Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

What is a small company?

The changes will not apply to end users who are a small company. If you meet two out the following 3 conditions, you will meet the small company definition and are therefore exempt from the changes to IR35:

  1. Annual turnover is no more than £10.2 million
  2. Balance sheet total is no more than £5.1 million
  3. No more than 50 employees

Companies will always be classified as small in their first financial year. Public companies will always be considered to be medium or large businesses and cannot fall under this exemption.

For a group company to be a small company its parent company must also meet the small company definition.

VIDEO EXPLAINER: Consultation exercises – the why, the who, and the how

This free Getting back to business webinar was held on Thursday 7th May.

On this video, employment partner Edward Nuttman and Graham Vials went through what a consultation exercise is and when you are required to hold one. They then took you step by step through the process, describing all you will need to do to ensure legal compliance whilst at the same time being sensitive to the emotional and motivational impact on your employees and managers.

Does an employee who is furloughed lose his/her benefits under an EMI share option?

One of the key legislative requirements of EMI is that the employee satisfies the working time requirement, which is that they work at least 25 hours per week in the company or, if less, 75% of the employee’s total working time. If the working time requirement ceases to be met, then there is a “disqualifying event”. That means that the tax benefits of EMI ceases. It may also mean that the option lapses, but that depends on the specific terms of the option.

An employee who has been furloughed is by definition no longer working 25 hours/week and therefore on the face of it, there is a disqualifying event. However, the Government has tabled an amendment to the Finance Bill currently going through Parliament providing in effect that time not worked because an employee has been furloughed counts as working time, both for determining whether the working time requirement is met initially and whether there is a disqualifying event. Provided this amendment is enacted, this should address the issue.

In a situation where a building has a B1 EWS1 rating but the insurance companies are either refusing to quote or saying the cladding is a fire risk (due to the result of the intrusive survey for the EWS1 rating) and quadrupling insurance premium, is there anything that will help with this situation in the Building Safety Act or the secondary regulations when they come in or do you think it is something case law will have to address?

The amount an insurer charges for providing cover is a critical aspect of the underwriting process. The premium must be sufficient to cover expected claims but must also take into account the possibility that the insurer will have to access its capital reserve –it is risk assessment based and the greater the risk, the higher the premium. Historically, insurers of high-rise buildings would have only had to prepare for a loss caused by damage to just a few flats within a building. That is because the design and construction of that building, with the right materials and fire safety provisions in place, should have limited the spread of fire and allowed the damage to be contained –or at least make this an extremely low risk. Now we know that many buildings have been designed, built and signed off in a regulatory system that an independent Government review has found was not fit for purpose. Premiums will reduce overtime but will be dependent upon the perceived level of risk reducing as the regulatory regime, BSA and BSR become more established.

What is the penalty for failing to comply with the collective consultation obligations?

Failure to comply with the collective inform and consult obligations could impact on the fairness of any dismissals – see next question. In addition, a Tribunal can award a protective award of up to 90 days gross pay for each affected employee. The purpose is intended punish the employer for not complying with the obligations, not to compensate the employee for their individual financial loss.