How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
Employees who are union or non-union representatives may undertake duties and activities for the purpose of individual or collective representation of employees or other workers. However in doing this, they must not provide services to or generate revenue for, or on behalf of your organisation or a linked or associated organisation.
Employees who are pension scheme trustees or trustee directors of a corporate trustee may also undertake trustee duties in relation to the pension scheme. However, a professional, independent pension scheme trustee who has been furloughed by the independent trustee company cannot undertake trustee work that would provide services to or generate revenue for, or on behalf of, the independent trustee company or any organisation linked or associated with that independent trustee company during hours when they are recorded as being on furlough.
Read more about this
Employees on any type of employment contract including full-time, part-time, agency, flexible or zero hours and foreign nationals who are eligible to work in the UK on any visa can be furloughed subject to the following excluded categories:
- Anyone who was not employed prior to 30 October 2020
- Anyone for whom you haven’t made a PAYE Real Time Information submission to HMRC between 20 March 2020 and 30 October 2020.
- Employees who are working but on reduced hours or for reduced pay
- Employees currently receiving SSP (see FAQ on SSP and self-isolation below)
- Public sector employees
- Employees of businesses or organisations in receipt of public funding for staff costs (except for those who are not primarily funded by the government and whose staff cannot be redeployed to assist with the Covid-19 response)
From 1 July 2020 the furlough scheme has been operating more flexibly.
The key changes from 1 July 2020 were:
- All furloughed employees are subject to the new flexible furlough rules and the new basis for calculating claims
- Furloughed employees can be brought back to work on a part-time basis for any amount of time and can work any work pattern
- Employers can claim for the hours not worked compared the hours the person would normally have worked in that period
- There must be a new written furlough agreement in place to record the agreement with the furloughed employee to return to work part-time
- The new agreement (including a collective agreement) must be made before any period of flexible furlough begins but it may be varied at a later stage if necessary. The agreement must be incorporated into the employee’s contract of employment, either expressly or impliedly
- Employers must keep a record of this agreement until at least 30 June 2025, and they must also keep a record of the hours the furlough employee worked and the hours that they were furloughed
- Employees can be furloughed from 1 July 2020 for any amount of time and more than once
- However, if you re-furloughed an employee after 10 June but before 1 July 2020, they had to be furloughed for an initial period of three consecutive weeks
- Claims for payments under the scheme must not cross calendar months so if you are claiming for the initial three week period of a re-furloughed employee who was furloughed on 12 June for example, you must submit separate claims for the dates in June and July
- Although flexible furlough agreements can last any length of time, you should only submit a claim to HMRC once a week.
The amount an insurer charges for providing cover is a critical aspect of the underwriting process. The premium must be sufficient to cover expected claims but must also take into account the possibility that the insurer will have to access its capital reserve –it is risk assessment based and the greater the risk, the higher the premium. Historically, insurers of high-rise buildings would have only had to prepare for a loss caused by damage to just a few flats within a building. That is because the design and construction of that building, with the right materials and fire safety provisions in place, should have limited the spread of fire and allowed the damage to be contained –or at least make this an extremely low risk. Now we know that many buildings have been designed, built and signed off in a regulatory system that an independent Government review has found was not fit for purpose. Premiums will reduce overtime but will be dependent upon the perceived level of risk reducing as the regulatory regime, BSA and BSR become more established.
Read more about thisAside from the CBILS Scheme, the Government have, or are in the process of, implementing several different schemes to support businesses financially through the Covid-19 outbreak.
Read more about this