Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

What do we need to do?

Privacy policy – You must make sure the relevant privacy policies deal with how you will process Covid-19 data. You should have an employee privacy policy and this may already deal with health data (if it doesn’t, it should). You might also need to look at privacy policies for customers, visitors and suppliers. This ensures that processing is lawful, fair and transparent.

Lawful processing conditions – You will need to consider which processing conditions you are relying on (remembering that you need both an Article 6 condition and an Article 9 condition – this is the part of the GDPR which deals with special category data). As a lot of the data you collect will be about employees, you can’t use consent so you will have to find another lawful reason under GDPR which allows you to process the data.

Appropriate policy document – When you are considering your Article 9 processing conditions, remember you must also have an “appropriate policy document” in place.

Processing record – Finally make sure your processing record is up to date with information on what data you collect and use.

Which products and services are affected?

Initially, the relaxation applied to supermarkets and food suppliers. This was subsequently widened to apply to other businesses, permitting them to collaborate where necessary to respond to the crisis in the interests of consumers.

What other factors may be considered?
  • Integration:
    • Is the individual held out as being employed by the business by having a company email address, uniform, how would they introduce themselves to customers?
  • Exclusivity:
    • Is the contractor restricted from working for other organisations without the consent of the end user client?
  • Length of engagement:
    • Is the contractor engaged to work on a specific project for a defined period? Or are they engaged for an indefinite period with no reference to a specific task or project?
  • Pay:
    • Are there regular fixed payments or is payment on completion of specific task or commission based? Is the contractor entitled to benefits or bonuses?
  • Facilities:
    • Does the contractor provide their own equipment and materials to provide the services?
  • Financial risk:
    • Is the contractor personally responsible for any loss arising from their work in performing the services? Will they have to rectify unsatisfactory work at their own time and expense? Will they have the opportunity to profit from the success of a project?
Flexible working

Many employees require flexible working now more than ever. That could be reduced hours, working from home, reduced days, etc. Be careful to act fairly when considering these requests as they can be a discrimination claim in the waiting.

A flexible working request is a request for a permanent change to the contract of employment however to encourage a greater take up during this difficult time, you can agree this on a temporary basis.

My business has a contract with a public sector body – what guidance has the Government issued about payment under contracts between public and private sector bodies?

The Cabinet Office has published a helpful Procurement Policy Note (“PPN”) on relief available to suppliers due to Covid-19 (available here). This can include making advance payments to suppliers, if necessary. The PPN sets out actions that public sector bodies should take (until at least 30 June 2020) to ensure continuity of service and to ensure that its suppliers can resume normal contract activity once able to.

The actions public sector bodies should be taking include:

  • Informing its suppliers (that they believe are at risk) that they will continue to be paid as normal until the end of June 2020 (even if service delivery is currently interrupted). Risk might include supply chains collapsing and/or significant financial implications for a supplier
  • If a contract involves a payment by results mechanism, basing payments on previous months (e.g. the average monthly payment over the previous 3 months), and
  • Ensuring that invoices submitted by suppliers are paid immediately to maintain cash flow in the supply chain and help to protect jobs.

If you are a supplier to a public sector body, you must act transparently and on an open-book basis, making cost data available to your public sector clients. You must also continue to pay your employees and subcontractors / suppliers. Suppliers to the public sector must not expect to make profits on any undelivered elements of a contract. The PPN makes clear that, should suppliers be found to be taking undue advantage, or failing to act transparently, a public sector body can take action to recover payments made to that supplier.

The PPN requires public sector bodies to urgently review their contract portfolios and take steps to support suppliers who they believe are “at risk”. However, no definition of “at risk” is given in the document.  We would suggest that if you are a supplier and you have yet to hear from a public sector client, you should seek to get in touch with them as soon as possible, particularly if you have concerns about your supply chain, staff retention and/or are experiencing financial difficulties currently. Given the requirement for transparency, you may be required to provide evidence, so it may be helpful to have any relevant documentation ready to send, if necessary, as this may help ensure a decision is made by the public sector client more promptly, particularly as the public sector body may have a number of contracts to consider.