How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
Remote mediations have become increasingly popular as a way of settling a dispute before it goes to court. There are a number of ways in which you can mediate remotely, but the most common platform is Zoom, due to its easy-to-use nature and the ability to have ‘break-out rooms’. We have answered some FAQs and set out a quick guide to remote mediations below.
What is remote mediation?
- Mediation is a form of assisted negotiation, in which a neutral 3rd party mediator seeks to help the parties resolve their dispute. The process on the day is managed by the mediator and adopts certain key ground-rules. These are that discussions are private and cannot be referred to in court; and the process is entirely voluntary and non-binding, if and until a settlement is finalised. In the current pandemic mediations are now usually conducted remotely by video conference, instead of an in-person meeting.
- The structure of the mediation will depend on the matters that are in dispute. Before the mediation the parties will exchange their views in position papers and prepare a bundle of the key documents.
- Generally the parties will start the mediation in the same ‘room’ as the mediator, where they will be invited to set out their positions. The mediator will then put the parties into ‘break-out rooms’. These rooms serve as your own private ‘room’ which the mediator will join. You will therefore be able to have private discussions with the mediator without the other side being able to hear those discussions. The mediator will go between the ‘break-out rooms’ to discuss a party’s position further in order to attempt to reach a settlement.
- If an agreement is reached, at the end of the mediation the Settlement Agreement will be drafted. The Settlement Agreement works as an enforceable contract. The Settlement Agreement will outline the details of what has been agreed and the intentions of the parties, such as any actions required, payments to be made and appropriate timescales. Each party will sign the Settlement Agreement, which can be done electronically.
- It is not always possible to reach a resolution/agreement by mediation, but the mediator serves as an impartial third party in order to aid the process. If no agreement has been reached, the mediation may still prove useful as it will give you a better understanding of the other side’s position.
What should I do before the mediation to prepare?
- Ensure that you are in an area with minimal distractions. Mediation is a confidential process, so make sure that you are in a private location.
- Ensure that your microphone and camera work and that you have access to the online platform that will be used. We send our clients a link to the website in advance so that this can be tested out.
- Consider any agreed dress code and dress appropriately.
- Have a copy of the mediation bundle to hand, whether in hard or soft copy, and be aware of what documents are in there.
Any tips on what to do on the day?
- Remember to make sure that before you have any private conversations with the mediator you are in your break-out room.
- You may contact the mediator whilst being in the break-out room. On Zoom there is an ‘Ask for Help’ button on the screen. The mediator will then be prompted to join your room.
- Ensure that you inform the mediator if you or others enter/leave the room. It is important that the mediator knows who is present.
- Be mindful of body language and facial expressions as these can appear more enhanced on the screen, and they are easier to pick up in a remote mediation.
- Stay calm and focussed at all times. When you have a dispute it is sometimes tricky to maintain a calm manner, but this is always vital in attempting to reach an agreement.
- When engaging with the mediator avoid any external distractions such as text messages and emails, as it may come across that you are not interested in the process. It is important to pay attention so that you do not miss any dialogue which may be key to any agreement that is reached.
- When you are in the break-out room without the mediator make sure that you take breaks and keep refreshed, as virtual mediations can be tiring.
Obtaining an employee’s Covid-19 test result will amount to processing personal data for the purposes of the General Data Protection Regulation 2016/679 (GDPR) and information about an employee’s health is a special category of data (sensitive personal data under the Data Processing Act 2018 (DPA)).
In accordance with the GDPR and DPA, there must be lawful grounds for processing such information. Most employers rely on employees’ consent to obtain medical information and process sensitive personal data and if the employee is unwilling to give consent, you will not normally be entitled to the information.
Special category data can be processed lawfully if it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. Employers may be able to require an employee to disclose their Covid-19 test if there is a substantial public interest, such as ensuring that the employee self-isolate if they have a positive test. However, there is a risk that this measure could be considered disproportionate particularly if it is enforced on all employees as a blanket measure.
IR35 is an anti-tax avoidance regime which is intended to tackle (in HMRC’s view) the long standing issue of individual contractors providing their services or labour via an intermediary – which is usually a personal service company (referred to as a PSC). We’ll talk about PSCs here, but there are other types of intermediaries that are caught.
HMRC’s view is that this arrangement is often considered to be disguised employment and therefore a tax-avoidance arrangement.
So IR35 is essentially a test of employment status – and if, once you apply the test, the contractor should be an employee, they should then be taxed as an employee.
Where an employer is proposing to dismiss:
- 100 or more employees at one establishment within a 90-day period, consultation must begin at least 45 days before the first dismissal takes effect
- Between 20 and 99 employees within a 90-day period, consultation must begin at least 30 days before the first dismissal takes effect
- If you are proposing to dismiss less than 20 employees then there are no minimum time limits but you must adhere to a fair process which will involve individual consultation and providing the employee with a right of an appeal
That will depend on the terms of your facility and the stance taken by your bank.
Banking facilities often place obligations on businesses to stick to certain financial criteria. For example, an obligation to keep turnover or profit above certain levels or a commitment to keep the bank’s exposure within an agreed percentage of the value of the company’s assets (known as loan to value ratio).
The consequences of breaching those covenants will depend on the terms of your facility, but normally this amounts to an event of default. Events of default can result in the loan (or whatever form the facility takes) becoming repayable and could give the bank certain powers to take action to recover the money that they are owed.
Whether the bank will take action during these unprecedented times is another matter, particularly given the extent of support being offered to businesses via mainstream lenders and the political desire to keep viable businesses up and running. Lenders themselves will no doubt wish to remain supportive where possible. The underlying performance of the business (and whether but for the effects of Covid-19 it would have been in a healthy financial position), the relationship you have with the bank and your history with them will no doubt be relevant to the approach taken by the bank. However, early engagement with your bank (as well as other key stakeholders in the business) will be important.