How much data can I gather?
You also need to consider other aspects of data protection.
Be proportionate – only gather and use Covid-19 data where you need to.
Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.
Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).
Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.
Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.
Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.
Related FAQs
Yes. The updated government guidance has confirmed that office holders (including company directors), salaried members of Limited Liability Partnerships (LLPs) individuals working under umbrella companies (including agency workers) and individuals who are classified as ‘workers’ rather than employees can be furloughed but only to the extent that they are paid via PAYE. Therefore director’s fees can be claimed (subject to the cap) but dividends are excluded, as are bonuses and commission payments.
Those who are paid annual are now eligible to make a claim, subject to meeting the remaining requirements. This includes being notified to HMRC on an RTI submission on or before 19 March 2020 which relates to a payment of earnings in the 19/20 tax year.
The decision to furlough a director or office holder should be adopted as a formal decision of the company or LLP which should be minuted and notified in writing.
Company directors can only undertake work to fulfil a duty or other obligation arising from an Act of Parliament relating to the filing of company accounts or provision of other information relating to the administration of the director’s company while furloughed and they cannot carry out work that would generate revenue or perform services to or on behalf of their company. This also applies to salaried individuals who are directors of their own personal service company (PSC).
The guidance gives numerous examples of the types of performance adjustment which parties should consider. For example this includes:
- Varying deadlines (e.g. for performance or payment)
- Varying compensation (e.g. to recognise increased costs)
- Varying the nature of performance (e.g. allowing substitute goods, allowing pert delivery of services)
The guidance also encourages a reasonable approach to enforcement, which might encourage delaying issuing formal proceedings, increased use of mediation or providing more information to the other party than would be volunteered under normal circumstances.
Given the impact the Coronavirus is going to have upon the commercial property market, landlords will undoubtedly, as a matter of good commercial sense, will have to seriously entertain approaches from tenants seeking a rent suspension – notwithstanding there is no entitlement to the same under their lease.
Some landlords may decide it is better to waive or suspend rental payments over the short term rather than face their tenants going out of business and leaving them with an empty building in a flat or dead market.
A measure falling short of a rent suspension would be for the tenants to negotiate with their landlord’s monthly payments of rent rather than quarterly and for those monthly payments to be in payments arrears, rather than in advance.
We hope that all organisations will come out of lockdown successfully. However, the current economic crisis means that many organisations will face very difficult trading conditions.
Employment costs are one of, if not the, largest cost to your organisation. These costs will have an effect on your financial well-being – and many organisations are now considering how to reduce employment costs. That said, your workforce is also your most important asset and as we get back to business, you will need your workforce to run the organisation, produce your goods, deliver your services and deal with your customers.
As a result, many organisations are facing a very difficult situation – how to reduce or flex the cost of the workforce whilst also maintaining an ability to service customers. This difficulty is enhanced by the uncertainty of when the pandemic will be controlled and the threat of lockdowns end.
The Act should make it easier for residents to obtain relevant information. It includes an obligation for the Principal Accountable Person to prepare a strategy for promoting the participation of residents, including the information to be provided to them and consultations about relevant decisions. The strategy must be provided to residents, and there will be provision for residents to be able to request information and copies of documents from the Principal Accountable Person. The type of information and the form in which it is to be provided will be set out in secondary legislation in due course, but the explanatory notes anticipate that it will include:
- Full current and historical fire risk assessments•Planned maintenance and repair schedules
- The outcome of building safety inspection checks
- Information on how assets in the building are managed
- Details of preventative measures
- Details of fire protection measures and the fire strategy for the building
- Information on the maintenance of fire safety systems
- Structural assessments
- Planned and historical changes to the building