If an employee has had a coronavirus test, can we require them to disclose evidence of their test results?
Obtaining an employee’s Covid-19 test result will amount to processing personal data for the purposes of the General Data Protection Regulation 2016/679 (GDPR) and information about an employee’s health is a special category of data (sensitive personal data under the Data Processing Act 2018 (DPA)).
In accordance with the GDPR and DPA, there must be lawful grounds for processing such information. Most employers rely on employees’ consent to obtain medical information and process sensitive personal data and if the employee is unwilling to give consent, you will not normally be entitled to the information.
Special category data can be processed lawfully if it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. Employers may be able to require an employee to disclose their Covid-19 test if there is a substantial public interest, such as ensuring that the employee self-isolate if they have a positive test. However, there is a risk that this measure could be considered disproportionate particularly if it is enforced on all employees as a blanket measure.
Related FAQs
Some employers falling into the third group of organisations described above could understandably feel aggrieved that on the first reading of the guidance they are not able to furlough employees and rely on the Government scheme. Many publicly funded organisations that are not public sector employers, receive a package of public funding with little expectation on how that funding is used or applied, other than broadly for it to be used in providing the services it is contracted to deliver. Also, several publicly funded organisations have many different income streams and the element of funding that is received from the public purse can be only an element of their operating costs.
Unfortunately there is still no clear guidance on when employers falling into the third category identified above can use the scheme. The only reference in the guidance on this states that where organisations are not “primarily funded” from the public purse and whose staff cannot be redeployed to assist with the coronavirus response, the scheme might be appropriate to be used for some staff. This seems to suggest that where an employing organisation is not wholly or mainly funded by public funding and staff cannot be redeployed to work in areas in the effort to combat coronavirus, then it would be appropriate for the employer to access the scheme.
If considering applying for grants under the scheme a sensible approach would be to look at the combined total of your public funding and payments under the scheme and make sure it will not represent more than 100% of the level of total income you would have expected to receive during this period in a non-Covid scenario.
Local Authorities are expected to maintain support to suppliers and this should be considered:
Data on properties, and people, has never been more important.
Given that compliance is at risk here, such a decision must be made by the Board to ensure good governance. Board approval should be sought and recorded for the approach the organisation is taking.
It is essential that you continue to record your data on compliance and report to your board at all times, and that there is a clear audit trail for issues with access, and if appropriate to the Regulator. Access issues as a result of self-isolation should be readily identifiable.
Operatives need to be provided with the tools to operate in as safe a way as possible:
- Checklist of questions to ascertain occupant’s current health
- Protective equipment (masks, gloves, over clothing)
The Gas Safe website is a useful resource for updates: https://www.gassaferegister.co.uk/help-and-advice/covid-19-advice-and-guidance/
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Yes, if there is a contractual right to do so. Furloughed employees who start work with another employer during this time must inform HMRC that they have another job.
Potentially, yes. If someone refuses to follow the health and safety measures that have been put in place to protect them, colleagues and possibly their customers, including (where appropriate) the use of PPE then this is a disciplinary issue and should be dealt with as such. Repeated failure to comply with the requirement to follow these measures, or a one off significant failure, may be sufficient to justify dismissal, depending on the circumstances.