Skip to content

Should I have a homeworking policy?

If organisations don’t have a formal home working policy, then they should set out, as soon as possible, in clear terms, what is expected of employees from a data protection perspective when working from home. These might include:

  • If someone is using their own device for remote working, ensuring that any devices that hold work-related information have up-to-date anti-virus software and that broadband connections have properly configured firewalls
  • Reminding staff to contact the organisation’s IT department if they encounter any issues with home working, and not to try and resolve any issues themselves
  • Reminding staff that they should notify relevant individuals within the organisation if they consider that there might have been a personal data breach. A breach will still be notifiable even if it does occur at home during the pandemic. These should be logged by the organisation in their data breach log in the normal way
  • Ensuring staff lock their devices whenever they are not using them
  • Where possible, working in a separate part of the home to family members
  • Ensuring confidentiality of information – advising staff not to have phone calls where others are likely to hear the conversation. This might mean moving to a different room, closing the door, or arranging a call for a more convenient time. If employees have smart speakers, you may want to consider advising them to either turn these off, if they are working in the same room as it, or work in a different room
  • Wherever possible, avoid taking hard copy documents home, and, if papers are taken home, never placing those papers in a bin or using a home shredder – any such papers should be shredded back at the office in the usual way
  • Locking any papers in a safe place
  • Not using social media platforms (unless already used and permitted by the organisation) to discuss work matters
  • Advising extra caution with incoming emails as at times such as this there may be an increased risk of fraud, email hacking, spear phishing etc.
  • Avoiding information being sent to personal email accounts (for example, so it can then be printed at home)
  • Reminding staff of your organisation’s Information Security policies, procedures and protocols. These could be emailed to all staff working from home or they could be directed to such documents on the organisation’s intranet, for example

Organisations should also ensure that their remote access systems can cope with increased demand.

Whilst the ICO appreciates the unprecedented nature of this pandemic, it does not mean that organisations can forget about their obligations as controllers of personal data. If a major data security breach were to happen, there is still the possibility of enforcement action where the organisation didn’t put in place good risk mitigation measures.

We have a specialist team of data protection lawyers here at Ward Hadaway, and would be happy to discuss any data protection concerns or issues that you might have.

Related FAQs

Can those on sick leave or who have been advised to self-isolate be furloughed?

If an employee is self-isolating (as a result of the pandemic) they may be entitled to SSP. Employers should not furlough employees in this category just because of their absence, but they can furlough if there are genuine business reasons for doing so and other eligibility requirements are met. In these cases the employees should no longer receive sick pay and they would be classified as furloughed.

The guidance has specified that those on long term sick leave or who are ‘shielding’ for 12 weeks in line with public health guidance can also be furloughed. But it is important that you clarify that they do fall in the category of extremely vulnerable (https://www.gov.uk/government/publications/guidance-on-shielding-and-protecting-extremely-vulnerable-persons-from-covid-19). It is up to employers to decide whether to furlough employees who are shielding or on long-term sick leave.

You can claim from the CJRS and also for the two week SSP rebate scheme (see below) for the same employee but not for the same period of time. Therefore if you have a furloughed employee who becomes ill and you subsequently move them to SSP you cannot claim the furlough rate of pay. If you keep the employee on the furloughed rate you can continue to claim this under CJRS.

I’m a landlord. How do I comply with Regulation 36 of the Gas Safety Regulations 1998 during the coronavirus outbreak?

Under their obligations arising from Regulation 36 of the Gas Safety (Installation and Use) Regulations 1998, landlords must service domestic gas appliances on an annual basis and provide tenants with a record of the service within 28 days of that service. Failure to comply can result in prosecution by the Health and Safety Executive (HSE) or downgrading by the Regulator.

We know how important this is. But how can you comply with your obligations during the Covid-19 epidemic?

The latest restrictions on leaving the home, currently allow registered gas engineers to undertake essential work, whilst taking the appropriate precautions advised to avoid spreading or contracting the virus in a new setting.

How is IR35 changing?

The current position is that the PSC is responsible for assessing whether IR35 applies. This current regime has been difficult to police by HMRC and HMRC considers there is widespread flouting of the rules by contractors.

From April 2021 the responsibility for assessing whether IR35 applies will shift to the end user/client (with the exception of ‘small’ companies) which will require an assessment to be carried out on a contract by contract basis. HMRC anticipates that this will be easier to monitor and that end user businesses will be more compliant.

The reformed regime will apply to payments made on or after 6 April 2021 for services carried out on or after this date.

What if I have missed the January deadline for submitting my 2018/2019 tax return?

You had until 23 April 2020 to submit your return in order to be considered for eligibility.

How do I guard against contractor insolvency in the construction industry?

It is almost impossible to completely guard against the risks associated with contractor insolvency, but there are some steps which can assist in mitigating and managing the risks involved.   To be in the best possible position, it is worth considering the following at the outset of any project:

  • Check the contractor’s financial position – particularly the specific company which will enter into the building contract, as the employer’s rights will be against this company rather than the business as a whole
  • Take legal advice to ensure that the building contract is properly drafted with appropriate provisions to deal with an insolvency event
  • Consider requiring a performance bond and/or parent company guarantee (each serve slightly different purposes)
  • Obtain collateral warranties from the consultants and sub-contractors involved, so that there are contractual rights against other parties if the contractor is no longer able to meet claims
  • Consider requiring retention bonds, advance payment bonds or vesting certificates if necessary
  • Project bank accounts and escrow accounts can also provide some further assurances for the parties involved