Skip to content

Should I have a homeworking policy?

If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:

  • If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
  • Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
  • Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
  • Ensuring staff lock their devices whenever they are not using them
  • Where possible, working in a separate part of the home to family members
  • Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
  • Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
  • Locking any papers in a safe place
  • Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
  • Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
  • Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
  • Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example

Organisations should also ensure that their remote access systems can cope with increased demand.

Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.

We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.

Related FAQs

What happens if an employee refuses to attend work because they are afraid of being exposed to COVID-19 particularly the new more transmissible strain?

An employee can refuse to attend work but their refusal to do so will have to be based on a reasonable belief that their health and safety is in danger.  Whether or not their refusal is reasonable will take into consideration factors such as the employee’s own health and whether they are at a higher risk of becoming seriously ill if they contract Covid-19 and the steps their employer has out in place to mitigate the danger of contracting Covid-19 at work.

In such circumstances where the employee’s belief is deemed to be reasonable, they will be entitled to stay at home and receive full pay.

If an employee is subsequently dismissed for refusing to attend work in these circumstances, they may be able to bring a claim for unfair dismissal.

What if a contractor is deemed to be employed?

The fee payer that pays the fee to the contractor’s PSC for the services (end user client or agency) will be responsible for operating PAYE and deducting NIC’s. The fee payer must also pay employer NIC’s and where applicable the apprenticeship levy so there will be additional costs involved in the event of a change to employed status for tax purposes.

If the assessment concludes that the contractor is self-employed, the PSC can continue to be paid gross.

Can I rotate staff who are furloughed? Can I put someone on furlough, bring them back when I need to, and then put them back on furlough, as demand requires? And practically how can we deal with this for those who want to rotate?

You can rotate staff on furlough or flexible furlough.

One option is to make it clear in the letter agreeing to being furloughed that there is an open ended right to rotate and to be able to take them off furlough and bring them back and put them back on.

So the employer reserves the ability to rotate by building into the agreement, but only exercises it if it is permissible.

Rotation is quite key for employers who need to make a temporary reduction to their overheads but want to retain the skills base to call back when work picks up. Having furloughed staff return on a part-time basis may reduce the need to rotate.

It also helps in the employer being able to show that they are treating the workforce as fairly as possible and everyone is taking a reduction. Get in touch if you need help preparing the documentation for furlough that will permit rotation or flexible furlough.

Read more about flexible furlough and how this can be used as part of the CJRS.

 

What is the amendment to The Working Time legislation called?

The government introduced The Working Time (Coronavirus) (Amendment) Regulations 2020 to amend the Working Time Regulations 1998 to allow for the change.

One of my employees has contracted Covid-19, should I report it under RIDDOR?

You must only make a report under RIDDOR (The Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013) when:

  • An unintended incident at work has led to someone’s possible or actual exposure to coronavirus. This must be reported as a dangerous occurrence
  • A worker has been diagnosed as having COVID 19 and there is reasonable evidence that it was caused by exposure at work. This must be reported as a case of disease
  • A worker dies as a result of occupational exposure to coronavirus.