What are the data protection implications of holding Covid-19 health data?
The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/
Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.
You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.
Related FAQs
Under usual rules, workers are entitled to a minimum of 28 days holiday including bank holidays, each year. Except in limited circumstances, it cannot be carried between leave years meaning that workers lose their holiday if they do not take it.
The government passed emergency legislation relaxing the carry-over of the 20 days leave entitlement provided under EU law. Where it is not reasonably practicable for an employee to take leave in the relevant leave year as a result of the effects of the coronavirus then they could be entitled to carry over the untaken leave into the next year.
It is clear that we are emerging from a completely unprecedented period of disruption for many businesses, and this may have had a huge impact on their contractual arrangements both with suppliers and customers.
As the lockdown eases, and we get back to business, it’s important that businesses take stock of what has happened, and ensure they review and address the legal and contractual consequences of what has been happening since the start of the global pandemic.
The Cabinet Office has published a helpful Procurement Policy Note (“PPN”) on relief available to suppliers due to Covid-19 (available here). This can include making advance payments to suppliers, if necessary. The PPN sets out actions that public sector bodies should take (until at least 30 June 2020) to ensure continuity of service and to ensure that its suppliers can resume normal contract activity once able to.
The actions public sector bodies should be taking include:
- Informing its suppliers (that they believe are at risk) that they will continue to be paid as normal until the end of June 2020 (even if service delivery is currently interrupted). Risk might include supply chains collapsing and/or significant financial implications for a supplier
- If a contract involves a payment by results mechanism, basing payments on previous months (e.g. the average monthly payment over the previous 3 months), and
- Ensuring that invoices submitted by suppliers are paid immediately to maintain cash flow in the supply chain and help to protect jobs.
If you are a supplier to a public sector body, you must act transparently and on an open-book basis, making cost data available to your public sector clients. You must also continue to pay your employees and subcontractors / suppliers. Suppliers to the public sector must not expect to make profits on any undelivered elements of a contract. The PPN makes clear that, should suppliers be found to be taking undue advantage, or failing to act transparently, a public sector body can take action to recover payments made to that supplier.
The PPN requires public sector bodies to urgently review their contract portfolios and take steps to support suppliers who they believe are “at risk”. However, no definition of “at risk” is given in the document. We would suggest that if you are a supplier and you have yet to hear from a public sector client, you should seek to get in touch with them as soon as possible, particularly if you have concerns about your supply chain, staff retention and/or are experiencing financial difficulties currently. Given the requirement for transparency, you may be required to provide evidence, so it may be helpful to have any relevant documentation ready to send, if necessary, as this may help ensure a decision is made by the public sector client more promptly, particularly as the public sector body may have a number of contracts to consider.
The Government has introduced legislation to expand the list of those who can register deaths to include Funeral Directors who are dealing with the funeral arrangements and who has been authorised by a relative of the deceased to register the death. Also, the medical cause of death certificate can be emailed to the Registrar’s office and arrangements made to have a telephone appointment to provide the Registrar with information to register the death. The requirement to attend the Registrar in person to sign the Register has been relaxed so that this is not necessary. It will however still be necessary to register the death within 5 days.
The European Commission has reintroduced its “comfort letter” system for cooperation in relation to shortage of supply. This allows cooperating businesses to check what the Commission’s view of their proposals are before implementing them.
In the UK context the SMA has introduced an exemption for suppliers of healthcare services to the NHS. This allows:
- Sharing information about capacity
- Coordination of staff deployment
- Joint purchasing of goods, services and facilities
- Sharing or lending of facilities
- Division of activities, including agreeing whether to expand or reduce the volume or type of services provided by suppliers
In relation to whether the CMA will investigate cooperation, it has indicated:
- The CMA will use its discretion as to the prioritisation of its enforcement action to permit some agreements/collaboration which would otherwise potentially give rise to enforcement action (including potentially attracting fines of up to 10% of group worldwide turnover)
- The CMA will use its existing power to exempt certain agreements under the Competition Act 1998 where these are in the public interest