Should I have a homeworking policy?
If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:
- If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
- Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
- Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
- Ensuring staff lock their devices whenever they are not using them
- Where possible, working in a separate part of the home to family members
- Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
- Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
- Locking any papers in a safe place
- Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
- Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
- Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
- Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example
Organisations should also ensure that their remote access systems can cope with increased demand.
Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.
We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.
Related FAQs
On 30th April 2020, the CMA issued a guidance note setting out its views about how the law operates in relation to refunds.
Where a contract is not performed as agreed, the CMA considers that in most cases, consumer protection law will generally allow consumers to obtain a refund.
This includes the following situations:
- Where a business has cancelled a contract without providing any of the promised goods or services
- Where no service is provided by a business, for example because this is prevented by Government public health measures
- A consumer cancels, or is prevented from receiving any services, because Government public health measures mean they are not allowed to use the services.
In the CMA’s view, this will usually apply even where the consumer has paid what the business says is a non-refundable deposit or advance payment.
This positon reflects the CMA’s previous guidance which they had issued in relation to the requirement of fairness in consumer contracts under the Consumer Rights Act 2015, which was that a clause in a contract that gives a blanket entitlement to a trader to cancel a contract and retain deposits paid is likely to be unfair, and therefore unenforceable – it would be unfair to a consumer to lose their deposit if the contract is terminated without any fault on their part, and if they had received no benefit for the payments made.
The CMA’s latest guidance therefore confirms their view that the Covid-19 outbreak does not change the basic rights of the consumer, and that they should not have to pay for goods or services that they do not receive.
- Trusts should allow for telephone advice rather than face-to-face review from critical care when clinically appropriate.
- Hospitals should discuss the sharing of resources and the transfer of patients between units, including units in other hospitals, to ensure the best use of critical care within the NHS.
Please note, the above is intended to provide a summary of the key recommendations which emerge from this guidance. Access to the full guidance can be found here.
Employers will need to be flexible with employees who are unable to return to work at present due to childcare difficulties. While schools have reopened, a period of isolation may result in employees having to keep children off school/nursery and therefore have childcare issues. Some employees will be able to manage this with their partner and extended family, whereas others will not. Where an employee simply cannot make any other arrangements to care for their children in the short term then they will be unable to return to work until that situation changes. Any dismissals on the basis that someone is unable to return to work as a result of lack of childcare are likely to be unfair, at least in the short term where such employees may well be able to demonstrate that they had no options available to them.
Yes. With respect to employees you have an obligation to protect their health so you can gather information to do that. You might gather information from your employees on who has the virus, who has had it and recovered and also who has tested negative. You might also want to know if individuals have been in contact with someone who has it or if they are in a vulnerable group. It is reasonable to want to know where individuals have travelled. In the future it may also be reasonable to know if they are planning to travel to a virus hot spot, as the impact of the virus around the world is likely to continue for some time even after the outbreak has been contained in the UK.
It is reasonable to gather some information about visitors to your site, be they customers or suppliers, as this information will also help protect your staff. However, you should keep what you gather to a minimum. For visitors, it’s unlikely that you need to know anything more than they have Covid-19, are displaying symptoms or have recently been in contact with someone who has the virus.
The Town and Country Planning (Use Classes) (Amendment) (England Regulations) 2020 were laid before Parliament and come into force on 1 September 2020. They apply in England only.
The changes include the revocation of the following Use Classes;
- A1 – shops
- A2 – financial and professional services
- A3 – restaurants and cafes
- A4 – drinking establishments
- A5 – hot food takeaways
- B1 – business. Also revoked are the sub parts of B1;
- B1(a) – offices
- B1(b) – research and development of products and processes
- B1(c ) – industrial process
- D1 – non residential institutions
- D2 – assembly and leisure
The changes include the amendment of the following Use Class;
- B2 (industry)
The changes include the introduction of the following Use Classes;
- E – commercial, business and service
- F.1 – learning and non-residential institutions
- F.2 – Local community
There are no changes to the following Use Classes;
- C1 – hotels, boarding and guest houses
- C2 – residential institutions
- C3 – dwellinghouses
- C4 – small HMO
From 1 September 2020;
- Small retail shops (not more than 280 sq metres net sales area) selling essential goods including food and at least 1 kilometre from another shop will cease being an A1 use and will become a F.2 (local community) use;
- Other A1 shops will become an E (commercial, business and service) use;
- A2 uses will become an E (commercial, business and service) use;
- A3 uses will become an E (commercial, business and service) use;
- A4 uses will not be in a Use Class, they will be sui generis, ie not in any use class;
- A5 uses will not be in a Use Class, they will be sui generis, ie not in any use class;
- B1 uses (included B1(a), B1 (b) and B1 (c) will become an E (commercial, business and service) use;
- B2 uses will either be B2 uses or will be Class E uses.
- Clinics, health centres, creches, day nurseries and day centres (previously D1 uses) will become an E (commercial, business and service) use;
- Schools, non residential education and training centres, museums, public libraries, public halls, exhibition halls, places of worship, law courts (previously D1 uses) will become an F.1 ( learning and non-residential institutions) use;
- Cinemas, concert halls, live music performance venues, bingo halls and dance halls (previously D2 uses) and will be sui generis, ie not in any use class;
- Gyms, indoor sport, recreation or fitness not involving motorised vehicles or firearms principally to visiting members of the public (previously D2 uses) will become an E (commercial, business and service) use;
- Hall or meeting place for the principal use of the local community (previously D2 uses) will become an F.2 (local community) use;
- Indoor or outdoor swimming baths, skating rinks, outdoor sports or recreation grounds (not involving motorised vehicles or firearms) (previously D2 uses) will become an F.2 (local community) use.
Changes of use within a Use Class do not constitute development. That being the case, provided the Order is applicable, its operation not having been restricted by planning condition, Agreement or Article 4 (1) Direction for example, planning permission would not be required, development as defined not happening. If legally binding confirmation is required that planning permission is not required this can only be obtained by way of a successful application for a Certificate of Lawfulness. In the absence of such, there is some risk.
It remains the case that planning permission may be required for operational works to buildings. It also remains the case that other consents and permissions may be necessary for example licenses. Furthermore amendments to leases may be required if the property is rented.
The Regulations additionally include transitional arrangements because of permitted development rights for changes of use in the Town and Country Planning (General Permitted Development) (England) Order amongst others. To respond to this Regulations introduce a ‘material period’ which is defined as meaning the period beginning 1 September 2020 and ending 31 July 2021. It is expected during the material period the Orders giving permitted development rights for changes for use which do constitute development will be amended / updated to reflect the new use classes.
Click here to view the Regulations.
The above is based on our understanding of the new Regulations at the time of issue and in advance of planning practice guidance being issued.