Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

What are the contractual issues that businesses need to think about as they get back to business following lockdown?

It is clear that we are emerging from a completely unprecedented period of disruption for many businesses, and this may have had a huge impact on their contractual arrangements both with suppliers and customers.

As the lockdown eases, and we get back to business, it’s important that businesses take stock of what has happened, and ensure they review and address the legal and contractual consequences of what has been happening since the start of the global pandemic.

What is the difference between individual and collective consultation?

Where it is envisaged that 20 or more employees will be dismissed at a relevant establishment within a 90 day period or less, then collective consultation is required (in addition to individual consultation) and the company must inform BEIS (using form HR1).

If there are less than 20 dismissals then you are only required to carry out individual consultation.

Can I argue that my contract has been frustrated?

It could be possible depending on your contract. If there is no force majeure clause in a contract, it may be possible that the contract may have been “frustrated” by emergency legislation. In legal terms, a contract can be frustrated where an event occurs after it is entered into which was not contemplated by any party at the outset, is not due to the fault of any party, and which makes the performance of the contract impossible.

If this is the case, the contract could be “discharged”, meaning that the parties’ obligations under the contract are no longer binding.

It is possible that a contract could be frustrated within this particular legal doctrine by a change in the law that makes performance of a contract illegal. However, if it simply becomes more difficult, or more expensive, then the legal tests for frustration might not be satisfied. There are also limits to the application of the rule if the frustrating event was already known about at the time the contracted was entered into.

Again, careful legal advice will be required at an early stage. The rules about force majeure or frustration might help businesses that find themselves unable to perform a contract because of the coronavirus outbreak.

Any new contracts that are concluded should expressly deal with the possibility that performance might become more difficult, more costly, or impossible to perform.

Do I have to continue to pay furloughed staff while furloughed? Can I wait until I receive the money from the government?

To qualify for a grant under the scheme you must pay your furloughed staff the wages you are claiming for. Failure to do so may result in a HMRC investigation and/or claims from furloughed staff for unlawful deductions from wages and possibly constructive dismissal claims.

Normal benefits including non-monetary benefits should continue during furlough unless the individual has agreed in writing to reduce or remove a benefit during this time.

Employers are expected to apply for one or more of the financial support schemes available to be able to continue to pay staff.

What impact does the Regulations have in respect of matters which arise from Fire Safety Audits - e.g. if balconies with wooden/decking elements are now considered higher risk and whether that would fall to developer to remedy the materials used to construct balconies?
The duty would fall on the owner of the building to control the hazards presented by balconies made from combustible materials. There may be scope (via warranties/indemnities or other terms) arising from the contract between the developer and owner for the owner to seek to recover the cost of remedial works.