Skip to content

How much data can I gather?

You also need to consider other aspects of data protection.

Be proportionate – only gather and use Covid-19 data where you need to.

Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.

Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to  make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).

Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.

Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.

Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.

Related FAQs

What rate of pay applies to an employee returning from statutory leave who is furloughed?

Statutory leave includes family related leave, sick leave or parental bereavement leave. Claims for furloughed individuals returning from statutory leave should be based on their salary, before tax, and not the pay they received while on statutory leave.

Similarly, claims for furloughed employees returning from a period of unpaid leave on sabbatical should be based on their pay they would have had on paid leave.

Do you have to collectively consult for the minimum period of time before you can issue notice?

These periods are often mistakenly referred to as minimum lengths of consultation (especially by Trade Unions). That is not correct. Consultation can commence, conclude and notices of dismissal be issued within the 30 and 45 day periods. The expiry of the notice would just have to be outside of those restricted periods.

What options do I have if I have staff with childcare responsibilities but their job cannot be done at home?

If it is not possible to find work for the employee to do at home, you do have the option of putting the employee on furlough.

I’m a doctor. Should I work outside my field of practice during the pandemic?

Whilst it is acknowledged that doctors may be working in unfamiliar circumstances or surroundings, or in clinical areas outside their usual practice. Doctors should consider the best course of action to take in these circumstances by utilising the following:

  • What is within their knowledge and skills
  • What support other members of the healthcare team could offer
  • What will be best for the individual patient given available options
  • The protection and needs of all patients they have a responsibility towards
  • Minimising the risk of transmission and protecting their health.
What are the key questions to ask ourselves as a business?

Some examples of the key questions to ask include:

  • Is there still a viable underlying business that is likely to continue beyond the current crisis?
  • What does the revised short to medium cash flow look like and will the company continue to be able to pay its liabilities?
  • Does the company have the support of all of its stakeholders – lenders, shareholders, customers, suppliers and banks – even though the business might be in breach of its own obligations?
  • What measures could (and should) the board put in place to protect creditors, including making sure that exposure to creditors (both collectively and individually) is not increased, assets are not sold at less than value and no creditor is treated more favourably than another?
  • Is there still a reasonable prospect of the business avoiding liquidation or administration?

The key question is always whether accepting the money is in the best interests of creditors as a whole bearing in mind that accepting Government support and continuing to trade might increase the company’s overall liabilities. Directors should be mindful that if the business fails, their decisions during this critical time may be scrutinised and it is therefore important that directors have up-to-date financial information and projections to form the basis of any decisions, take stock, get the right advice and document the decisions that are taken.