Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

Which properties should I prioritise?

Some organisations are prioritising properties, known to be higher risk, such as properties with open flues, or near to the certificate expiry date.

Vulnerable staff and tenants need protection, safe working practices need to be established, and communicated. Organisations should bring forward servicing for people known to be vulnerable – but bearing in mind the guidance as to preserving the annual test date.

What routes of challenge are available to an insurer's rejection of my business interruption claim?

Many policies will only provide business interruption cover if it arises from property damage. The FCA has acknowledged that insurers are entitled to reject claims in relation to such policies, notwithstanding the success of the FCA’s test case in the Supreme Court, and which was generally favourable to policyholders [Insert a link here to our update on the test case]. In other cases the policy wording will be less clear and businesses may legitimately feel that their insurer is wrongly withholding payment.

One route of challenge to an insurer’s decision is via one of the well-publicised class actions. Another route of challenge is by a complaint to the Financial Ombudsman Service (FOS). This service is open to consumers and small and medium-sized businesses, ‘micro-enterprises’, charities and trusts. The service will be an attractive option for many businesses, as it is free and relatively quick (although it remains to be seen how the service keeps up with an increase in demand as a result of the pandemic). You will need to have complained to your insurer before bringing a complaint with the FOS.

Further details can be found here.

What options do I have if I have staff with childcare responsibilities but their job cannot be done at home?

If it is not possible to find work for the employee to do at home, you do have the option of putting the employee on furlough.

Can an employee in a public facing role refuse to interact with a customer who is not wearing a face mask?

In some circumstances, visitors and customers are required to wear face coverings, such as those travelling on public transport, shoppers and museum visitors. The government guidance states that:

  • businesses must remind people to wear face coverings where mandated; and
  • premises where face coverings are required should take reasonable steps to promote compliance with the law.

As part of their duty of care to employees and to uphold a relationship of mutual trust and confidence, employers should consider how employees can ensure that visitors and customers comply with the rules and provide their staff with guidance. They must also seek ways to protect their employees both from the risks of those customers not wearing face masks and potential abuse from customers or visitors who decline to wear a face covering. This may include having signs in place requiring customers and visitors to wear a mask and allowing staff to refuse to serve customers if they do not follow the rules.

However, it is ultimately the responsibility of the police, security and public transport officials to remove customers from premises where they are not complying with the rules on face coverings.

The police and Transport for London have been given greater powers by the government to take measures if the public do not comply with the law relating to face coverings without a valid exemption, such as refusing to wear a face covering. This includes issuing fines which have now been increased to £200 for the first offence (and £100 if paid within 14 days). Transport operators can also deny access to their public transport services if a passenger is not wearing a face covering, or direct them to wear one or leave a service.

How do I remain compliant and cover any risk?

Data on properties, and people, has never been more important.

Given that compliance is at risk here, such a decision must be made by the Board to ensure good governance. Board approval should be sought and recorded for the approach the organisation is taking.

It is essential that you continue to record your data on compliance and report to your board at all times, and that there is a clear audit trail for issues with access, and if appropriate to the Regulator. Access issues as a result of self-isolation should be readily identifiable.

Operatives need to be provided with the tools to operate in as safe a way as possible:

  • Checklist of questions to ascertain occupant’s current health
  • Protective equipment (masks, gloves, over clothing)

The Gas Safe website is a useful resource for updates: https://www.gassaferegister.co.uk/help-and-advice/covid-19-advice-and-guidance/