Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

Can employers reduce their pension contributions?
  • Yes, if contributions to a defined contribution (“DC”) scheme exceed statutory minimum for auto-enrolment purposes, it may be possible to reduce employer contributions to the statutory minimum, but not further.
  • However, the processes required for reduction of DC employer contributions will necessitate obtaining legal advice:
    • Reducing employer contributions may require changes to the employment contracts of affected staff (as does the furlough process).
    • Reducing employer contributions may also require negotiation with trade unions or other staff representative forums.
    • Where group personal pensions are used, the contractual format may not permit changes of employer contributions, and hence it may also be necessary to enter into a new contractual arrangement. Choosing a new group personal pension plan is a not insignificant task in itself.
    • Employers with at least 50 employees are required to conduct a 60-day consultation process with affected employees if they propose to reduce employer contributions (but please see below).
    • Finally, it may require a change to the scheme rules and engagement with the scheme trustees if the scheme is operated under trust.
  • For DB schemes, specific considerations apply (see the last section, below).
Can you furlough a suspended employee?

Yes. You should be able to furlough a suspended employee subject to all other eligibility requirements however we recommend that you take advice on this before doing so.

Can landlords re-possess properties if tenants can’t afford to pay the rent because of the coronavirus outbreak?

After 25 March 2020, and until 30 September 2020, a landlord can only start possession proceedings against a tenant if they have served 3 months’ notice upon the tenant – irrespective of any grounds relied upon.

On 27 March 2020, the Court introduced new rules to put all possession proceedings (except against trespassers) on hold until 25 June 2020 – it means that the Court cannot make an order for possession or any other order that would cause someone to be evicted during that time.

These rules do not just apply to tenants who have fallen into rent arrears.

On 5 June 2020, the Government announced that this stay would be extended further until 23 August 2020.

This means that you can issue new possession proceedings (provided you have complied with the new temporary rules in relation to notice periods, if the notice was served since 25 March 2020) and you can continue with existing possession proceedings.

However, any progress you may be able to make in dealing with those proceedings is likely to be very limited – the Court will allow you to comply with directions orders that have already been made but non-compliance will not be punished (at least for the time being).

These rules, and the latest announcements, are in keeping with the Government’s expectation that landlords show compassion towards affected tenants and that all parties will work together to establish a suitable repayment plan to allow tenants to repay the arrears at an affordable rate.

What should payroll look out for if the Government's Coronavirus Job Retention Scheme is used?
  • It is important to have a clear paper trail for any agreed reduction in salary, and hence any reduction in the amount of contributions. However, the contribution rates (as opposed to the amounts) should be the same as normal, and hence all processes and software should function as per normal and, amongst other things, remain compliant with auto-enrolment employer duties.
  • However, if the period of affected contributions does not overlap precisely with the period of reduced salary, for example because of different cut-off dates, there may well be instances of non-compliance with auto-enrolment employer duties at the beginning as well as at the end of the period covered by the Coronavirus Job Retention Scheme.
  • Accordingly, where an employer takes advantage of the Coronavirus Job Retention Scheme, good communication with the persons responsible for pensions administration and detailed record-keeping are essential to prevent non-compliances in the short-term and confusion in the long term.
What agreements will the CMA choose not to take enforcement action in respect of?

CMA guidance suggests that it will not take enforcement action in respect of agreements which:

  • Are appropriate and necessary to avoid a shortage, or ensure security, of supply
  • Are clearly in the public interest
  • Contribute to the benefit or wellbeing of consumers
  • Deal with critical issues that arise as a result of the Covid-19 pandemic
  • Last no longer than is necessary to deal with these critical issues