How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
If an employee is self-isolating (as a result of the pandemic) they may be entitled to SSP. Employers should not furlough employees in this category just because of their absence, but they can furlough if there are genuine business reasons for doing so and other eligibility requirements are met. In these cases the employees should no longer receive sick pay and they would be classified as furloughed.
The guidance has specified that those on long term sick leave or who are ‘shielding’ for 12 weeks in line with public health guidance can also be furloughed. But it is important that you clarify that they do fall in the category of extremely vulnerable (https://www.gov.uk/government/publications/guidance-on-shielding-and-protecting-extremely-vulnerable-persons-from-covid-19). It is up to employers to decide whether to furlough employees who are shielding or on long-term sick leave.
You can claim from the CJRS and also for the two week SSP rebate scheme (see below) for the same employee but not for the same period of time. Therefore if you have a furloughed employee who becomes ill and you subsequently move them to SSP you cannot claim the furlough rate of pay. If you keep the employee on the furloughed rate you can continue to claim this under CJRS.
Failure to comply with the collective inform and consult obligations could impact on the fairness of any dismissals – see next question. In addition, a Tribunal can award a protective award of up to 90 days gross pay for each affected employee. The purpose is intended punish the employer for not complying with the obligations, not to compensate the employee for their individual financial loss.
The application has to be made before the date on which the accounts should have been filed, so this process can’t be used if you are already late. If you don’t make the application before your filing deadline, then a fine will automatically be generated if your accounts are filed late. Whilst you could appeal against such a fine on the grounds that the delay was caused by coronavirus issues, this is likely to be a much more time consuming and uncertain process that applying in advance.
It does not appear that the process applies to Confirmation Statements or other returns.
The Act is intended to facilitate the rescue of businesses that are in financial difficulty by preventing suppliers from invoking certain termination clauses under a supply contract, and therefore maintaining supply of goods and services to the business whilst plans to save the business can be considered.
Supply contracts often contain a clause enabling them to terminate the contract, or take other steps such as requiring payment in advance, in the event that the customer enters an insolvency procedure.
This new Act removes any such contractual right by dis-applying any clause that allows the supplier to terminate the contract, or take any other step, due to the customer entering an insolvency process.
Suppliers are also prevented from demanding payment for pre-insolvency debts owed by the customer as a condition of continued supply.
Additionally, where the supplier had a contractual right to terminate the contract due to an event occurring before the customer went into the insolvency process (whether or not linked to payment issues), the supplier loses this right for the duration of the insolvency process.
If a contract contains a force majeure clause this may become operative due to the coronavirus pandemic and related emergency legislation. Such clauses exist to ensure that if some unforeseen event prevents a party from being able to perform their obligations under a contract, either on time or at all, they will be excused from their obligations and not be held liable for non-performance.
The clause must actually be written into the contract to have effect – a force majeure clause cannot be implied into a contract. Whether it can be relied on by a party will depend on the wording of the clause itself as it may only be applicable in certain limited circumstances.
You should seek legal advice at an early stage if you think that force majeure is relevant, because a number of potentially complex issues must be addressed, many of which will turn upon the exact wording of the force majeure clause in the contract in question:
- Has a force majeure event actually arisen?
- What notification process do you have to follow to rely on the provision?
- What mitigation steps do you have to take?
- What is the effect of the force majeure event – is the contract suspended, or can it be terminated (which might not be what you want)?