Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Can employees on fixed-term contracts be furloughed?

Yes. Their contracts can be renewed or extended during the furlough period without breaking the terms of the scheme.

If the employee’s contract has not already expired, the contract can be extended or renewed. The employee may be furloughed provided that they were employed on or before 30 October 2020. You must also have made a RTI submission to HMRC between 20 March 2020 and 30 October 2020.

If the employee’s contract expired on or after 23 September 2020, the employee can be re-employed and furloughed. Please note that the employee must have been employed by you on 23 September 2020 and you must have made a RTI submission to HMRC between 20 March 2020 and 30 October 2020.

 

Given the recent decline in financial performance, the business is now in breach of its covenants with the bank. Should we be concerned?

That will depend on the terms of your facility and the stance taken by your bank.

Banking facilities often place obligations on businesses to stick to certain financial criteria. For example, an obligation to keep turnover or profit above certain levels or a commitment to keep the bank’s exposure within an agreed percentage of the value of the company’s assets (known as loan to value ratio).

The consequences of breaching those covenants will depend on the terms of your facility, but normally this amounts to an event of default. Events of default can result in the loan (or whatever form the facility takes) becoming repayable and could give the bank certain powers to take action to recover the money that they are owed.

Whether the bank will take action during these unprecedented times is another matter, particularly given the extent of support being offered to businesses via mainstream lenders and the political desire to keep viable businesses up and running. Lenders themselves will no doubt wish to remain supportive where possible. The underlying performance of the business (and whether but for the effects of Covid-19 it would have been in a healthy financial position), the relationship you have with the bank and your history with them will no doubt be relevant to the approach taken by the bank. However, early engagement with your bank (as well as other key stakeholders in the business) will be important.

ONLINE EVENT: Contracts, managing supply chain issues and the role of directors

Hosted by NewcastleGateshead Initiative, Partners Damien Charlton and Jane Garvin discussed in this webinar contracts, managing supply chains and the role of directors, with  a particular focus on cancellation of events and businesses in the tourism and hospitality sector.

You can find a recording of the webinar from NGI here.

Can I reduce the risk of IR35 applying?

It is possible to review working arrangements for contractors before the new rules come into effect. This will require immediate action.

You could consider terminating current contracts and entering into new terms that reflect working arrangements for a self-employment arrangement.

Another possibility is encouraging contractors to abandon the PSC model and provide services under a compliant umbrella company.

In the event of a determination of employed status you should seek to enter new terms that at the very least reflect the new tax arrangements .

Are there steps to ensure they will have access to an open register (BSR) & building safety assessments etc?

The Act should make it easier for residents to obtain relevant information. It includes an obligation for the Principal Accountable Person to prepare a strategy for promoting the participation of residents, including the information to be provided to them and consultations about relevant decisions. The strategy must be provided to residents, and there will be provision for residents to be able to request information and copies of documents from the Principal Accountable Person. The type of information and the form in which it is to be provided will be set out in secondary legislation in due course, but the explanatory notes anticipate that it will include:

  • Full current and historical fire risk assessments•Planned maintenance and repair schedules
  • The outcome of building safety inspection checks
  • Information on how assets in the building are managed
  • Details of preventative measures
  • Details of fire protection measures and the fire strategy for the building
  • Information on the maintenance of fire safety systems
  • Structural assessments
  • Planned and historical changes to the building