Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Employer furlough schemes

Furlough means temporary leave of absence. There is nothing to stop an employer seeking to agree a temporary leave of absence – with or without pay – with its workforce.

This could not be forced on an employee without significant risk. Without agreement, this would need fair selection and consultation – more on that later.

How should contracting authorities work with PFI providers?
  • Working with PFI providers to get contingency plans up to date
  • If a PFI provider is struggling to achieve service delivery requirements due to Covid-19, then local arrangements should be put in place to:
    • maintain unitary charge payments
    • revise contract requirements/standards

moderating payment and performance regimes where appropriate.

  • In any event, you may wish to review and adjust your requirements to reflect the current situation. It is possible that some requirements can be relaxed, whereas others need to be tightened. For example, there may be an increased need for cleaning and maintenance in certain areas of your PFI premises or the layout of the premises and/or room uses may have temporarily changed. With staff illness and shortage likely to be an issue, you may also wish to consider if the resource can be moved from one area to another to help maintain essential services.
  • When putting local bespoke arrangements into place it is vital that:
    •  Contract requirements or performance standards are not relaxed to the point where health and safety are put at risk.
    • It is made clear that the arrangements are temporary and that matters will return to normal as soon as the Covid-19 emergency is over. Indeed the guidance note makes clear that if assets temporarily close they should be kept in such condition that they can be immediately up and running when this emergency is over. In such instances, likely a basic level of maintenance and security will therefore be required as a minimum.
The proposed start date on the Certificate of Sponsorship is about to pass, what do I do?

Sponsors should update the proposed start date by adding a sponsor note to the CoS via the Sponsor Management System.
Does a sponsor need to report a change in workplace if a Tier 2 visa holder is working from home as a result of Covid-19?

Can an employee in a public facing role refuse to interact with a customer who is not wearing a face mask?

In some circumstances, visitors and customers are required to wear face coverings, such as those travelling on public transport, shoppers and museum visitors. The government guidance states that:

  • businesses must remind people to wear face coverings where mandated; and
  • premises where face coverings are required should take reasonable steps to promote compliance with the law.

As part of their duty of care to employees and to uphold a relationship of mutual trust and confidence, employers should consider how employees can ensure that visitors and customers comply with the rules and provide their staff with guidance. They must also seek ways to protect their employees both from the risks of those customers not wearing face masks and potential abuse from customers or visitors who decline to wear a face covering. This may include having signs in place requiring customers and visitors to wear a mask and allowing staff to refuse to serve customers if they do not follow the rules.

However, it is ultimately the responsibility of the police, security and public transport officials to remove customers from premises where they are not complying with the rules on face coverings.

The police and Transport for London have been given greater powers by the government to take measures if the public do not comply with the law relating to face coverings without a valid exemption, such as refusing to wear a face covering. This includes issuing fines which have now been increased to £200 for the first offence (and £100 if paid within 14 days). Transport operators can also deny access to their public transport services if a passenger is not wearing a face covering, or direct them to wear one or leave a service.

What impact does the Regulations have in respect of matters which arise from Fire Safety Audits - e.g. if balconies with wooden/decking elements are now considered higher risk and whether that would fall to developer to remedy the materials used to construct balconies?
The duty would fall on the owner of the building to control the hazards presented by balconies made from combustible materials. There may be scope (via warranties/indemnities or other terms) arising from the contract between the developer and owner for the owner to seek to recover the cost of remedial works.