Skip to content

Should I have a homeworking policy?

If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:

  • If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
  • Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
  • Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
  • Ensuring staff lock their devices whenever they are not using them
  • Where possible, working in a separate part of the home to family members
  • Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
  • Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
  • Locking any papers in a safe place
  • Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
  • Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
  • Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
  • Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example

Organisations should also ensure that their remote access systems can cope with increased demand.

Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.

We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.

Related FAQs

What are the negatives associated with having MHFAs in the workplace and what is the best way to manage this without removing MHFAs from the company?

The only potential negatives are the potential for MHFAs to become overloaded, or for MHFAs to overstep the boundaries of their role. Both would be avoided if a suitable framework is in place around them, and if adequate ongoing support and training is provided.

Will I need to make an application to the court for a remote hearing?

Despite remote hearings being the default position at present, formal permission will still be required by the court and a template order was circulated with the guidance. This template sets out the relevant directions and recitals to include in your order. An application to the COP for a remote hearing will not be required.

Can I demand that my employees have the vaccine?

In most circumstances the answer will be no. It would be an infringement of their human rights. It could also be a criminal assault.

However where there is a high risk to employees of exposure to COVID-19, such as care homes and healthcare environments, you might be able to make it a requirement of their role to have the vaccine.

First, consider whether you need to have a blanket requirement covering all employees or whether only certain groups who work in the most high risk areas require the vaccine.

You will need to do a thorough risk assessment balancing the amount that the risk of exposure would be reduced against the interference with the employee’s human rights. Consideration will need to be given as to whether insisting on the vaccine is proportionate to the risk and whether other less invasive steps could be taken instead, such as maintaining social distancing, wearing a mask, washing hands.

Any requirement for employees to be vaccinated should be communicated clearly to employees and trade unions together with a clear explanation for why it is necessary.

What further proposals has the Government made in relation to Public Companies?

It has also been proposed in the Corporate Insolvency and Governance Bill that public companies who were due to file their accounts in the period from 26 March 2020 to 30 September 2020 will have until the earlier of the 30 September 2020 and the date which is 12 months after the end of their relevant accounting period to do this.

This is separate from the pre-existing scheme, announced on 25 March 2020, whereby companies can apply to Companies House for a 3 month extension for filing their accounts.

What is classed as a good ratio of MHFA to staff numbers?

There is not a magic number. It depends on the nature of the organisation, the work carried out, the organisational structure, the geographical spread, working patterns and conditions. We would give specific advice personalised to the organisation and taking all these and other factors in to consideration. There is no such things as too many MHFAs!