Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

What is the penalty for failing to comply with the collective consultation obligations?

Failure to comply with the collective inform and consult obligations could impact on the fairness of any dismissals – see next question. In addition, a Tribunal can award a protective award of up to 90 days gross pay for each affected employee. The purpose is intended punish the employer for not complying with the obligations, not to compensate the employee for their individual financial loss.

Can I use my Public and Employer's Liability insurance to protect my business from a claim?

Business operators such as travel operators, hotels and restaurants remain vulnerable to claims of failure to protect against contracting the virus. There is a high chance of claims from employees, clients and members of the public. These are likely to be covered under public liability and employer’s liability insurance.

What are the key questions to ask ourselves as a business?

Some examples of the key questions to ask include:

  • Is there still a viable underlying business that is likely to continue beyond the current crisis?
  • What does the revised short to medium cash flow look like and will the company continue to be able to pay its liabilities?
  • Does the company have the support of all of its stakeholders – lenders, shareholders, customers, suppliers and banks – even though the business might be in breach of its own obligations?
  • What measures could (and should) the board put in place to protect creditors, including making sure that exposure to creditors (both collectively and individually) is not increased, assets are not sold at less than value and no creditor is treated more favourably than another?
  • Is there still a reasonable prospect of the business avoiding liquidation or administration?

The key question is always whether accepting the money is in the best interests of creditors as a whole bearing in mind that accepting Government support and continuing to trade might increase the company’s overall liabilities. Directors should be mindful that if the business fails, their decisions during this critical time may be scrutinised and it is therefore important that directors have up-to-date financial information and projections to form the basis of any decisions, take stock, get the right advice and document the decisions that are taken.

What payments can be included in the claim for a grant?

You can claim for regular payments you are obliged to pay staff such as non-discretionary overtime, non-discretionary fees, non-discretionary commission and piece-time payments. Overtime in this context is referred to as ‘past overtime’ in the updated guidance which would suggest that you should use the variable pay calculation (see FAQ above) for those who regularly carry out overtime.

If an employee refuses to come into work is their absence unauthorised and do I have to pay them?

This would depend on the reason as to why the employee is refusing to come into work. An unauthorised absence is where an employee fails to attend work and they do not have a statutory or contractual right, or their employer’s permission, to do so. An employer will not be obliged to pay employees their normal pay for periods of unauthorised absence.

There are some absences which may be viewed as authorised which would entitle the employee to their full pay. For instance, employees who believe that they are in serious and imminent danger by coming to work would be entitled to stay at home and receive pay if their belief is deemed reasonable.

An employer should always try to discuss any unauthorised absences with an employee. They may then consider whether to take disciplinary action against the employee.