Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

VIDEO: An update from cashflow.co.uk expert Chris Silverwood about access to finance

Partner at Ward Hadaway Adrian Ballam catches up with corporate finance expert and CBILS specialist Chris Silverwood (CorpFin and cashflow.co.uk) a month after their initial conversation to talk about what the last couple of months have taught us about access to finance.

Sections of the video and their timings are as follows:

(01.06) – example of continuing appetite for certain businesses (e.g. tech sector)

(02.06) – conflict between incumbent bank and different CBILS lenders, plus brief discussion of CBILS II

(05.36) – bounce back loans have been a distraction

(06.27) – muted impact of fintech CBILS lenders

(07.52) – discussion about invoice discounting

(11.59) – looming insolvency environment

(12:52) – emerging themes

 

How do I guard against contractor insolvency in the construction industry?

It is almost impossible to completely guard against the risks associated with contractor insolvency, but there are some steps which can assist in mitigating and managing the risks involved.   To be in the best possible position, it is worth considering the following at the outset of any project:

  • Check the contractor’s financial position – particularly the specific company which will enter into the building contract, as the employer’s rights will be against this company rather than the business as a whole
  • Take legal advice to ensure that the building contract is properly drafted with appropriate provisions to deal with an insolvency event
  • Consider requiring a performance bond and/or parent company guarantee (each serve slightly different purposes)
  • Obtain collateral warranties from the consultants and sub-contractors involved, so that there are contractual rights against other parties if the contractor is no longer able to meet claims
  • Consider requiring retention bonds, advance payment bonds or vesting certificates if necessary
  • Project bank accounts and escrow accounts can also provide some further assurances for the parties involved
What is the NICE guidance around Service organisation?
  • Trusts should allow for telephone advice rather than face-to-face review from critical care when clinically appropriate.
  • Hospitals should discuss the sharing of resources and the transfer of patients between units, including units in other hospitals, to ensure the best use of critical care within the NHS.

Please note, the above is intended to provide a summary of the key recommendations which emerge from this guidance. Access to the full guidance can be found here.

Can I switch an existing loan facility onto the CBILS scheme?

If a business has been provided with a loan from 23 March on commercial terms, providing the borrower meets the CBILS eligibility criteria, lenders have been asked to bring these facilities onto CBILS wherever possible (e.g. where the lender is accredited to offer the same facility through CBILS) and changes retrospectively applied as necessary. Please contact us if this applies to you and we can review facilities and advise upon the potential changes that may be made retrospectively to the benefit of the business.

Is there anything else I should consider from a health and safety perspective?

Increased hygiene measures should be introduced to limit the spread of infection. Increase the frequency of cleaning, particularly higher risk contact points such as door handles. Avoid the use and sharing of hardcopy in favour of electronic documents; avoid sharing of tools and work equipment; increase the availability of handwashing facilities and hand sanitisers; issue anti-bacterial wipes and tissues to staff, and remind everyone to maintain good personal hygiene practices, including regular hand washing. Prominent and repeat signage will be vital in reminding workers of these steps they can take to protect themselves.

PPE – e.g. disposable gloves and face masks – are not currently legally required in the UK, but especially where social distancing might not be possible, it may be necessary to make appropriate PPE available to staff. If so, you will need to make sure there is enough available train everyone so it used properly and provide for safe disposal of used items.

MOST IMPORTANTLY – communicate with your people; invite their input and suggestions and act on them. Communication and participation in the process of a safe return to work are going to be crucial to its’ success.
Monitor for illness: train managers how to spot the symptoms of COVID-19 and have a clear process if someone is potentially infected. Continue to remind staff to only come into work if they are well and not experiencing any symptoms. A number of businesses are planning on using testing and screening methods, such as temperature checks. Remember, these steps create data privacy considerations which you will need to consider.

Do not forget existing health and safety obligations, such as maintaining sufficient numbers of fire marshals and first aiders on-site. Employers should also be aware that the Health and Safety Executive must be notified under RIDDOR of any workplace incidents that lead to exposure to COVID-19 and any cases where there is “reasonable evidence” that it was caused by exposure in the workplace. Be aware that workers are being encouraged to report to HSE failures of their employers to keep them safe from the threat of the virus.