How much data can I gather?
You also need to consider other aspects of data protection.
Be proportionate – only gather and use Covid-19 data where you need to.
Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.
Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).
Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.
Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.
Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.
Related FAQs
It is worth pointing out that, despite all the guidance, survey results and other advice about managing Covid-19 H&S risk in the workplace, the law has not been changed. None of the guidance is codified by regulation/legislation, which means that you are managing this risk in the context of existing H&S law.
In very simple terms, HASWA74 requires employers to take “all reasonably practicable steps” to ensure the health and safety of its employees (and anyone else affected by your business).
“Reasonably practicable” means to balance risk reduction against the time, money and effort required. If measures are grossly disproportionate, you wouldn’t be expected to take them, but there is a strong presumption in favour of taking any steps which will protect workers.
As part of managing the health and safety of your people, you must control the risks in your workplaces. To do this, look for what might cause harm to people while they work and decide whether you are taking reasonable steps to prevent that harm. This related duty under MHSWR is to ensure you undertake a “suitable and sufficient assessment of risks.”
The recommendation is every 3 years, however it is recommended that MHFAs receive regular ongoing training and support.
This is unlikely. Frustration is a doctrine rarely used as a way of getting out of leases. It operates to bring a lease to an early end because of the effect of a supervening event. It is then not a concept readily applicable to a situation where one party is looking to get out of a lease. To be able to argue the doctrine of frustration, you must be able to demonstrate that something unforeseeable has happened that makes it impossible to fulfil the lease and unjust to hold a party to its obligations.
This is not something that can be demonstrated easily.
There was a case in the High Court last year when the doctrine of frustration was looked at in a case involving the European Medical Agency.
The court found that Brexit did not frustrate EMA’s lease. EMA was granted leave to appeal that decision to the Court of Appeal, but unfortunately, the parties settled out of court so the arguments were not tested in the higher court.
Another reason why frustration is likely to fail is an argument that, whilst the current lockdown may force closures to businesses and whilst such closures maybe for a lengthy period, such closures will only be temporary.
As a result of the CJRS being extended, the Job Retention Bonus will no longer be paid in February 2021.
Interestingly, there is currently no ‘single’ technology to be used by the judiciary within the protocol. The court and parties must choose from a selection of possible IT platforms or audio/telephone hearing (further details available in the guidance e.g. Skype for Business, Microsoft Teams, Zoom etc.) The particular platform must be agreed at the outset of each case and then specified in the case management order. The guidance issued also sets out the basic principles which apply when conducting remote hearings.