Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

Can I have legal documents signed and witnessed?

Solicitors can be authorised to sign contracts for their clients – a signed letter of authority should be scanned and sent to avoid posting potentially contaminated documents.

Solicitors should exchange supplemental agreements on behalf of their clients to agree to postpone exchange and completion dates if it has been agreed to push these back.

The Law Society advises that electronic signatures be used as much as possible for contracts, to avoid possible contamination. However, the Land Registry confirms that the legal transfer document cannot be validly executed with an electronic signature. Solicitors should agree a completion undertaking that the original transfer document will be sent when received and after the restrictions have been lifted.

The Land Registry’s latest guidance https://www.gov.uk/guidance/coronavirus-covid-19-impact-on-hm-land-registrys-services published on 14 May states:

We accept deeds that have been signed using the ‘Mercury signing approach’.

For land registration purposes, a signature page will need to be signed in pen and witnessed in person (not by a video call). The signature will then need to be captured, with a scanner or a camera, to produce a PDF, JPEG or other suitable copy of the signed signature page. Each party sends a single email to their conveyancer to which is attached the final agreed copy of the document and the copy of the signed signature page.

Solicitors should be willing to adopt this procedure for completing transactions to enable them to be registered by the Land Registry.

The execution of a transfer is a deed and must be witnessed. Members of the family can witness signatures so long as they are not also a party to the document. A witness will be more credible if they are 18 or over, but this is not a legal requirement. The legal requirement is for the witness “to be present” when the document is signed. It would be possible for a witness to be on the other side of the room or the other side of a window, and validly witness the execution of a deed. The witness does need to take precautions to avoid possible contamination from the document.

A statutory declaration does not need to be witnessed but must be administered by a solicitor or commissioner for oaths. There is no legally prescribed process for this, and there is nothing to suggest that this could not be validly done via a video telephone call if the signature on the declaration can clearly be seen by the person commissioning the oath when the oath is made.

How do I ensure my use of video conferencing calls complies with GDPR?

With the loss of face-to-face meetings in the current situation, video conferencing has taken centre stage. But how do you do that in a compliant way? Here are some of the main high-level data protection issues to consider when selecting and implementing a new third party provider’s video conferencing system.

  1. Make sure you do your due diligence on the security measures offered by the provider. Clearly you can’t visit them, so look at the information offered publicly by the provider and read good quality, reliable, third party sources and ask the provider questions directly. Also ask any other organisations you know that use the provider. Document all this.
  2. If personal information is being sent outside of the UK/European Economic Area, make sure that transfer complies with GDPR. If it’s a US provider, is it registered in the EU-US Privacy Shield list or does it offer a model clause contract (you’re likely to need the 2010 version)? Or is the service provided from a country whose data protection laws offer equivalent protection to those in Europe? Look at the support service as well as the hosting. Document this.
  3. Make sure you put a compliant processor agreement in place. The provider should offer one as part of the contract terms. Check it meets GDPR requirements.
  4. You’re likely to need to update your privacy notice, particularly if you’re going to record calls. Provide participants with a short message and link to the privacy notice in the meeting invite and on any registration page.
  5. Create or update other GDPR-mandated documentation – for example, depending on your use, you may need a legitimate interests assessment and to update your record of processing.
  6. Finally, configure and use the system in a secure and compliant way. Look at the settings/options carefully and think through the security and compliance implications of each. That could include deciding who in the meeting can share their screen; whether or not you use passwords for participants; whether or not to record, and if you’re going to record, where to store the recording. Document your decisions and the reasons for them.

The ICO has said it understands that resources, whether they are finances or people, might be diverted away from usual compliance work during the pandemic. However the last thing you need at the moment is to create a bigger problem than the one you are trying to solve. So do the best you can, ask for help from one of our specialists if you need it, and keep the whole thing under review.

On 16 April 2020, Ian Hulme, the ICO’s Director of Assurance, posted a blog for business owners, employers and managers about how to safely roll out the latest video conferencing technology.

On 21 April 2020, the NCSC published security guidance for organisations on choosing, configuring and deploying video conferencing services.

What are the NICE protocols around a patient’s ongoing treatment whilst in critical care during the pandemic?
  • Start critical care treatment with a clear plan of how the treatment will address the diagnosis and lead to agreed outcomes.
  • Review critical care treatment regularly and when the patient’s clinical condition changes.
  • Stop critical care treatment when it is no longer considered able to achieve the desired outcomes. Record the decision and the discussion with family, carers and the patient (if possible).
What are the limitations of furloughing staff for publicly funded organisations?

The guidance from the Government concerning private sector organisations is very different from the guidance for public sector and organisations that receive public funding. The guidance states:

“The government expects that the scheme will not be used by many public sector organisations, as the majority of public sector employees are continuing to provide essential public services or contribute to the response to the coronavirus outbreak.

Where employers receive public funding for staff costs, and that funding is continuing, we expect employers to use that money to continue to pay staff in the usual fashion – and correspondingly not furlough them. This also applies to non-public sector employers who receive public funding for staff costs. Organisations who are receiving public funding specifically to provide services necessary to respond to Covid-19 are not expected to furlough staff.”

This guidance isn’t particularly clear but it appears that there is a recognition that there are different types of organisations which could be caught by this:

  1. Organisations who will be required to provide frontline services during the Covid-19 response. It is interpreted that NHS organisations such as NHS Trusts will fall firmly into this category. Employees of such organisations are expected not to be furloughed and to continue to work and be paid their normal salary in the usual way.
  2. Organisations who receive public funding to provide services to respond to the Covid-19 crisis. These organisations are not expected to furlough their staff. The type of organisation that would fit into this category are those that have been commissioned to developing breathing apparatus or testing kits to meet the needs of the healthcare sector during the peak of the pandemic.
  3. Organisations who receive public funds for staff costs to operate services. Employers are expected to continue to pay staff if the money to pay them is publicly funded. It is strongly inferred that this is irrespective of whether such staff have any work to perform. The type of organisation that is likely to fall into this category are GP practices, charities and private sector companies that have won contracts with the public sector.
What will be the impact of the proposals on suppliers?

The change in the law has the potential to place much greater financial risks on suppliers, making it more difficult to exit a contract with a customer of doubtful solvency.  This will place increased emphasis on appropriate financial due diligence and credit checking before entering into supply contracts.

In addition to the obvious issues around financial risk, suppliers will also need to think carefully about how their contracts are drafted.  For example, any form of right that is drafted so as to be triggered on customer insolvency will clearly be problematic.  These could include:

  • Retention of Title provisions, which are commonly drafted so that the right to enter premises and retake possession of the goods is triggered on insolvency;
  • Provisions for brand protection, which seek to control how goods are dealt with on termination of the contract.

This is potentially a very significant development for many businesses.  We would strongly recommend specialist advice be obtained so that:

  • businesses understand the potential increased risks faced; and
  • where possible, contracts are updated so that appropriate protections are maintained.