How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
All employers have a duty to prevent illegal working, and carrying out proper Right to Work checks are a fundamental part of this. In light of Covid-19, the Home Office has brought in some temporary measures for employers to use to carry out the requisite Right to Work checks. Failure to follow these could lead to enforcement action and penalties.
All three of the PPNs are effective immediately and apply to the following Contracting Authorities:
- Central Government Departments
- Executive agencies
- Non-departmental public bodies
- Local authorities
- NHS bodies
- The wider public sector
In regards to PPN03/20, those in scope organisations that do not currently use procurement cards are advised to immediately put in place arrangements using the relevant Crown Commercial Service Agreement (Lot 2 of RM3828 Payment Solutions).
The Government’s guidance says walk, cycle or drive to work and avoid public transport if you can. Businesses will need to support workers in adopting alternative travel methods to reduce exposure to the virus. You could consider staggering start and finish times for shifts to reduce commuting during peak hours, or support cycling with secure storage facilities and a drying room.
- The Pensions Regulator has published regularly-updated guidance for employers.
- It will take “a proportionate and risk-based approach towards enforcement decisions … with the aim of supporting both employers and savers”. In other words, the law remains the same, but the Regulator will show restraint in enforcement against breaches.
All employers in the UK are eligible to participate in the scheme. The purpose of the scheme is to allow employers to claim back employment costs if they have furloughed employees arising from the coronavirus crisis. Importantly this means the scheme is not limited to cases where the employee would otherwise have been made redundant.
Key points:
- Between 1 November 2020 – 30 June 2021, the government will reimburse employers for 80% of wage costs, up to a cap of £2,500 per month, with employers expected to contribute 10% of that 80% in July 2021 and 20% of that 80% in August and September 2021. Employers will still need to pay employer NICs and employer pension contributions (these cannot be claimed for).
- The scheme now also allows employees to return to work part time being on furlough for the remainder. See flexible furlough above for more information.
- The employer can agree to pay the employee more than it will be reimbursed but it cannot reclaim the additional amount or any other costs associated with the additional amount.
- The workers covered by the scheme are those who have been “furloughed” which is a leave of absence.
- Workers must be told about and agree to this change of status (see below).
- Employers have to continue to pay the furloughed workers and the Government will reimburse the employer.
- HMRC is administering the scheme and it has been extended until the end of September 2021
- Those who left employment and are re-employed and subsequently furloughed by agreement are eligible (please see the FAQ regarding redundancy and furlough above).
- Payments may be withheld if claims are based on inaccurate or dishonest information, or are found to be fraudulent. HMRC has put in place an online hotline for employees and the general public to report suspected fraudulent claims.
- The Government has made alternative help available for employers to continue to pay employees while the scheme is set up.