Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

What happens if I need to sign a new commercial lease in the future?

The outbreak is certainly going to have an impact on new lease negotiations.

Undoubtedly many transactions will be put on hold or indeed stop entirely. Where matters are ongoing, tenants may well look to strengthen rent suspension provision.

It is also possible that tenants and their representatives will also now seek to include termination rights for unseen events. In this regard, the concept of force majeure may start to appear more often in leases.

In both of the examples above, such attempts are not likely to be well received from landlords who will undoubtedly suggest that tenants ensure that their business interruption insurance policies are robust enough to protect the tenant in the event of any future pandemic events.

Another approach tenants might adopt going forwards in negotiations for a new lease (or indeed seeking to vary existing leases), is to move away from the traditional market rent model to a turnover rent arrangement. This will offer some protection going forward if trading conditions deteriorate, but again getting institutional landlords to agree such an approach may prove difficult.

What does “Force Majeure” mean?

Crucially the phrase “force majeure” has no specific meaning in English law. As a result, there is scope for complex legal argument, including as to whether the effects of the coronavirus outbreak can amount to force majeure in the first place. If the coronavirus crisis deepens, force majeure provisions could become relevant in the following ways:

  • suppliers to your business might seek to invoke force majeure
  • you may need to invoke force majeure under your own contracts

Each of these will need careful analysis of the relevant contract against the applicable factual background. Unfortunately, the position is unlikely to be clear cut.

What does the new Chief Coroner guidance cover?

This guidance from the Chief Coroner applies to reports of death and coroner investigations in England and Wales. It is to assist coroners in continuing to exercise their judicial decisions independently, in accordance with the law, and during the extraordinarily pressured events being faced at present.

VIDEO: SRA Standards and Regulations

Damien Charlton, Julie Huntingdon and Chris Hugill look at the SRA Standards and Regulations (STaRS) for solicitors which came into effect late 2019, and represented a whole new regulatory landscape for the legal profession. The enhanced reporting and transparency obligations have an important impact on in-house practice, so this webinar gives you the opportunity to reflect on how the new rules impact on in-house lawyers, in both your professional and personal lives.

This webinar is part of a series designed for in-house lawyers. If you would like to register to receive invitations to future events for in-house legal counsel, please email damien.charlton@wardhadaway.com.

How are the Courts applying the new guidance?

Overall it is our experience that the Courts are quickly adapting in the context of the Coronavirus epidemic and making pragmatic decisions. The Judges seem live to the difficulties currently been faced by practitioners dealing with litigation and they are applying the new guidance.

The Courts are also mindful of pressures on NHS frontline staff and are taking steps not to put additional pressures on them at this time, including in our experience vacating an imminent Trial.