Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Will remote court hearings be permitted?

Court hearings have been conducted remotely, with the judgment in Kerry v SSCLG being given via telephone. The Senior President of Tribunals issued emergency Practice Directions which will apply to Property and Lands Chambers’ respectively. This has made provision for remote hearings. Inspections of properties have been suspended with immediate effect, with photographs, videos or external visits permitted where appropriate. Where inspections are essential, the case should be stayed.

What about someone who refuses because they are against the vaccine (the anti-vaxers)?

It is a theoretical possibility that “anti-vax” beliefs could be a philosophical belief under the Equality Act 2010 and therefore anti-vaxers have the right not to be discriminated against for their beliefs. Much will depend on why the individual is against the vaccine. Conspiracy theorists (the vaccine is being used as an opportunity to monitor you or it’s all because of 5G) are highly unlikely to be treated as having a philosophical belief!

Is there a time limit on making an insurance claim?

All policies will impose a stringent obligation, often with time limits, for you to notify insurers of circumstances that may give rise to a potential claim under the policy and non-compliance may well negate your cover. If therefore you have potential cover under your policy you must make a precautionary notification to Insurers as soon as possible.

What is the difference between individual and collective consultation?

Where it is envisaged that 20 or more employees will be dismissed at a relevant establishment within a 90 day period or less, then collective consultation is required (in addition to individual consultation) and the company must inform BEIS (using form HR1).

If there are less than 20 dismissals then you are only required to carry out individual consultation.

Who is expected to be principal accountable person in local authorities who are landlords of high rises?

This will be dependent upon the how the leasehold structure is set up for each relevant building, but it may be the local authority. We would be happy to provide further advice in relation to specific buildings if you contact us separately with the relevant details and documents.