Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

What is a small company?

The changes will not apply to end users who are a small company. If you meet two out the following 3 conditions, you will meet the small company definition and are therefore exempt from the changes to IR35:

  1. Annual turnover is no more than £10.2 million
  2. Balance sheet total is no more than £5.1 million
  3. No more than 50 employees

Companies will always be classified as small in their first financial year. Public companies will always be considered to be medium or large businesses and cannot fall under this exemption.

For a group company to be a small company its parent company must also meet the small company definition.

How is an establishment defined?

The definition of a relevant establishment is a question of fact for an Employment Tribunal. Guidance from case law says that ‘establishment’ should be interpreted very broadly (so as to avoid employers escaping the need to collectively consult), and may consist of:

  • A distinct entity
  • With a certain degree of permanence and stability
  • Which is assigned to perform one or more tasks
  • Which has a workforce, technical means and a certain organisational structure to allow it to do so

However, there is no need for it to have the following:

  • Legal, economic, financial, administrative or technological autonomy
  • A management which can independently effect collective redundancies
  • Geographical separation from the other units and facilities of the undertaking
How do I bring an employee with a visa off furlough?

Employees with visas should be treated consistently with the wider workforce. When their furlough leave ends, they should return to work and their pay should be reinstated. If you agree a pay cut or reduction in working hours, you need to ensure that sponsored workers are still earning above the minimum salary for their role and working in excess of the minimum number of hours (see above).

The flexible furlough scheme is now in place and can be used for employees who have previously been furloughed for a consecutive period of at least three weeks. The flexible furlough scheme remains in place until 31 October 2020.

What are the additional costs for the end user if the contractor is deemed employed?

The immediate impact is accounting for payroll purposes for the additional cost of 13.8% employers NIC’s and 0.5% apprenticeship levy on top of the payment to the contactor’s PSC.

Secondary NIC’s cannot be recovered from payments due to employees and the same applies under the new IR35 regime. However, new terms can be agreed with reduced level of fees to reflect this additional cost.

What are the new rules about wearing face masks in the workplace?

The new rules for wearing face masks/face coverings in the workplace introduced on 23 September 2020 are as follows:

  • Staff in retail, including shops, supermarkets and shopping centres, will now have to wear a face covering
  • Staff in hospitality will now have to wear a face covering
  • Guidance stating that face coverings and visors should be worn in close contact services, such as hairdressers and beauticians, will now become law
  • Staff working on public transport and taxi drivers will continue to be advised to wear face coverings

You can take off your mask if:

  • You who need to eat, drink, or take medication
  • A police officer or other official asks you to