How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
If a tenant continues to refuse to take heed of the government’s social-distancing guidelines, for example by inviting large groups of people who do not reside there to their property, it can constitute a nuisance. One housing association successfully applied for an injunction. The injunction ordered by the Court stipulated that no persons, other than the children of the tenant, are to attend the property until the current social-distancing restrictions are lifted by the government.
A representative of the housing association highlighted the need for the current guidelines to be followed and the need for housing providers to ensure that all residents living in their communities are kept safe during this time of ‘unprecedented risk’.
This case demonstrates that flouting of the current restrictions is likely to be considered anti-social in the eyes of the courts – a point which all housing providers should bear in mind during this period. Further, it highlights the availability of an alternative remedy to the issuing of possession proceedings (in light of the government’s moratorium on evictions) to deal with anti-social behaviour during the next three months, Covid-19 related or not.
The first point to note is that it is the position as at 14 February 2022 which is relevant, as whether or not a lease is a ‘qualifying lease’ for the purposes of recovering costs under the Building Safety Act was effectively frozen at that time.
If a leaseholder owned more than three properties in the UK (and the property in question was not their principal home) at that time, then the lease will not be a qualifying lease. The protections under the Act which prevent or restrict the landlord’s ability to recover the cost of remedial works through the service charge will not therefore apply to that lease (save potentially for the provision that costs cannot be recovered where the landlord is responsible for the defects, which does not expressly refer to qualifying leases).
The lack of a searchable database to assess how many properties a leaseholder has in the UK is however one of the difficulties to be resolved in this regard, as there is currently no way of searching the Land Registry to obtain a list of properties owned by one individual. The guidance appears to rely on the leaseholder completing the leaseholder deed of certificate being open and honest in this regard, and that deed of certificate being passed onto subsequent owners. Making false representations or failing to disclose required information in the deed of certificate may be a criminal offence, although reliance on this to discourage mis-reporting is clearly less satisfactory than having a searchable register.
The basics of health and safety law requires that employers take “all reasonably practicable steps” to ensure workers’ safety and that a suitable and sufficient assessment of risk is undertaken. It is the individual assessment of Covid-19 risk in each workplace that will be central. Employers will be required to conduct a robust risk assessment and then, following the hierarchy of controls, put robust processes and safeguards in place to address those risks.
UK government guidance and HSE advice is continually evolving, which in practice means that any risk assessment will need to be reviewed very regularly as that guidance develops. There is flexibility for individual businesses within the overall government framework and there will need to be a process of evaluation to ensure that the measures in place continue to meet the requirements.
The starting point of avoid, eliminate and control means looking at individuals continuing to work from home where possible (the fewer the number of people back in the workplace the lower the risk), and if not look at risk management, which leads to administrative controls – i.e. changing work practices before ending up at PPE. PPE is generally seen as control of last resort but in practice – facemasks, disposable gloves and constant prompts to wash hands for example.
In terms of changing working practices, employers should be thinking about:
- the workspace and how this is laid layout
- how do we make sure it is kept clean and hygienic
- how do we keep people apart
- how can we use toilets, canteens or other shared spaces/facilities safely
- how do we promote and enable higher levels of workplace hygiene
- if we are going to rely on PPE – can we get it, and is it suitable
- what about limiting customer interactions
- will there be enough first aiders on site
- can we manage fire safety, deliveries etc
- what about higher risk workers
- should work tools and equipment be allocated on an individual basis to employees.
These decisions need to be recorded and clearly communicated to staff members.
Suspension should always be a last resort and not a knee jerk reaction. We would not advise suspension unless a the above steps around the risk assessment have been undertaken. Depending on your local policies, suspension could then be an option on the basis that their health and safety and the health and safety of others are put at risk by their actions.
Companies House guidance on the impact of coronavirus on their services can be found at: https://www.gov.uk/guidance/coronavirus-guidance-for-companies-house-customers-employees-and-suppliers
This flexibility offered by Companies House could be a useful short-term help to businesses that are struggling to deal with the impact of the Covid-19 outbreak, but be sure to take action in advance of your filing deadline.