How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
- Employee pensions contributions are often paid by way of salary sacrifice arrangements.
- Use of such arrangements may reduce the amount of wage an employer can claim under the Coronavirus Job Retention Scheme, as the reimbursement is calculated by reference to an employee’s actual pay as at 28 February 2020, hence post sacrifice pay.
- Using the Coronavirus Job Retention Scheme does not in itself bring a salary sacrifice arrangement to an end, but where an employer wishes to maximise the amount of an employee’s pay that will be covered by the CJRS, the employer and employee(s) concerned may agree to terminate the salary sacrifice arrangement as part of furlough. HMRC has recently announced that the Covid-19 pandemic will be considered a “life event” (i.e. one of the permitted reasons to break a salary sacrifice arrangement mid-term), if the employment contract is updated accordingly.
No. This bill relates to corporate insolvencies only. Should you require any advice as to personal insolvency situations, please contact our team.
If suppliers still wish to terminate the contract, they must contact the directors or the officeholder dealing with the insolvency process and obtain their approval to terminate the contract – which, of course, might not be given.
If the continued obligation under the contract to supply goods/services to the customer would place the supplier in financial hardship the supplier can apply to court for permission to terminate the contract. This will involve time and legal expense.
Yes, but as a last resort. In summary, the law requires employers:
- to assess the workplace risks posed to new or expectant mothers or their babies;
- to alter the employee’s working conditions or hours of work to avoid any significant risk to them;
- where it is not reasonable to alter working conditions or hours, or would not avoid the risk, to offer suitable alternative work on terms that are not “substantially less favourable”;
- where suitable alternative work is not available, or the employee reasonably refuses it, the employer should consider whether it is appropriate to suspend the employee on full pay.
As an occupier of premises, you owe a duty of care to your visitors to take reasonable care to see that the visitor will be reasonably safe in using your premises.
It is therefore essential that you are taking reasonable steps and strictly adhering to up-to-date Government advice in all aspects of your business to avoid any potential liability.
Failure to follow Government advice could leave you vulnerable to claims for compensation for pain and suffering should a visitor on your premises contract Covid-19.
However, each case will be fact-specific and it would be very difficult for a visitor to establish that they contracted Covid-19 specifically from those premises (as opposed to being exposed to the virus anywhere else).
If someone suggests that they are going to make a claim make sure that you report matters to your insurer or insurance broker immediately.