How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
In the unfortunate event that there will be a significant number of deaths, planning will fall to the local resilience forum; which includes all relevant local organisations and statutory bodies, who will have prior experience in working in excessive death scenarios.
It is for the coroners to ensure that they are familiar with the local resilience forum plans and discussions required. This will include issues regarding storage capacity and post-mortem examination capacity.
- Remember that employees will also be making contributions on any reduced wage under the Coronavirus Job Retention Scheme. The amount contributed may be less, but the contribution rate will be the same, unless the following applies.
- Employees may reduce their DC employee contributions if their scheme rules allow them to do so, but no further than the statutory minimum if the scheme qualifies as the employer’s auto-enrolment vehicle.
- Employees might choose to opt-out or cease active membership of their scheme, which might cause a spike in administration at a time when administrators are likely to be understaffed. It is important that employers remember they must not do anything to encourage or induce employees from leaving an auto-enrolment vehicle as this may constitute an offence.
- Employees who leave their scheme in this way will have to be re-enrolled in due course as and when required by law.
- For DB schemes, specific considerations apply (see the last section, below).
The application is made via the Companies House website, and only takes a few minutes to complete. Companies House have indicated that the extension is “automatic and immediate” and will be for three months.
Having said that the extension is “automatic”, their website also says that Companies that have already extended their filing deadline, or shortened their accounting reference period, may not be eligible for an extension.
If an extension is granted, it will not affect the due date for filing accounts in future years – so the deadline will revert to the usual date for the next accounting period.
On 25th June 2020, the Corporate Insolvency and Governance Act, among other things, introduced new restrictions on suppliers of goods and services to terminate the contract in the event that the customer enters an insolvency process. This has very important consequences for many businesses as it could expose them to greater financial risks.
You must exercise reasonable care in assessing status and making a status determination, considering what the position would be if the contractor was engaged directly by the end user client instead of via a PSC.
Status is usually determined by looking a number of factors and how they apply to the contractor’s working arrangements. This is a difficult exercise that is usually carried out by employment and tax lawyers and it is full of grey areas. We have a toolkit that can help you navigate this process which Paul will tell you more about at the end of the session.
The key factors used to determine status are:
- Control:
- How much control does the end user client have over the contractor in terms of working arrangements (hours, place of work) and how the work is carried out? Or is the individual contractor able to determine how and when they work and without direct supervision of the end user client?
- Personal service:
- Is the contractor required to perform the services personally without the right to send a substitute? If there is a right to appoint a substitute is this subject to end user client approval?
- Mutuality of obligation:
- Is the end user client obliged to provide the contractor work with a mutual obligation on the contractor to accept that work?