How should an employer handle personal information in relation to NHS Test and Trace?
Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.
- Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
- Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
- Only use the information for the purpose of managing the workforce during the pandemic.
- Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
- Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
- Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
- Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
- Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
- Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
- All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.
If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.
** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.
Related FAQs
Many policies will only provide business interruption cover if it arises from property damage. The FCA has acknowledged that insurers are entitled to reject claims in relation to such policies, notwithstanding the success of the FCA’s test case in the Supreme Court, and which was generally favourable to policyholders [Insert a link here to our update on the test case]. In other cases the policy wording will be less clear and businesses may legitimately feel that their insurer is wrongly withholding payment.
One route of challenge to an insurer’s decision is via one of the well-publicised class actions. Another route of challenge is by a complaint to the Financial Ombudsman Service (FOS). This service is open to consumers and small and medium-sized businesses, ‘micro-enterprises’, charities and trusts. The service will be an attractive option for many businesses, as it is free and relatively quick (although it remains to be seen how the service keeps up with an increase in demand as a result of the pandemic). You will need to have complained to your insurer before bringing a complaint with the FOS.
Further details can be found here.
The Office of the Public Guardian is continuing to accept applications to register Lasting Powers of Attorney but their usual estimated timescale of eight to ten weeks is likely to be affected by the current situation.
Consequently, an alternative or interim measure if you need something quickly is to execute a General Power of Attorney to authorise someone to act as your Attorney to undertake day to day financial transactions for you. The General Power of Appointment only needs to be executed by you in the presence of a witness (not the Attorney) to be valid and does not need to be registered with the Court of Protection. However, the Power of Attorney would cease to have effect if you become incapable of managing your affairs. It should be seen as a stop-gap only.
The Government assured parity for the self-employed but it has since accepted that this would be difficult to achieve. The Association of Independent Professionals and the Self-Employed (IPSE) has worked closely with the Government on implementing the current self-employment income support scheme. IPSE has confirmed that it will continue to work on helping to extend measures to all freelancers in need as a result of Covid-19.
The Government announced an extension to the Self-Employment Income Support Scheme from 1 November 2020.
The FCA’s test case in the Supreme Court ruled overwhelmingly in favour of policyholders. However, business interruption cover generally has the prerequisite of physical damage or loss to the property (or in some circumstances, the presence of a notifiable disease at the property or within a certain radius of it), to recover losses caused by the interruption to your business. The onus is on insurers to re-assess those claims which are impacted by the Supreme Court’s judgment and to make contact with the policyholders regarding next steps. If you have not already made a claim, in the first instance the terms of any policy should be checked carefully to see whether business interruption cover is provided.
All employers have a duty to prevent illegal working, and carrying out proper Right to Work checks are a fundamental part of this. In light of Covid-19, the Home Office has brought in some temporary measures for employers to use to carry out the requisite Right to Work checks. Failure to follow these could lead to enforcement action and penalties.