Skip to content

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

Related FAQs

My planning permission is due to expire, can I extend the period for implementation?

The Government announced on 22 June 2020 that it would be making provisions to enable planning permissions that have lapsed since 23 March 2020, and those that are due to lapse before the end of 2020, to be automatically extended.
The Government’s detailed proposals are set out in section 17 of the Business and Planning Act 2020, which entered the statute books on 22 July 2020. If a relevant planning permission is subject to a condition which requires the development to be begun no later than between 19 August 2020 (when section 17 of the Business and Planning Act 2020 will come into effect) and 31 December 2020, the condition is automatically deemed to instead provide that the development must be begun no later than 1 May 2021.

The Act also makes provision for any conditions requiring development to be begun between 23 March 2020 and 19 August 20202 to be extended to 1 May 2021, although this is not automatic. Where the provisions have such retrospective effect, an application is required to the local planning authority. The local planning authority are only able to grant approval, however, if they are satisfied that any EIA and habitats assessments continue to be valid. Deemed approval provisions will apply if the local planning authority do not determine any application within 28 days. The local planning authority are not able to approve such applications after 31 December 2020 so applications should be made in good time in advance of this date. There is the possibility of an appeal against the local planning authority’s decision but notice of the appeal must be submitted before 31 December 2020.

The Act includes similar provisions in relation to both detailed and outline planning permissions.

VIDEO: In conversation with cashflow.co.uk expert Chris Silverwood about CBILS

Partner at Ward Hadaway Adrian Ballam talks to corporate finance expert and CBILS specialist Chris Silverwood (CorpFin and cashflow.co.uk) to explore the practical ins, outs, dos and don’ts of CBILS applications, answering the questions:

  1. How are banks making their assessments of whether a business can afford a CBILS loan when for many they cannot accurately forecast their revenues for at least the next three months?
  2. What are the red flags that banks are looking for when assessing whether or not to grant a request for a CBILS loan?
  3. What cost mitigation measures should a business have already implemented prior to applying for a CBILS loan?
  4. What level of information should a business provide to support a CBILS application?
  5. What common mistakes are businesses making when applying for funding?
  6. What general tips do you have for businesses seeking CBILS funding?

Click read more to view the video.

Given the recent decline in financial performance, the business is now in breach of its covenants with the bank. Should we be concerned?

That will depend on the terms of your facility and the stance taken by your bank.

Banking facilities often place obligations on businesses to stick to certain financial criteria. For example, an obligation to keep turnover or profit above certain levels or a commitment to keep the bank’s exposure within an agreed percentage of the value of the company’s assets (known as loan to value ratio).

The consequences of breaching those covenants will depend on the terms of your facility, but normally this amounts to an event of default. Events of default can result in the loan (or whatever form the facility takes) becoming repayable and could give the bank certain powers to take action to recover the money that they are owed.

Whether the bank will take action during these unprecedented times is another matter, particularly given the extent of support being offered to businesses via mainstream lenders and the political desire to keep viable businesses up and running. Lenders themselves will no doubt wish to remain supportive where possible. The underlying performance of the business (and whether but for the effects of Covid-19 it would have been in a healthy financial position), the relationship you have with the bank and your history with them will no doubt be relevant to the approach taken by the bank. However, early engagement with your bank (as well as other key stakeholders in the business) will be important.

Are all employees required to stay at home?

No, where employees cannot work from home, and it is safe for them to return to work, they should do so.

What payments can be included in the claim for a grant?

You can claim for regular payments you are obliged to pay staff such as non-discretionary overtime, non-discretionary fees, non-discretionary commission and piece-time payments. Overtime in this context is referred to as ‘past overtime’ in the updated guidance which would suggest that you should use the variable pay calculation (see FAQ above) for those who regularly carry out overtime.