Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

What can I do to make sure my home-working people are doing so safely?
  1. Keep in touch. If contact is poor, workers can feel disconnected, isolated or abandoned. This can adversely affect stress levels and mental health – especially in the current crisis when everyone is feeling more anxious.
  2. Think about the use of laptops/devices (DSE) at home. Provide a basic form of risk assessment for self-completion.
  3. Remind workers of simple steps to reduce the risks from display screen work:
    • take regular breaks (at least 5 minutes every hour) or change activity
    • avoid awkward, static postures by regularly changing position
    • get up and move or do stretching exercises
    • avoid eye fatigue by changing focus or blinking from time to time
Can employers reduce their pension contributions?
  • Yes, if contributions to a defined contribution (“DC”) scheme exceed statutory minimum for auto-enrolment purposes, it may be possible to reduce employer contributions to the statutory minimum, but not further.
  • However, the processes required for reduction of DC employer contributions will necessitate obtaining legal advice:
    • Reducing employer contributions may require changes to the employment contracts of affected staff (as does the furlough process).
    • Reducing employer contributions may also require negotiation with trade unions or other staff representative forums.
    • Where group personal pensions are used, the contractual format may not permit changes of employer contributions, and hence it may also be necessary to enter into a new contractual arrangement. Choosing a new group personal pension plan is a not insignificant task in itself.
    • Employers with at least 50 employees are required to conduct a 60-day consultation process with affected employees if they propose to reduce employer contributions (but please see below).
    • Finally, it may require a change to the scheme rules and engagement with the scheme trustees if the scheme is operated under trust.
  • For DB schemes, specific considerations apply (see the last section, below).
My visa is about to expire, can I apply to extend it?

Yes, you should submit a new visa application before your current visa expires.

The visa application is a two stage process:

  • First you submit the online application and pay the fee
  • Second you attend a visa application centre to enrol your biometrics and verify your passport.

Submitting a valid online application before your current visa expires secures your right to continue living and working in the UK, even after your current visa has expired.

Visa application centres across the world have been closed due to covid19 but are now mostly re-open to enable you to book an appointment to complete your application, albeit some are experiencing a backlog of applications.

What is happening with public transport?

Government guidance is that public transport should be avoided wherever possible. Transport providers will be expected to follow government guidance to make their services more COVID-19 secure.