Skip to content

How much data can I gather?

You also need to consider other aspects of data protection.

Be proportionate – only gather and use Covid-19 data where you need to.

Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.

Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to  make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).

Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.

Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.

Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.

Related FAQs

What should be included in genuinely self-employed contractor terms?

If you consider the factors used to determine status you can include the following terms that are more in line with a self-employed relationship:

  • The right to provide a substitute of the contractor’s choice in the event the individual is not able to perform the services;
  • The ability to work for other businesses as long as doing so will not affect the services to be provided by the contractor;
  • The contractor should have sufficient control over how, when and where (if possible) they provide the services;
  • A degree of financial risk can be included for unsatisfactory work or failing to complete a project or task

We have terms that cover all of these points that can be tailored to your needs. The consultancy agreement is included in our IR35 toolkit.

Freedom to Speak up – a reminder

Has there ever been a more important time for all staff to feel that they are able to raise concerns about their working environment?

It is a pertinent time to remind all staff that they should be able to raise concerns without the fear of repercussions. It is a good time to be reviewing and re-issuing your Freedom to Speak up/Whistleblowing policy to all. Likewise it is a good time to remind all staff that they should not treat others unfairly or detrimentally for raising health and safety concerns.

Both subjecting someone to a detriment because they have blown the whistle or raised health and safety concerns (and dismissing someone for the same) is unlawful.

What is the guidance for doctors working during the pandemic?

The General Medical Council (GMC) have published guidance online for doctors during this time of uncertainty.

 

Alongside this, their website displays guidance for temporary registration to approximately 15,000 doctors, who left the register or gave up their licence to practise in the last three years.

 

These clinicians have been contacted to assist with the growing pandemic, outlining the process they would follow and informing them of their right to opt-out. The Secretary of State for Health can ask the GMC to grant such registration under Section 18a of the Medical Act 1983, in an emergency.

Are Public Bodies able to continue to pay contractors (and their supply chains) at risk as a result of Covid-19?

Yes: The Cabinet Office has published a number of Procurement Policy Notes to provide instructions to Public Bodies to enable payments to continue to be made to at risk suppliers (and their supply chains) who have been affected by Covid-19. Copies of this guidance can be obtained from the Government website at: https://www.gov.uk/government/publications/procurement-policy-note-0220-supplier-relief-due-to-covid-19

Who should come back to work and when?

This is critical. The guidance remains clear – IF YOU CAN WORK FROM HOME YOU SHOULD CONTINUE TO DO SO. Bringing people back into work unnecessarily is a big mistake.

Think about how many employees should physically return to the workplace – the fewer the people on site, the lower the risk AND the less pressure on public transport.

Employers will need to be very careful to recognise workers in vulnerable groups or who develop or live in a household with someone who develops symptoms of Covid-19 – again, look at government guidelines. You should understand that this will mean a higher number of staff absences and consider how this might be managed.

Look to keep smaller teams of workers together, minimise physical meetings and if you MUST have them, keep them short and under 15 minutes. Be imaginative – use online platforms like Teams and Zoom wherever you can.