How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
In recognition of the problems that the current situation is causing, the UK IPO classed the 24th March and all subsequent days as “interrupted days” which means that deadlines that fall within this period will be extended until the UK IPO declares that the interrupted days have ceased. As lockdown has begun to be eased, the IPO has now reviewed its position and has confirmed that the “interrupted days” period will come to an end on the 29 July 2020. This means that Thursday 30 July 2020 will be the first normal day of operation, therefore all “interrupted days” deadlines will expire on this day. Similarly, if your deadline falls after the period of interruption ends, this deadline will not be automatically extended.
The IPO is conscious that many businesses may still be in challenging positions when the period of “interrupted days” end. They will endeavour to continue to provide flexibility and support to assist businesses with their applications. They hope to temporarily remove fees for requests for extensions of deadlines, and will give further updates when this fee exemption is in place.
The IPO continues to encourage applicants to meet original deadlines where they are able. As their offices are closed, the UK IPO is not currently processing paper forms (i.e. hard copy) and faxes. However, they are processing forms which have been submitted electronically, or via email and have made a new email address available for the submission of forms.
Intellectual Property Offices covering other territories have made their own announcements about the extension of deadlines. The EUIPO’s period of extension of deadlines came to an end on the 18th May. However, they have published a Guidance Note and accompanying webinar on the EUIPO website, detailing options for parties who may struggle to meet deadlines and remedies for those who may have missed deadlines.
This is likely to be a common situation and employers and employees are going to have to take a pragmatic approach. You could enter into a temporary flexible working arrangement perhaps agreeing to vary working hours/days or reducing targets or agree to use some annual leave.
Employees could ask to take a period of unpaid leave, asserting their right to time off to care for a dependant but the lack of pay is likely to be unappealing.
Alternatively employees who are unable to work because they have caring responsibilities as a result of COVID-19, which includes childcare responsibilities, can be furloughed.
Office holders who provide services under an intermediary (such as a service company consultancy agreement) and whose services relate to the office held, would fall under the IR35 regime and must be assessed accordingly.
On 25th June 2020, the Corporate Insolvency and Governance Act, among other things, introduced new restrictions on suppliers of goods and services to terminate the contract in the event that the customer enters an insolvency process. This has very important consequences for many businesses as it could expose them to greater financial risks.
Yes. The Town and Country Planning (General Permitted Development) (Coronavirus) (England) (Amendment) Order 2020 came into force on 9 April 2020 giving permitted development rights for emergency development. The permitted development right is available to local authorities and health service bodies (as defined) on land owned, leased, occupied or maintained by it for the purposes of:
- Preventing an emergency
- Reducing, controlling or mitigating the effects of an emergency
- Taking other action in connection with an emergency
It could cover, for example, the temporary change of use of buildings into a Nightingale Hospital or the establishment of a testing centre.
The permitted development right is not permitted in certain instances and is subject to a number of conditions including the notification of the local planning authority and the cessation of the use before 31 December 2020.
Further detail of the permitted development right is available at the link below.