relation to a particular individual, it cannot be made in relation to groups of people.

Best interest decisions

  • In many cases, a best interests decision will be sufficient to provide the necessary care and treatment for a person who lacks the capacity to consent to the care and/or treatment arrangements during this emergency period.
  • If an individual has made a valid and applicable advance decision to refuse the treatment in question, then the relevant treatment, even for Covid-19, cannot be provided.

Delivering life-saving treatment

  • Where life-saving treatment is being provided in care homes or hospitals, including for the treatment of Covid-19, then the person will not be deprived of liberty as long as the treatment is the same as would normally be given to any person without a mental disorder.
  • The DoLS will therefore not apply to the vast majority of patients who need life-saving treatment who lack the mental capacity to consent to that treatment, including treatment to prevent the deterioration of a person with Covid-19.

The full guidance can be found here.