How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
During the COVID-19 global pandemic, trials and hearings have been mostly conducted over Skype for Business and various other online platforms. Looking forward to the future, what we have experienced during the lock-down may continue and we believe will make litigation a more streamlined, user friendly experience for litigants.
One example of a regime which has been introduced is hybrid trials for lower value claims. Hybrid trials allow for parties and their witnesses to be linked into the court room by video link, whilst the judge and advocates are present in court. This makes it easier and frees up more time for witnesses, which would otherwise be spent in travel and waiting time, especially for those with other commitments.
With hybrid trials, clients still get a full legal experience and the judge will still apply normal legal principles during the trial. The procedure for the case is the same, both leading up to the trial or hearing and during the case itself; except without the need to physically attend court. It may also mean that there will be less of a backlog arising from the current crisis with cases continuing to be heard, allowing for matters to be listed earlier and a quicker outcome for the parties involved.
The shift to the use of online platforms may prove more practical for all those involved in legal matters. Interim hearings can be heard remotely resulting in a time and cost saving for litigants. Even for the final hearing only the legal representatives need to attend court – again resulting in time and cost savings for all concerned.
The Government expects the use of bespoke contractual documents to implement temporary arrangements relating to your PFI contracts.
With time and resource precious commodities, focus should be given to documenting:
- The key changes to your PFI requirements
- The temporary nature of the measures
- The requirement for best efforts on behalf of the PFI Contractor
- The importance of continued health and safety measures at all times
Initially, the relaxation applied to supermarkets and food suppliers. This was subsequently widened to apply to other businesses, permitting them to collaborate where necessary to respond to the crisis in the interests of consumers.
From 8 June 2020, people entering the UK from overseas (excluding those entering from Ireland, the Channel Islands or the Isle of Man) must comply with a mandatory 14 day quarantine period. However, for those travelling to England, a number of country specific exemptions have been introduced.
A full list of the countries excluded from the quarantine provisions can be found on the gov.uk website which change on a regular basis, often on short notice.
Where a quarantine period does apply, a person will not be able to leave the place they are staying in for 14 days, except in some very limited circumstances.
These rules will apply to both British and foreign nationals, however there are some further exemptions to this rule where a person is coming to the UK to undertake a certain role (such as a healthcare professional coming to the UK to provide essential healthcare). A full list of the narrow exemptions can be found on the gov.uk website.
Before travelling, individuals will be asked to provide their contact details and information about their journey and the accommodation that they will be self-isolating in. To do this, individuals will need to fill in an online form on the gov.uk website. Individuals who refuse to fill in this form may be fined £100 and/or denied entry at the UK border should they not be a British citizen or UK resident.
The information provided in the form will ensure that the Government can check that an individual is self-isolating at the address given. Where an individual refuses to self-isolate they can be fined £1,000 if they are staying in England or Wales.
Once visa application centres re-open overseas and UK visa applications are processed, this 14 day period will need to be taken into consideration and may require employment start dates in the UK to be delayed.
Government guidance is that public transport should be avoided wherever possible. Transport providers will be expected to follow government guidance to make their services more COVID-19 secure.