How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
There has been a significant amount of press coverage talking about institutional racism within the NHS not only in terms of the treatment of patients but also in terms of the low representation of ethnic minority staff in management positions. Whilst tackling that issue is beyond the brief here, it is important to recognise that sub conscious bias can, regrettably, play a part in decision making processes. An Employment Tribunal will explore a alleged discriminator’s conscious and sub conscious decision making and working in an environment which has not set out sufficient controls to avoid such sub conscious stereotyping places someone at a greater risk of being discriminated against.
In the context of the issues we are addressing here, i.e. risk assessments around BAME staff, as we have stated above, it is essential that BAME staff are represented at all levels in the discussion. Trusts need to be mindful that BAME are underrepresented in management positions.
BAME staff need to be included in the dialogue and need to have a safe place where they can challenge decisions that are being made in relation to them. There needs to be accountability in the processes applied. Meaningful conversations need to happen and concerns should not be dismissed.
The key factors for determining status for employment and tax purposes are generally the same. However there are some cases that highlight the different approaches taken by employment tribunals and HMRC when determining status. The important thing to consider for IR35 purposes is that being deemed employed for tax purposes does not mean a contractor is ’employed’. PSC’s can still be used in moving forward but there are likely to be discussions on the commercial aspects of the contractor arrangement. Employment status for tax purposes is likely to come at a cost for both parties.
The immediate impact is accounting for payroll purposes for the additional cost of 13.8% employers NIC’s and 0.5% apprenticeship levy on top of the payment to the contactor’s PSC.
Secondary NIC’s cannot be recovered from payments due to employees and the same applies under the new IR35 regime. However, new terms can be agreed with reduced level of fees to reflect this additional cost.
As discussed above, Covid-19 will inevitably deplete the workforce of housing providers in the foreseeable future. It would be prudent to consider making short-term policy changes to deal with this situation and manage the expectations of tenants going forward. A key policy change to consider is the extension of the standard lead-time for completing all non-urgent repairs and inform tenants of this change.
Such a change will also reduce pressure on landlords and front-facing staff.
As above, employers must protect the interests of their staff, particularly regarding health and safety. Extra care should be exercised when assessing the level of emergency of a repair on a case by case basis. All efforts should be made to reduce the number of attendances at properties by repair staff, whilst keeping all tenants safe.
As ever, communication is key – the pandemic cannot be used as a blanket excuse for abstaining from all duties and obligations. Housing providers must take a pragmatic approach in safeguarding customers whilst considering the interests of is workers. Maintaining lines of communication with all parties remains paramount.
The basics of health and safety law requires that employers take “all reasonably practicable steps” to ensure workers’ safety and that a suitable and sufficient assessment of risk is undertaken. It is the individual assessment of Covid-19 risk in each workplace that will be central. Employers will be required to conduct a robust risk assessment and then, following the hierarchy of controls, put robust processes and safeguards in place to address those risks.
UK government guidance and HSE advice is continually evolving, which in practice means that any risk assessment will need to be reviewed very regularly as that guidance develops. There is flexibility for individual businesses within the overall government framework and there will need to be a process of evaluation to ensure that the measures in place continue to meet the requirements.
The starting point of avoid, eliminate and control means looking at individuals continuing to work from home where possible (the fewer the number of people back in the workplace the lower the risk), and if not look at risk management, which leads to administrative controls – i.e. changing work practices before ending up at PPE. PPE is generally seen as control of last resort but in practice – facemasks, disposable gloves and constant prompts to wash hands for example.
In terms of changing working practices, employers should be thinking about:
- the workspace and how this is laid layout
- how do we make sure it is kept clean and hygienic
- how do we keep people apart
- how can we use toilets, canteens or other shared spaces/facilities safely
- how do we promote and enable higher levels of workplace hygiene
- if we are going to rely on PPE – can we get it, and is it suitable
- what about limiting customer interactions
- will there be enough first aiders on site
- can we manage fire safety, deliveries etc
- what about higher risk workers
- should work tools and equipment be allocated on an individual basis to employees.
These decisions need to be recorded and clearly communicated to staff members.