How much data can I gather?
You also need to consider other aspects of data protection.
Be proportionate – only gather and use Covid-19 data where you need to.
Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.
Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).
Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.
Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.
Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.
Related FAQs
The Thriving at Work Report and the recent NICE Workplace Mental Health Guidelines provide a good baseline for what all organisations should be doing on workplace mental health – this includes some guidance on training. There does need to be a plan in place and we recommend taking a holistic view of the integration of mental health first aiders into a business – ie it should be one component in a strategy that also comprises training for line managers, awareness training and education for all staff, peer support, and a documented framework for support and signposting. It is also worth ensuring you have senior manager sponsorship, strong links with Occupational Health if available and also raising awareness via any works councils or employee forums helps ensure there is buy in at all levels.
Read more about thisAs mentioned earlier, if an agency is involved you must send them a copy of the status determination statement for each contractor, and they will also have the right to dispute the outcome.
If the agency pays the contractor, they will be responsible for the operation of PAYE and NIC’s deductions and any apprenticeship levy. The agency may try to recover these costs from the end user client.
If workers are supplied by an agency or umbrella company and are already treated as employees by the agency, they will remain unaffected by IR35.
Read more about thisCharities can also take advantage of the existing measures the Government has already put in place including deferring their VAT bills, paying no business rates for their shops next year and furloughing staff where possible with the Government paying 80% of their wages under the Coronavirus Job Retention Scheme – see our People and Employment FAQ’s and our Premise and Property FAQ’s.
Read more about thisYes, but only for work purposes and where it is unreasonable to do so from home. Work colleagues cannot meet to socialise.
Read more about thisPartner at Ward Hadaway Adrian Ballam talks to corporate finance expert and CBILS specialist Chris Silverwood (CorpFin and cashflow.co.uk) to explore the practical ins, outs, dos and don’ts of CBILS applications, answering the questions:
- How are banks making their assessments of whether a business can afford a CBILS loan when for many they cannot accurately forecast their revenues for at least the next three months?
- What are the red flags that banks are looking for when assessing whether or not to grant a request for a CBILS loan?
- What cost mitigation measures should a business have already implemented prior to applying for a CBILS loan?
- What level of information should a business provide to support a CBILS application?
- What common mistakes are businesses making when applying for funding?
- What general tips do you have for businesses seeking CBILS funding?
Click read more to view the video.
Read more about this