Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

How do I determine contractor status?

You must exercise reasonable care in assessing status and making a status determination, considering what the position would be if the contractor was engaged directly by the end user client instead of via a PSC.

Status is usually determined by looking a number of factors and how they apply to the contractor’s working arrangements. This is a difficult exercise that is usually carried out by employment and tax lawyers and it is full of grey areas. We have a toolkit that can help you navigate this process which Paul will tell you more about at the end of the session.

The key factors used to determine status  are:

  • Control:
    • How much control does the end user client have over the contractor in terms of working arrangements (hours, place of work) and how the work is carried out? Or is the individual contractor able to determine how and when they work and without direct supervision of the end user client?
  • Personal service:
    • Is the contractor required to perform the services personally without the right to send a substitute? If there is a right to appoint a substitute is this subject to end user client approval?
  • Mutuality of obligation:
    • Is the end user client obliged to provide the contractor work with a mutual obligation on the contractor to accept that work?
Can employees on Flexible Furlough work as union or non-union representatives or as pension trustees?

Employees who are union or non-union representatives may undertake duties and activities for the purpose of individual or collective representation of employees or other workers. However in doing this, they must not provide services to or generate revenue for, or on behalf of your organisation or a linked or associated organisation.

Employees who are pension scheme trustees or trustee directors of a corporate trustee may also undertake trustee duties in relation to the pension scheme. However, a professional, independent pension scheme trustee who has been furloughed by the independent trustee company cannot undertake trustee work that would provide services to or generate revenue for, or on behalf of, the independent trustee company or any organisation linked or associated with that independent trustee company during hours when they are recorded as being on furlough.

What is the NHS coronavirus Test and Trace scheme and how does it work?

The NHS Test and Trace service is operated by the NHS in England to track and help prevent the spread of COVID-19. Where an individual displays symptoms of coronavirus they can be tested to determine whether or not they have the disease. Those with the disease will then be contacted by NHS contact tracers and asked who they have come into close contract with.
Close contact is defined as:

  • Face to face (within 1 metre)
  • Spent more than 15 minutes within 2 metres of another person
  • Travelled in a car or on a plane with another person

The contact tracer will then contact those people with whom the individual has come into close contact and tell them to self-isolate for 14 days.

What can I do as an employer if employees are known to be breaking the National Lockdown rules?

This will depend on the particular facts and the employee’s circumstances but an employee should co-operate with the employer so far as is necessary to enable compliance with any statutory duty or requirement relating to health and safety.

In addition, conduct outside of work can result in an employee’s dismissal if the conduct pertains to the employment relationship. If an employee breaches the lockdown rules and it affects their ability to work, such as it being no longer safe for them to attend work, or the reputation of the employer, these may be grounds for disciplinary action and subsequent dismissal.

Can furloughed workers still continue with union or non-union representation duties?

Yes, they can continue to undertake duties or activities for representative purposes. This includes individual or collective representation of their colleagues. They must not carry out any actual work or generate revenue for their employer or a linked or associated organisation.