What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
- Integration:
- Is the individual held out as being employed by the business by having a company email address, uniform, how would they introduce themselves to customers?
- Exclusivity:
- Is the contractor restricted from working for other organisations without the consent of the end user client?
- Length of engagement:
- Is the contractor engaged to work on a specific project for a defined period? Or are they engaged for an indefinite period with no reference to a specific task or project?
- Pay:
- Are there regular fixed payments or is payment on completion of specific task or commission based? Is the contractor entitled to benefits or bonuses?
- Facilities:
- Does the contractor provide their own equipment and materials to provide the services?
- Financial risk:
- Is the contractor personally responsible for any loss arising from their work in performing the services? Will they have to rectify unsatisfactory work at their own time and expense? Will they have the opportunity to profit from the success of a project?
The best advice is that parties should proceed as they would have done before the crisis began.
Follow up to date UK Government advice. This can be found at: https://www.gov.uk/government/publications/guidance-to-employers-and-businesses-about-covid-19/guidance-for-employers-and-businesses-on-coronavirus-covid-19
For best practice and more detailed information; consult the HSE’s website at https://www.hse.gov.uk/news/coronavirus.htm
Failing to follow the guidance is likely to be regarded as failing to take all reasonably practicable steps.
Privacy policy – You must make sure the relevant privacy policies deal with how you will process Covid-19 data. You should have an employee privacy policy and this may already deal with health data (if it doesn’t, it should). You might also need to look at privacy policies for customers, visitors and suppliers. This ensures that processing is lawful, fair and transparent.
Lawful processing conditions – You will need to consider which processing conditions you are relying on (remembering that you need both an Article 6 condition and an Article 9 condition – this is the part of the GDPR which deals with special category data). As a lot of the data you collect will be about employees, you can’t use consent so you will have to find another lawful reason under GDPR which allows you to process the data.
Appropriate policy document – When you are considering your Article 9 processing conditions, remember you must also have an “appropriate policy document” in place.
Processing record – Finally make sure your processing record is up to date with information on what data you collect and use.
To qualify for a grant under the scheme you must pay your furloughed staff the wages you are claiming for. Failure to do so may result in a HMRC investigation and/or claims from furloughed staff for unlawful deductions from wages and possibly constructive dismissal claims.
Normal benefits including non-monetary benefits should continue during furlough unless the individual has agreed in writing to reduce or remove a benefit during this time.
Employers are expected to apply for one or more of the financial support schemes available to be able to continue to pay staff.