Skip to content

How much data can I gather?

You also need to consider other aspects of data protection.

Be proportionate – only gather and use Covid-19 data where you need to.

Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.

Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to  make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).

Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.

Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.

Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.

Related FAQs

What happens if an employee refuses to attend work because they are afraid of being exposed to COVID-19 particularly the new more transmissible strain?

An employee can refuse to attend work but their refusal to do so will have to be based on a reasonable belief that their health and safety is in danger.  Whether or not their refusal is reasonable will take into consideration factors such as the employee’s own health and whether they are at a higher risk of becoming seriously ill if they contract Covid-19 and the steps their employer has out in place to mitigate the danger of contracting Covid-19 at work.

In such circumstances where the employee’s belief is deemed to be reasonable, they will be entitled to stay at home and receive full pay.

If an employee is subsequently dismissed for refusing to attend work in these circumstances, they may be able to bring a claim for unfair dismissal.

Does an employee who is furloughed lose his/her benefits under an EMI share option?

One of the key legislative requirements of EMI is that the employee satisfies the working time requirement, which is that they work at least 25 hours per week in the company or, if less, 75% of the employee’s total working time. If the working time requirement ceases to be met, then there is a “disqualifying event”. That means that the tax benefits of EMI ceases. It may also mean that the option lapses, but that depends on the specific terms of the option.

An employee who has been furloughed is by definition no longer working 25 hours/week and therefore on the face of it, there is a disqualifying event. However, the Government has tabled an amendment to the Finance Bill currently going through Parliament providing in effect that time not worked because an employee has been furloughed counts as working time, both for determining whether the working time requirement is met initially and whether there is a disqualifying event. Provided this amendment is enacted, this should address the issue.

What are the new Procurement Policy Notes (PPN)?

The Government has produced and published three new Procurement Policy Notes as a direct result of the ever changing Covid-19 environment.

PPN 01/20: Responding to COVID-19

The purpose of PPN 01/20 is to ensure that contracting authorities are able to procure goods, services and works with extreme urgency, to allow them to respond to the pandemic efficiently.

This PPN provides guidance for the following circumstances:

  • Direct award due to extreme urgency (regulations 32(2)(c)) (click here to read our article regarding regulation 32)
  • Direct award due to an absence of competition or protection of exclusive rights
  • Call off from an existing framework agreement or dynamic purchasing system
  • Call for competition using a standard procedure with accelerated timescales
  • Extending or modifying a contract during its term

PPN 02/20: Supplier relief due to COVID-19

PPN 02/20 focuses predominantly on the supplier to assist in keeping supply chains open and ensuring that suppliers are kept financially sound during these unpredictable times.

This PPN provides guidance for the following circumstances:

  • Urgent reviews of contract portfolios and to update suppliers if they believe they are at risk
  • Put in place appropriate payment measure to support supplier cash flow
  • Where contract payments are based on ‘payment by results’ make payments based on previous invoices
  • Ask suppliers to act on a ‘open book’ basis and make cost data available to the contracting authority during this period
  • Ensure invoices submitted by suppliers are paid immediately on receipt

PPN 03/20: Use of Procurement Cards

The third guidance note PPN 03/20 relates to the use of procurement cards to increase efficiency and accelerate payment to suppliers.

This PPN provides the following advice and urges organisations to arrange with their procurement card provider to:

  • Increase a single transaction limit to £20,000 for key card holders
  • Raise monthly limits on spending with procurement cards to £100,000 for key card holders
  • Spend on procurement cards each month in excess of £100,000 should be permissible to meet business needs

Although the above advice has been provided, should these limits not be necessary, organisations should seek an appropriate transaction limit or monthly limit.

The PPN also advises that by 30 April 2020, in scope organisations should:

  • Ensure that a number of appropriate staff have the authority to use these cards
  • Open all relevant categories of spend to enable these cards to be used more widely
Is it legally enforceable?

The guidance is non-statutory and is not binding on business. However, businesses should be aware that there might be reputational consequences if they do not follow the guidance; we have already seen in the context of taking advantage of furlough funding that not being in breach of the law is no protection against negative publicity. Further to the extent a contract expressly requires parties to act reasonably, it could be expected that this guidance is one of the factors a court would consider in determining what is reasonable.

What is Coronavirus Business Interruption Loan Scheme (CBILS)?

The Coronavirus Business Interruption Loan Scheme (“CBILS“) is open for applications to provide small businesses with a loan of up to £5m to assist with the Covid-19 outbreak. The Scheme is aimed at businesses who are experiencing lost or deferred revenues, and who otherwise would be denied support from lenders, to be supported by a Government backed guarantee. The Scheme will initially run for six months with the possibility to be extended where required, so businesses should only approach a lender under the Scheme as and when they require assistance.