Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

If an employee refuses to come into work is their absence unauthorised and do I have to pay them?

This would depend on the reason as to why the employee is refusing to come into work. An unauthorised absence is where an employee fails to attend work and they do not have a statutory or contractual right, or their employer’s permission, to do so. An employer will not be obliged to pay employees their normal pay for periods of unauthorised absence.

There are some absences which may be viewed as authorised which would entitle the employee to their full pay. For instance, employees who believe that they are in serious and imminent danger by coming to work would be entitled to stay at home and receive pay if their belief is deemed reasonable.

An employer should always try to discuss any unauthorised absences with an employee. They may then consider whether to take disciplinary action against the employee.

What are the temporary adjustments to Right To Work checks?

To facilitate social distancing the Home Office has stated that as of 30 March 2020, the following are permitted:

  • The RTW check can now take place over video call.
  • Job applicants no longer have to send original documents but can send scanned copies or photos to the employer.
  • Where the job applicant cannot provide these documents, employers can use the Employer Checking Service and if they have the right to work, then the employer will receive a Positive Verification Notice which will provide the employer with a statutory excuse for 6 months.

These adjustments remain in place until the Home Office confirms otherwise.

 

Can you furlough a suspended employee?

Yes. You should be able to furlough a suspended employee subject to all other eligibility requirements however we recommend that you take advice on this before doing so.

What sort of issues are likely to have arisen?

The Coronavirus pandemic will have impacted businesses in many different ways, but some of the most likely impacts that could have a legal implication are as follows:

  • Services were not performed in accordance with contract during the period of disruption. This could be a reduction in volume of services performed, a suspension of services, or performance in a way that does not comply with contractual KPIs
  • Late delivery or non-delivery of goods because of factory closures, or disruption in the supply chain
  • Changes being agreed between parties to contracts to deal with the consequences of the Covid-19 outbreak
How much notice do I need to give people to return to work?

There is no minimum period of notice you are required to give employees of their return, but from a good HR practice point of view you should be speaking to your staff and letting them know what the plan is; giving people a reasonable amount of notice of return will allow them to prepare both practically and psychologically.