If, after deploying all control measures the risk is still deemed too great for employees to work safely, then what should employers do?
The law says that if after assessing a risk and considering all the control measures available to you, you cannot undertake a task safely – then you should not undertake the task.
If that means taking BAME workers out of higher risk frontline work, that is what will have to be done.
Beware of workers saying “we’ll accept the risk” – it does not protect you against regulatory/enforcement action or civil claims.
Related FAQs
The NHS Test and Trace service is operated by the NHS in England to track and help prevent the spread of COVID-19. Where an individual displays symptoms of coronavirus they can be tested to determine whether or not they have the disease. Those with the disease will then be contacted by NHS contact tracers and asked who they have come into close contract with.
Close contact is defined as:
- Face to face (within 1 metre)
- Spent more than 15 minutes within 2 metres of another person
- Travelled in a car or on a plane with another person
The contact tracer will then contact those people with whom the individual has come into close contact and tell them to self-isolate for 14 days.
The parties to litigation should still take the steps they have been ordered to take and comply with any Orders made by the court. If for any reason it looks as if a direction cannot be complied with because of the Covid-19 virus then an extension of time can be agreed with the other party (up to 28 days) or through the court. We are aware that Orders have been made extending the time for certain steps to be taken by 56 days.
If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:
- If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
- Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
- Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
- Ensuring staff lock their devices whenever they are not using them
- Where possible, working in a separate part of the home to family members
- Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
- Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
- Locking any papers in a safe place
- Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
- Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
- Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
- Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example
Organisations should also ensure that their remote access systems can cope with increased demand.
Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.
We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.
For the purposes of collective consultation, making someone redundant and/or changing terms and conditions of employment, by termination and re-engagement, is also classed as a dismissal by reason of redundancy and so has the exact same consultation requirements.
The vast majority of disputes settle without ever reaching a final hearing with something in the region of 2-5% of all cases actually ending up in court at a final trial. So whilst it is very unlikely you would need to attend a court hearing, it is always a possibility.