Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

What are the new rules about wearing face masks in the workplace?

The new rules for wearing face masks/face coverings in the workplace introduced on 23 September 2020 are as follows:

  • Staff in retail, including shops, supermarkets and shopping centres, will now have to wear a face covering
  • Staff in hospitality will now have to wear a face covering
  • Guidance stating that face coverings and visors should be worn in close contact services, such as hairdressers and beauticians, will now become law
  • Staff working on public transport and taxi drivers will continue to be advised to wear face coverings

You can take off your mask if:

  • You who need to eat, drink, or take medication
  • A police officer or other official asks you to
What should an employer do when an employee has been told to self-isolate under the coronavirus Test and Trace scheme?
  • Do not require them to work
  • Continue to communicate with and support them
  • Allow them to work from home, is there alternative work for them to do if they can’t do their work from home
  • Offer SSP or allow them to take holiday if they want to.
ONLINE EVENT: Contracts, managing supply chain issues and the role of directors

Hosted by NewcastleGateshead Initiative, Partners Damien Charlton and Jane Garvin discussed in this webinar contracts, managing supply chains and the role of directors, with  a particular focus on cancellation of events and businesses in the tourism and hospitality sector.

You can find a recording of the webinar from NGI here.

How should I approach negotiations with my landlord?

Given the impact the Coronavirus is going to have upon the commercial property market, landlords will undoubtedly, as a matter of good commercial sense, will have to seriously entertain approaches from tenants seeking a rent suspension – notwithstanding there is no entitlement to the same under their lease.

Some landlords may decide it is better to waive or suspend rental payments over the short term rather than face their tenants going out of business and leaving them with an empty building in a flat or dead market.

A measure falling short of a rent suspension would be for the tenants to negotiate with their landlord’s monthly payments of rent rather than quarterly and for those monthly payments to be in payments arrears, rather than in advance.

What can I do if someone refuses to wear PPE for cultural and/or religious observance reasons?

Again, the primary point must be that an open dialogue is held with that individual to understand their concerns and to properly consider the impact that not wearing PPE will have on their abilities to undertake their duties. Consideration must be given as to whether there are any parts of their duties that they can undertake and whether they can remain in their role. Engage with the individual to ensure that you understand their point of view. What other duties can they do if they cannot do fulfil all the duties of their role?