Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

How should contracting authorities work with PFI providers?
  • Working with PFI providers to get contingency plans up to date
  • If a PFI provider is struggling to achieve service delivery requirements due to Covid-19, then local arrangements should be put in place to:
    • maintain unitary charge payments
    • revise contract requirements/standards

moderating payment and performance regimes where appropriate.

  • In any event, you may wish to review and adjust your requirements to reflect the current situation. It is possible that some requirements can be relaxed, whereas others need to be tightened. For example, there may be an increased need for cleaning and maintenance in certain areas of your PFI premises or the layout of the premises and/or room uses may have temporarily changed. With staff illness and shortage likely to be an issue, you may also wish to consider if the resource can be moved from one area to another to help maintain essential services.
  • When putting local bespoke arrangements into place it is vital that:
    •  Contract requirements or performance standards are not relaxed to the point where health and safety are put at risk.
    • It is made clear that the arrangements are temporary and that matters will return to normal as soon as the Covid-19 emergency is over. Indeed the guidance note makes clear that if assets temporarily close they should be kept in such condition that they can be immediately up and running when this emergency is over. In such instances, likely a basic level of maintenance and security will therefore be required as a minimum.
How do you prevent MHFA from handling situations that are for qualified individuals such as their GP or EAP?

The MHFA training makes this clear, it should be made clear in the MHFA role specification and procedures and discussed during regular MHFA peer support and MHFA surgery sessions. It is important to ensure that where an Employee Assistance Programme is in place, all MHFAs have details of that scheme available so they are able to instantly share details of the scheme with those who require support. If in doubt due to serious concerns then using 999 or Samaritans is an option.

What rules has the European Commission introduced?

The Commission has provided guidance as to measures which Member States can introduce without notification. These include:

  • Measures which apply to all businesses within a Member State (for example the furloughing measures introduced by the UK Government)
  • Measures providing support direct to consumers
  • Measures which are already exempt from the notification requirement (discussed further below).

To respond to the crisis the European Commission has also issued a temporary framework to provide a basis for emergency aid to be notified for approval. The framework is initially in place until 31 December 2020. The Commission continues to keep this under review and has twice widened its scope to allow more types of aid to be notified. The type of measures covered include:

  • The provision of guarantees (including guarantees for 100% of loans)
  • The provision of loans at low interest rates, at zero interest rates or subordinated to senior debt
  • Measures to support liquidity needs or to alleviate difficulties caused by the current crisis
  • Measures to recapitalise businesses
  • Measures to assist sectors hit particularly hard by the current crisis (eg transport)
  • Measures targeted at COVID-19 such as research and development or production of products related to tackling the virus

The Commission has approved a UK Government “umbrella” notification to allow UK public authorities to adopt the measures permitted by the Commission framework. Therefore public authorities in the UK can use the Framework without notifying individual measures or schemes to the Commission.

What security will be required for CBILS?

At the discretion of the lender, the Scheme may be used for unsecured lending for facilities of £250,000 and under.

Lenders were required to demonstrate lending additionality (i.e. lending that without the Scheme, wouldn’t have otherwise taken place). The Scheme has been extended to those businesses who would have previously met requirements for a commercial facility and would not have been eligible for CBILS.  As a result  it is suggested that all viable small businesses affected by Covid-19, and not just those unable to secure regular commercial financing, will now be eligible should they need finance to keep operating.

Primary Residential Property cannot be taken as Security under the Scheme. If the lender can offer finance on normal commercial terms without the need to make use of the Scheme, they will do so.

Can we still use the furlough (coronavirus job retention scheme)?

Yes. For further guidance, please see our FAQs section on Furlough.