How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
Many planning permissions contain a condition restricting the hours within which a developer can carry out construction work or are subject to an approved construction management plan setting out the permitted construction hours.
The Business and Planning Act 2020 entered the statute books on 22 July 2020. Section 16 of the Act incorporates a new S.74B into the Town and Country Planning Act 1990. The effect is that any condition/approved document which limits construction hours on a site could be amended through an application to the local planning authority. The application to the local planning authority must set out the date on which the proposed extension to construction hours shall cease (such date being no later than 1 April 2021, after which the original conditions over construction hours will resume). The local planning authority must determine the application within 14 days (beginning with the day after the application was submitted) otherwise there is deemed approval.
New guidance has been published alongside the Act and is available here
An employee can refuse to attend work but their refusal to do so will have to be based on a reasonable belief that their health and safety is in danger. Whether or not their refusal is reasonable will take into consideration factors such as the employee’s own health and whether they are at a higher risk of becoming seriously ill if they contract Covid-19 and the steps their employer has out in place to mitigate the danger of contracting Covid-19 at work.
In such circumstances where the employee’s belief is deemed to be reasonable, they will be entitled to stay at home and receive full pay.
If an employee is subsequently dismissed for refusing to attend work in these circumstances, they may be able to bring a claim for unfair dismissal.
Potentially, yes. If someone refuses to follow the health and safety measures that have been put in place to protect them, colleagues and possibly their customers, including (where appropriate) the use of PPE then this is a disciplinary issue and should be dealt with as such. Repeated failure to comply with the requirement to follow these measures, or a one off significant failure, may be sufficient to justify dismissal, depending on the circumstances.
Yes. With respect to employees you have an obligation to protect their health so you can gather information to do that. You might gather information from your employees on who has the virus, who has had it and recovered and also who has tested negative. You might also want to know if individuals have been in contact with someone who has it or if they are in a vulnerable group. It is reasonable to want to know where individuals have travelled. In the future it may also be reasonable to know if they are planning to travel to a virus hot spot, as the impact of the virus around the world is likely to continue for some time even after the outbreak has been contained in the UK.
It is reasonable to gather some information about visitors to your site, be they customers or suppliers, as this information will also help protect your staff. However, you should keep what you gather to a minimum. For visitors, it’s unlikely that you need to know anything more than they have Covid-19, are displaying symptoms or have recently been in contact with someone who has the virus.
The Chancellor announced:
- A new “job retention bonus” for employers to access for furloughed employees subject to certain conditions being met – see below for more information.
- A “Kickstart scheme” which will directly pay employers to create jobs for any 16-24 year old at risk of long-term unemployment.
- Incentives for employers to take on apprentices.
As a result of the CJRS being extended, the Job Retention Bonus will no longer be paid in February 2021.