Skip to content

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

Related FAQs

I hold a licence but can’t trade. Can I terminate it?

A licence to occupy premises is not an interest land and operates as a commercial contract between the parties that enter into it. Licences tend to be put in place to cover short periods and consequently they are generally a lot more flexible than commercial leasing arrangements. To that extent occupants under licences should review the contract to establish whether or not there are any provision allowing them to terminate on notice to the Licensor.

Occupants under licences that are granted for longer periods without the option to terminate may try to argue that the contract has frustrated because they are effectively unable to occupy.

Read more about this
What can I do as an employer if employees are known to be breaking the National Lockdown rules?

This will depend on the particular facts and the employee’s circumstances but an employee should co-operate with the employer so far as is necessary to enable compliance with any statutory duty or requirement relating to health and safety.

In addition, conduct outside of work can result in an employee’s dismissal if the conduct pertains to the employment relationship. If an employee breaches the lockdown rules and it affects their ability to work, such as it being no longer safe for them to attend work, or the reputation of the employer, these may be grounds for disciplinary action and subsequent dismissal.

Read more about this
If an employee refuses to wear a face mask at work, can I discipline or dismiss them?

In appropriate cases, disciplinary action and then dismissal may be fair if an employee refuses to wear a face covering in the workplace. For example, if this is in breach of the government guidance or if  employer has issued a reasonable management instruction to this effect due to an identified health and safety risk.

It is important that employers use a fair and reasonable procedure when deciding whether to discipline and/or dismiss an employee and that its actions does not unlawfully discriminate against employees who have legitimate reasons for not wearing masks, such as those individuals who have health conditions like asthma.

Read more about this
What is defined as a redundancy?

It is where the need for a role at a specific site, or the number of people performing a role, has ceased or diminished or the site closes down.

Read more about this
VIDEO: In conversation with cashflow.co.uk expert Chris Silverwood about CBILS

Partner at Ward Hadaway Adrian Ballam talks to corporate finance expert and CBILS specialist Chris Silverwood (CorpFin and cashflow.co.uk) to explore the practical ins, outs, dos and don’ts of CBILS applications, answering the questions:

  1. How are banks making their assessments of whether a business can afford a CBILS loan when for many they cannot accurately forecast their revenues for at least the next three months?
  2. What are the red flags that banks are looking for when assessing whether or not to grant a request for a CBILS loan?
  3. What cost mitigation measures should a business have already implemented prior to applying for a CBILS loan?
  4. What level of information should a business provide to support a CBILS application?
  5. What common mistakes are businesses making when applying for funding?
  6. What general tips do you have for businesses seeking CBILS funding?

Click read more to view the video.

Read more about this