Should I have a homeworking policy?
If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:
- If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
- Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
- Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
- Ensuring staff lock their devices whenever they are not using them
- Where possible, working in a separate part of the home to family members
- Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
- Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
- Locking any papers in a safe place
- Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
- Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
- Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
- Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example
Organisations should also ensure that their remote access systems can cope with increased demand.
Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.
We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.
Related FAQs
The Government announced on 22 June 2020 that it would be making provisions to enable planning permissions that have lapsed since 23 March 2020, and those that are due to lapse before the end of 2020, to be automatically extended.
The Government’s detailed proposals are set out in section 17 of the Business and Planning Act 2020, which entered the statute books on 22 July 2020. If a relevant planning permission is subject to a condition which requires the development to be begun no later than between 19 August 2020 (when section 17 of the Business and Planning Act 2020 will come into effect) and 31 December 2020, the condition is automatically deemed to instead provide that the development must be begun no later than 1 May 2021.
The Act also makes provision for any conditions requiring development to be begun between 23 March 2020 and 19 August 20202 to be extended to 1 May 2021, although this is not automatic. Where the provisions have such retrospective effect, an application is required to the local planning authority. The local planning authority are only able to grant approval, however, if they are satisfied that any EIA and habitats assessments continue to be valid. Deemed approval provisions will apply if the local planning authority do not determine any application within 28 days. The local planning authority are not able to approve such applications after 31 December 2020 so applications should be made in good time in advance of this date. There is the possibility of an appeal against the local planning authority’s decision but notice of the appeal must be submitted before 31 December 2020.
The Act includes similar provisions in relation to both detailed and outline planning permissions.
The reality of these unprecedented times is that enforcement of health and safety legislation by the HSE (particularly through the criminal courts) in relation to Covid-19 is an extremely unlikely outcome.
Solicitors can be authorised to sign contracts for their clients – a signed letter of authority should be scanned and sent to avoid posting potentially contaminated documents.
Solicitors should exchange supplemental agreements on behalf of their clients to agree to postpone exchange and completion dates if it has been agreed to push these back.
The Law Society advises that electronic signatures be used as much as possible for contracts, to avoid possible contamination. However, the Land Registry confirms that the legal transfer document cannot be validly executed with an electronic signature. Solicitors should agree a completion undertaking that the original transfer document will be sent when received and after the restrictions have been lifted.
The Land Registry’s latest guidance https://www.gov.uk/guidance/coronavirus-covid-19-impact-on-hm-land-registrys-services published on 14 May states:
We accept deeds that have been signed using the ‘Mercury signing approach’.
For land registration purposes, a signature page will need to be signed in pen and witnessed in person (not by a video call). The signature will then need to be captured, with a scanner or a camera, to produce a PDF, JPEG or other suitable copy of the signed signature page. Each party sends a single email to their conveyancer to which is attached the final agreed copy of the document and the copy of the signed signature page.
Solicitors should be willing to adopt this procedure for completing transactions to enable them to be registered by the Land Registry.
The execution of a transfer is a deed and must be witnessed. Members of the family can witness signatures so long as they are not also a party to the document. A witness will be more credible if they are 18 or over, but this is not a legal requirement. The legal requirement is for the witness “to be present” when the document is signed. It would be possible for a witness to be on the other side of the room or the other side of a window, and validly witness the execution of a deed. The witness does need to take precautions to avoid possible contamination from the document.
A statutory declaration does not need to be witnessed but must be administered by a solicitor or commissioner for oaths. There is no legally prescribed process for this, and there is nothing to suggest that this could not be validly done via a video telephone call if the signature on the declaration can clearly be seen by the person commissioning the oath when the oath is made.
On 4 May 2020, the Government launched the Bounce Back Loan Scheme (BBLS), which is intended to cut red tape to enable smaller businesses to access finance quickly during the coronavirus outbreak.
The scheme helps small and medium-sized businesses to borrow between £2,000 and up to 25% of their turnover. The maximum loan available is £50,000.
The government guarantees 100% of the loan and there are no any fees or interest to pay for the first 12 months. After 12 months the interest rate will be 2.5% a year.
The length of the loan is 6 years, but it can be repaid early without penalty. No repayments will be due during the first 12 months.
Under the scheme, lenders are not permitted to take any form of personal guarantee or take recovery action over a borrower’s personal assets (such as their main home or personal vehicle).
Businesses can apply for a BBLS loan if it:
- is based in the UK
- was established before 1 March 2020, and
- has been adversely impacted by the coronavirus.
Any business regarded as being a business in difficulty on 31 December 2019 will need to confirm that it is complying with additional state aid restrictions.
Businesses from any sector can apply, except the following:
- banks, insurers and reinsurers (but not insurance brokers)
- public-sector bodies, and
- state-funded primary and secondary schools.
Businesses already claiming under the following schemes cannot apply although it is possible to convert an existing loan under such schemes into BBLS:
- Coronavirus Business Interruption Loan Scheme (CBILS)
- Coronavirus Large Business Interruption Loan Scheme (CLBILS)
- COVID-19 Corporate Financing Facility.
There are 11 lenders participating in the scheme including many of the main retail banks, which are listed on the British Business Bank’s website (www.british-business-bank.co.uk/ourpartners/coronavirus-business-interruption-loan-schemes/bounce-back-loans/for-businesses-and-advisors/). Applicants are directed to approach a suitable lender via the lender’s website. If an applicant is declined by a lender, they can apply to other lenders in the scheme.
The lender will ask applicants to fill in a short online application form and self-declare that they are eligible. All lending decisions remain fully delegated to the accredited lenders.
Transparency is considered to be central to the philosophy of the COP. The guidance provides details on issues concerning transparency of proceedings and involvement/attendance of P. Whilst there will be some difficulties with ensuring that remote hearings are accessible to the public as an ‘open court’, provisions have been made for the continued presence of the press where the facilities can accommodate this.