Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Can I ask furloughed staff to agree to accept less than 80% of their normal pay?

The guidance is clear that furloughed staff must receive no less than 80% of their reference pay (up to the monthly cap of £2500).

Employers cannot enter into any transaction with the worker which reduces the wages below this amount. This includes any administration charge, fees or other costs in connection with the employment.

What is the "Job Retention Bonus"?

As a result of the CJRS being extended, the Job Retention Bonus will no longer be paid in February 2021.

What was included in the Government’s self-employment income support scheme?
  • A taxable grant worth 80% of the average monthly profit over the last three years (one or two years will be reviewed for those who do not have three years of tax returns)
  • The grant will be capped at £2,500 per month
  • The scheme was initially available for three months and has been extended as necessary
  • Individuals claiming a grant can continue to do business (unlike employees who must not work when furloughed)
Are there steps to ensure they will have access to an open register (BSR) & building safety assessments etc?

The Act should make it easier for residents to obtain relevant information. It includes an obligation for the Principal Accountable Person to prepare a strategy for promoting the participation of residents, including the information to be provided to them and consultations about relevant decisions. The strategy must be provided to residents, and there will be provision for residents to be able to request information and copies of documents from the Principal Accountable Person. The type of information and the form in which it is to be provided will be set out in secondary legislation in due course, but the explanatory notes anticipate that it will include:

  • Full current and historical fire risk assessments•Planned maintenance and repair schedules
  • The outcome of building safety inspection checks
  • Information on how assets in the building are managed
  • Details of preventative measures
  • Details of fire protection measures and the fire strategy for the building
  • Information on the maintenance of fire safety systems
  • Structural assessments
  • Planned and historical changes to the building
What if we are a charity in Scotland Wales or Northern Ireland?

Because they all have devolved governments, when there are changes to spending levels in England, the Government makes adjustments to the amount of public expenditure allotted to Scotland, Wales and Northern Ireland.  In this case £60 million will be made available for all of the devolved administrations as a result of the £370 million funding allocated to charities in England. This is broken down as follows:

  • £30 million for the Scottish Government
  • £20 million for Welsh Government
  • £10 million for the Northern Ireland Executive

There may be further allocations, dependent on the final projects funded, through the £360 million direct grant pot.