How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
As an occupier of premises, you owe a duty of care to your visitors to take reasonable care to see that the visitor will be reasonably safe in using your premises.
It is therefore essential that you are taking reasonable steps and strictly adhering to up-to-date Government advice in all aspects of your business to avoid any potential liability.
Failure to follow Government advice could leave you vulnerable to claims for compensation for pain and suffering should a visitor on your premises contract Covid-19.
However, each case will be fact-specific and it would be very difficult for a visitor to establish that they contracted Covid-19 specifically from those premises (as opposed to being exposed to the virus anywhere else).
If someone suggests that they are going to make a claim make sure that you report matters to your insurer or insurance broker immediately.
Damien Charlton, Julie Huntingdon and Chris Hugill look at the SRA Standards and Regulations (STaRS) for solicitors which came into effect late 2019, and represented a whole new regulatory landscape for the legal profession. The enhanced reporting and transparency obligations have an important impact on in-house practice, so this webinar gives you the opportunity to reflect on how the new rules impact on in-house lawyers, in both your professional and personal lives.
This webinar is part of a series designed for in-house lawyers. If you would like to register to receive invitations to future events for in-house legal counsel, please email damien.charlton@wardhadaway.com.
The General Medical Council (GMC) have published guidance online for doctors during this time of uncertainty.
Alongside this, their website displays guidance for temporary registration to approximately 15,000 doctors, who left the register or gave up their licence to practise in the last three years.
These clinicians have been contacted to assist with the growing pandemic, outlining the process they would follow and informing them of their right to opt-out. The Secretary of State for Health can ask the GMC to grant such registration under Section 18a of the Medical Act 1983, in an emergency.
Hosted by The North East England Chamber of Commerce, this webinar discussed practical advice on Covid-19 and the specific challenges for International Trade.
Partner Damien Charlton along with Andrew Needham,from Haines Watts and Grant Murray from XE Finance, provided an update on the challenges and potential solutions in their field, as well as a look forward for the “New Normal”.
To watch the full recording, please click here or to view the slides, please click here.
On 18 March 2020, the Government announced that it would pass emergency legislation which would prevent landlords, both social and private, from bringing possession proceedings against tenants who are unable to pay their rent. The Housing Secretary, Robert Jenrick, stated that “no renter who has lost income due to coronavirus will be forced out of their home, nor will any landlord face unmanageable debts.”
The announcement came after several organisations, including housing charity Shelter, expressed concerns that more than 50,000 households could face possession proceedings due to the economic uncertainty following the Covid-19 outbreak.