How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
Potentially. The first question is why the person is not able to return, as their individual circumstances will be very relevant in terms of whether they can be safely dismissed.
Employers should ask themselves 2 questions in this situation:
- Have I done everything I am required to do in order to make the workplace safe for the individual to return; and
- Is what the employee saying reasonable?
If the answer to question 1. is no then a dismissal is unlikely to be fair. However, even if the answer to question 1. is yes, then there is still question 2. to address. If the employee has reasonable grounds as to why they are unable to return to work, e.g. due to health issues, childcare responsibilities etc then the dismissal is unlikely to be fair. It is only if you can answer yes to question 1. and no to question 2. that you can have some confidence in the potential safety of the dismissal.
Dismissals based on objections to returning to work on health and safety grounds will very often be risky and are highly fact specific, therefore please contact one of the employment team for further advice prior to dismissal.
CMA guidance suggests that it will not take enforcement action in respect of agreements which:
- Are appropriate and necessary to avoid a shortage, or ensure security, of supply
- Are clearly in the public interest
- Contribute to the benefit or wellbeing of consumers
- Deal with critical issues that arise as a result of the Covid-19 pandemic
- Last no longer than is necessary to deal with these critical issues
The Thriving at Work Report and the recent NICE Workplace Mental Health Guidelines provide a good baseline for what all organisations should be doing on workplace mental health – this includes some guidance on training. There does need to be a plan in place and we recommend taking a holistic view of the integration of mental health first aiders into a business – ie it should be one component in a strategy that also comprises training for line managers, awareness training and education for all staff, peer support, and a documented framework for support and signposting. It is also worth ensuring you have senior manager sponsorship, strong links with Occupational Health if available and also raising awareness via any works councils or employee forums helps ensure there is buy in at all levels.
Government guidance is that public transport should be avoided wherever possible. Transport providers will be expected to follow government guidance to make their services more COVID-19 secure.
The Government guidance does not require any business to close except some non-essential shops and public venues, so in theory, all businesses can continue to occupy and operate from their existing premises. However, government guidance strongly encourages businesses to arrange for everybody able to work from home to do so. The majority of office sector business will fall into this category.
In the industrial sector, the majority of businesses will not be able to operate via home working and will, therefore, need to retain employees on site though in some cases this may be able to be scaled back.
Any tenants continuing to operate from their premises should consider whether or not they need to make any alterations to the premises to facilitate social distancing of employees and whether or not such works would require a consent from the Landlord under the terms of the lease.