Skip to content

Should I have a homeworking policy?

If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:

  • If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
  • Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
  • Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
  • Ensuring staff lock their devices whenever they are not using them
  • Where possible, working in a separate part of the home to family members
  • Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
  • Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
  • Locking any papers in a safe place
  • Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
  • Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
  • Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
  • Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example

Organisations should also ensure that their remote access systems can cope with increased demand.

Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.

We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.

Related FAQs

If a member of staff does not inform me that they ought to be self-isolating will I still be liable for a fine?

Potentially no.

If an employer is not put on notice that the circumstances of a worker or agency worker are such that they ought to be self-isolating, by either the worker or agency worker themselves or another member of staff, then there ought to be a reasonable excuse, and potentially, no fixed penalty notice will be issued.

Which agreements will qualify for exemption?

There are four criteria which must be satisfied if an agreement is to be considered exempt:

  • It must improve production or distribution, or promoting technical or economic progress – the guidance suggests that cooperation ensuring essential goods and services can be made available to the public, or an important sub-set of the public such as key workers, will satisfy this criterion.
  • It must allow consumers a fair share of the resulting benefit – the guidance suggests this will be the case where the action prevents or reduces shortages.
  • It must not impose on the undertakings concerned restrictions which are not indispensable to the attainment of the above benefits – the guidance suggests this will be the case where the cooperation is the only reasonable option due to the urgency of the crisis and where the cooperation is temporary in nature.
  • It must not afford the undertakings concerned the possibility of eliminating competition – therefore the parties must endeavour to retain competition in respect of the products (in particular price competition).
What is the NHS coronavirus Test and Trace scheme and how does it work?

The NHS Test and Trace service is operated by the NHS in England to track and help prevent the spread of COVID-19. Where an individual displays symptoms of coronavirus they can be tested to determine whether or not they have the disease. Those with the disease will then be contacted by NHS contact tracers and asked who they have come into close contract with.
Close contact is defined as:

  • Face to face (within 1 metre)
  • Spent more than 15 minutes within 2 metres of another person
  • Travelled in a car or on a plane with another person

The contact tracer will then contact those people with whom the individual has come into close contact and tell them to self-isolate for 14 days.

What about someone who refuses because they are against the vaccine (the anti-vaxers)?

It is a theoretical possibility that “anti-vax” beliefs could be a philosophical belief under the Equality Act 2010 and therefore anti-vaxers have the right not to be discriminated against for their beliefs. Much will depend on why the individual is against the vaccine. Conspiracy theorists (the vaccine is being used as an opportunity to monitor you or it’s all because of 5G) are highly unlikely to be treated as having a philosophical belief!

Can a Charity use its restricted funds for its general funding in the current circumstances?

Many charities have money that are considered restricted funds which are given to the charity or raised for a specific purpose.  The Charity Commission gives guidance on this, please see the link below. Depending on the circumstances in which these monies have been given to a charity or raised you may or may not be able to use them.

Monies raised in an appeal or specific fund raising campaign are unlikely to be available as it is likely to be impossible to get the permission of the donor to change the use.  If however you have had monies donated for a specific purpose and you can identify the donor you can use these funds for general overheads and to pay wages etc. if you receive the donor’s specific permission to do so.