Skip to content

Should I have a homeworking policy?

If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:

  • If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
  • Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
  • Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
  • Ensuring staff lock their devices whenever they are not using them
  • Where possible, working in a separate part of the home to family members
  • Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
  • Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
  • Locking any papers in a safe place
  • Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
  • Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
  • Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
  • Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example

Organisations should also ensure that their remote access systems can cope with increased demand.

Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.

We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.

Related FAQs

As an employer, can I force employees to wear face masks at work?

An employer has a duty of care to its workforce and must take reasonable precautions to protect the health and safety of employees. Employers also have a duty of care towards anyone entering or using their place of business, such as visiting clients or customers.

This means that if an employer reasonably believes that wearing face masks at work is appropriate and necessary, it can issue an instruction to employees to this effect and employees should abide by this as far as possible.

However employers should be cautious about introducing and enforcing a policy across its business which requires its staff to wear face masks as there is the risk of unlawfully discriminating against people who are exempt from wearing face coverings or have legitimate reasons for not doing so. An employer should also consider the duty to make reasonable adjustments for disabled employees and discuss any concerns raised by employees who do not want to or feel unable to wear a mask.

What are the key questions to ask ourselves as a business?

Some examples of the key questions to ask include:

  • Is there still a viable underlying business that is likely to continue beyond the current crisis?
  • What does the revised short to medium cash flow look like and will the company continue to be able to pay its liabilities?
  • Does the company have the support of all of its stakeholders – lenders, shareholders, customers, suppliers and banks – even though the business might be in breach of its own obligations?
  • What measures could (and should) the board put in place to protect creditors, including making sure that exposure to creditors (both collectively and individually) is not increased, assets are not sold at less than value and no creditor is treated more favourably than another?
  • Is there still a reasonable prospect of the business avoiding liquidation or administration?

The key question is always whether accepting the money is in the best interests of creditors as a whole bearing in mind that accepting Government support and continuing to trade might increase the company’s overall liabilities. Directors should be mindful that if the business fails, their decisions during this critical time may be scrutinised and it is therefore important that directors have up-to-date financial information and projections to form the basis of any decisions, take stock, get the right advice and document the decisions that are taken.

Who is eligible for CBILS?

To be eligible for CBILS, the British Business Bank has confirmed that businesses should be able to answer YES to the following points:

  • Your application must be for business purposes
  • You must be a UK-based SME with an annual turnover of up to £45m. This includes sole traders, freelances, body corporates, limited partnerships and limited liability partnerships. For sole traders to be eligible it is expected that sole traders will need to have a business account with its funders and not be operating via a personal account
  • Your business must generate more than 50% of its turnover from trading activity
  • Your CBILS-backed facility will be used to support primarily trading in the UK
  • You wish to borrow up to a maximum of £5m.

Businesses meeting these criteria from all sectors can apply save for Banks, Building Societies, Insurers and Reinsurers (but not insurance brokers), the public sector including state-funded primary and secondary schools, employer, professional, religious or political membership organisation or trade unions which are not eligible.

Your borrowing proposals must be considered viable by the relevant lender under normal circumstances aside from the Covid-19 outbreak, and the lender believes the provision of finance will enable the business to trade out of any short-to-medium term difficulty. Lending decisions are delegated to the accredited lenders and lenders will need further information to confirm eligibility.

The eligibility criteria for CBILS does not require lenders to take into account other forms of Government support that SME’s may already be benefiting from, most notably business rate relief.

We understand that ownership structure is not taken into account when confirming eligibility and that businesses back by a PE funder or a subsidiary of an overseas entity can be eligible if it meets the other criteria.

An update on eligibility – 3 April 2020

Previously, for facilities above £250,000, the lender must establish a lack or absence of security prior to businesses using the Scheme. The requirement for insufficient collateral has been removed allowing those SMEs who are considered to have sufficient collateral to access the Scheme. We would expect that where security is available, a lender will seek to take security over the relevant assets.

Can NHS or local authority workers be furloughed?

It is envisaged that employees of organisations falling into the first two categories set out above and won’t be eligible for the job retention scheme in relation to the majority of their employees. It is envisaged that NHS Trusts for example are going to require their staff to be working at full capacity where possible. However, the guidance doesn’t definitely exclude public sector organisations from furloughing employees and notably the government expects such organisations to use public money to continue to pay staff and not furlough them, rather than say requires. In reality, it is difficult to see how such an organisation will be able to rely on the scheme, but the guidance doesn’t completely rule it out.

Can employees on fixed-term contracts be furloughed?

Yes. Their contracts can be renewed or extended during the furlough period without breaking the terms of the scheme.

If the employee’s contract has not already expired, the contract can be extended or renewed. The employee may be furloughed provided that they were employed on or before 30 October 2020. You must also have made a RTI submission to HMRC between 20 March 2020 and 30 October 2020.

If the employee’s contract expired on or after 23 September 2020, the employee can be re-employed and furloughed. Please note that the employee must have been employed by you on 23 September 2020 and you must have made a RTI submission to HMRC between 20 March 2020 and 30 October 2020.