Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

I submitted my online visa application but couldn't book an appointment, what should I do?

Normally, once you have submitted the online visa application and paid the fee, you have to attend an appointment to enrol your biometrics and verify your passport within 45 days. This requirement has been relaxed due to the visa application centres being closed.

Now that application centres have mostly reopened, you must book and attend an appointment to complete the application process. However, the Home Office has recently introduced the IDV app which allows applicants who previously gave their fingerprints as part of a previous application since July 2015, to upload a photo electronically. There will then be no need to attend a Visa Application Centre to submit their biometrics. Applicants who are eligible to use this electronic option will be contacted by UKVI.

Do you have to collectively consult for the minimum period of time before you can issue notice?

These periods are often mistakenly referred to as minimum lengths of consultation (especially by Trade Unions). That is not correct. Consultation can commence, conclude and notices of dismissal be issued within the 30 and 45 day periods. The expiry of the notice would just have to be outside of those restricted periods.

Which products and services are affected?

Initially, the relaxation applied to supermarkets and food suppliers. This was subsequently widened to apply to other businesses, permitting them to collaborate where necessary to respond to the crisis in the interests of consumers.

Should Covid-19 be recorded as a cause of death?

The Chief Coroner supports the position, communicated by NHS England and the Chief Medical Officer that Covid-19 is an acceptable direct or underlying cause of death for the purposes of completing the Medical Certificate of Cause of Death (MCCD) and is considered a naturally occurring disease. This cause of death alone is not a reason to refer a death to a coroner under CJA 2009.

If the cause of death is believed to be due to confirmed Covid-19 infection, there is unlikely to be any need for a post mortem to be conducted and the MCCD should be issued, and guidance is given on how this is delivered to the Registrar in the event of the next of kin/informant being in self-isolation. 

In a hospital setting the MCCD process should be straightforward because of diagnosis and treatment in life. This may be more complex in a community setting. The Coronavirus Act 2020 however expanded the window for last medical review from 14 to 28 days. Outside of this, the death will need to be reported to the coroner.

Although Covid-19 is a naturally occurring disease, there may be additional factors around the death which mean it should be reported to the coroner; for example, the cause of death is unclear, or where there are other relevant factors. Guidance is given to coroners on how to manage such reported deaths, particularly where post mortem examinations may not be readily availability.

What can I do to make sure my home-working people are doing so safely?
  1. Keep in touch. If contact is poor, workers can feel disconnected, isolated or abandoned. This can adversely affect stress levels and mental health – especially in the current crisis when everyone is feeling more anxious.
  2. Think about the use of laptops/devices (DSE) at home. Provide a basic form of risk assessment for self-completion.
  3. Remind workers of simple steps to reduce the risks from display screen work:
    • take regular breaks (at least 5 minutes every hour) or change activity
    • avoid awkward, static postures by regularly changing position
    • get up and move or do stretching exercises
    • avoid eye fatigue by changing focus or blinking from time to time