How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
The Thriving at Work Report and the recent NICE Workplace Mental Health Guidelines provide a good baseline for what all organisations should be doing on workplace mental health – this includes some guidance on training. There does need to be a plan in place and we recommend taking a holistic view of the integration of mental health first aiders into a business – ie it should be one component in a strategy that also comprises training for line managers, awareness training and education for all staff, peer support, and a documented framework for support and signposting. It is also worth ensuring you have senior manager sponsorship, strong links with Occupational Health if available and also raising awareness via any works councils or employee forums helps ensure there is buy in at all levels.
Individual contractors who are not operating via an intermediary (eg sole traders) do not need to be assessed under IR35. However, you will always have the risk with those individuals that there is no intermediary – therefore if their tax status is wrong, HMRC are very likely to consider that responsibility for this would fall on the hiring company in any event.
This is a concern for many businesses at the moment.
Firstly, the directors need to be mindful of their duties to creditors . Click here for further information on those duties and the measures introduced by the government to help support directors during these difficult times.
There is also a raft of funding and grants as well as commercial finance that might be available to you. Click here for further information or contact us if you would like to discuss further.
If you are coming under increasing creditor pressure, there are other options to explore like the new “moratorium” procedure, which allows viable businesses in financial difficulty to work with an insolvency practitioner to obtain at least 20 business days’ breathing space from creditors to allow the business to formulate a plan to deal with its financial problems.
If you have any concerns about the viability of your business you should speak to your advisors, whether that is your lawyers, accountants or an insolvency practitioner who should be able to help you.
If you consider the factors used to determine status you can include the following terms that are more in line with a self-employed relationship:
- The right to provide a substitute of the contractor’s choice in the event the individual is not able to perform the services;
- The ability to work for other businesses as long as doing so will not affect the services to be provided by the contractor;
- The contractor should have sufficient control over how, when and where (if possible) they provide the services;
- A degree of financial risk can be included for unsatisfactory work or failing to complete a project or task
We have terms that cover all of these points that can be tailored to your needs. The consultancy agreement is included in our IR35 toolkit.
Business operators such as travel operators, hotels and restaurants remain vulnerable to claims of failure to protect against contracting the virus. There is a high chance of claims from employees, clients and members of the public. These are likely to be covered under public liability and employer’s liability insurance.