What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
A number of our clients and networks raised issues in the early stages of the Scheme around the requirement for personal guarantees to access finance under the Scheme. The Scheme has now been updated so that:
- For facilities under £250,000, personal guarantees cannot be taken to support lending under the Scheme.
- For facilities above £250,000, personal guarantees may still be required by a lender but the amount which can be recovered under these guarantees is capped at a maximum of 20% of the outstanding balance of the CBILS facility after taking into account any other recoveries from business assets.
- On admission to hospital, all adults should be assessed for frailty, irrespective of their age and Covid-19 status. Regard should be had to any comorbidities and underlying health conditions.
- If a patient is identified as potentially having Covid-19, the UK Government guidance on infection prevention and control measures should be followed.
- If Covid-19 is then diagnosed in someone who is not isolated from admission or presentation, the UK Government guidance on actions required when a case was not diagnosed on admission should be followed.
No. The Home Office has confirmed that sponsors do not need to report sponsored workers as working from home, where this is directly related to the coronavirus outbreak.
However any UK employers who sponsor overseas workers, should also ensure that they remain compliant with their other sponsor licence duties, which includes reporting any change to an employee’s salary and duties.
Under CBILS, for the purposes of calculating the applicant’s annual turnover, approved lenders have been aggregating turnover across the whole of the private equity investor’s portfolio meaning they failed to qualify for the scheme as they were deemed to exceed the £45 million threshold.
For private equity-backed businesses, the removal of the upper limit on annual turnover criteria for CLBILS seemingly avoids the issue of turnover aggregation across investment portfolios seen with the CBILS, potentially enabling more private equity sponsor portfolio companies to be able to access the CLBILS funding.
Obtaining an employee’s Covid-19 test result will amount to processing personal data for the purposes of the General Data Protection Regulation 2016/679 (GDPR) and information about an employee’s health is a special category of data (sensitive personal data under the Data Processing Act 2018 (DPA)).
In accordance with the GDPR and DPA, there must be lawful grounds for processing such information. Most employers rely on employees’ consent to obtain medical information and process sensitive personal data and if the employee is unwilling to give consent, you will not normally be entitled to the information.
Special category data can be processed lawfully if it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. Employers may be able to require an employee to disclose their Covid-19 test if there is a substantial public interest, such as ensuring that the employee self-isolate if they have a positive test. However, there is a risk that this measure could be considered disproportionate particularly if it is enforced on all employees as a blanket measure.