Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

Can you furlough a suspended employee?

Yes. You should be able to furlough a suspended employee subject to all other eligibility requirements however we recommend that you take advice on this before doing so.

VIDEO: An update from cashflow.co.uk expert Chris Silverwood about access to finance

Partner at Ward Hadaway Adrian Ballam catches up with corporate finance expert and CBILS specialist Chris Silverwood (CorpFin and cashflow.co.uk) a month after their initial conversation to talk about what the last couple of months have taught us about access to finance.

Sections of the video and their timings are as follows:

(01.06) – example of continuing appetite for certain businesses (e.g. tech sector)

(02.06) – conflict between incumbent bank and different CBILS lenders, plus brief discussion of CBILS II

(05.36) – bounce back loans have been a distraction

(06.27) – muted impact of fintech CBILS lenders

(07.52) – discussion about invoice discounting

(11.59) – looming insolvency environment

(12:52) – emerging themes

 

If a member of staff does not inform me that they ought to be self-isolating will I still be liable for a fine?

Potentially no.

If an employer is not put on notice that the circumstances of a worker or agency worker are such that they ought to be self-isolating, by either the worker or agency worker themselves or another member of staff, then there ought to be a reasonable excuse, and potentially, no fixed penalty notice will be issued.

Can I dismiss an employee who refuses to return to work?

Potentially. The first question is why the person is not able to return, as their individual circumstances will be very relevant in terms of whether they can be safely dismissed.

Employers should ask themselves 2 questions in this situation:

  1. Have I done everything I am required to do in order to make the workplace safe for the individual to return; and
  2. Is what the employee saying reasonable?

If the answer to question 1. is no then a dismissal is unlikely to be fair. However, even if the answer to question 1. is yes, then there is still question 2. to address. If the employee has reasonable grounds as to why they are unable to return to work, e.g. due to health issues, childcare responsibilities etc then the dismissal is unlikely to be fair. It is only if you can answer yes to question 1. and no to question 2. that you can have some confidence in the potential safety of the dismissal.

Dismissals based on objections to returning to work on health and safety grounds will very often be risky and are highly fact specific, therefore please contact one of the employment team for further advice prior to dismissal.

What can suppliers of goods and services do to minimize risk?

If suppliers still wish to terminate the contract, they must contact the directors or the officeholder dealing with the insolvency process and obtain their approval to terminate the contract – which, of course, might not be given.

If the continued obligation under the contract to supply goods/services to the customer would place the supplier in financial hardship the supplier can apply to court for permission to terminate the contract.  This will involve time and legal expense.