How much data can I gather?
You also need to consider other aspects of data protection.
Be proportionate – only gather and use Covid-19 data where you need to.
Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.
Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).
Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.
Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.
Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.
Related FAQs
Some examples of the key questions to ask include:
- Is there still a viable underlying business that is likely to continue beyond the current crisis?
- What does the revised short to medium cash flow look like and will the company continue to be able to pay its liabilities?
- Does the company have the support of all of its stakeholders – lenders, shareholders, customers, suppliers and banks – even though the business might be in breach of its own obligations?
- What measures could (and should) the board put in place to protect creditors, including making sure that exposure to creditors (both collectively and individually) is not increased, assets are not sold at less than value and no creditor is treated more favourably than another?
- Is there still a reasonable prospect of the business avoiding liquidation or administration?
The key question is always whether accepting the money is in the best interests of creditors as a whole bearing in mind that accepting Government support and continuing to trade might increase the company’s overall liabilities. Directors should be mindful that if the business fails, their decisions during this critical time may be scrutinised and it is therefore important that directors have up-to-date financial information and projections to form the basis of any decisions, take stock, get the right advice and document the decisions that are taken.
Put simply, if it is a requirement of a particular role that PPE is worn, then this should be provided to the employee. If an employer dismissed an employee for refusal to carry out their role due to lack of PPE then this is likely to be an automatically unfair health and safety dismissal.
Furthermore, anyone who is subject to a detriment as a result of raising a health and safety concern, e.g. someone in this situation who refuses to work due to lack of PPE and is sent home without pay, will also have a potentially valid claim in the Employment Tribunal for that detriment, even if they are not dismissed.
CMA guidance suggests that it will not take enforcement action in respect of agreements which:
- Are appropriate and necessary to avoid a shortage, or ensure security, of supply
- Are clearly in the public interest
- Contribute to the benefit or wellbeing of consumers
- Deal with critical issues that arise as a result of the Covid-19 pandemic
- Last no longer than is necessary to deal with these critical issues
It is possible to review working arrangements for contractors before the new rules come into effect. This will require immediate action.
You could consider terminating current contracts and entering into new terms that reflect working arrangements for a self-employment arrangement.
Another possibility is encouraging contractors to abandon the PSC model and provide services under a compliant umbrella company.
In the event of a determination of employed status you should seek to enter new terms that at the very least reflect the new tax arrangements .
The guidance asks parties to act responsibly and fairly in performing and enforcing contracts. They are encouraged to act in a spirit of cooperation to achieve practical, just and equitable outcomes. In essence, rather than sticking strictly to the contract as agreed, they are encouraged to give each other leeway to deliver performance differently than they are required to do under the contract.