Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

One of my employees has contracted Covid-19, should I report it under RIDDOR?

You must only make a report under RIDDOR (The Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013) when:

  • An unintended incident at work has led to someone’s possible or actual exposure to coronavirus. This must be reported as a dangerous occurrence
  • A worker has been diagnosed as having COVID 19 and there is reasonable evidence that it was caused by exposure at work. This must be reported as a case of disease
  • A worker dies as a result of occupational exposure to coronavirus.
What was the eligibility criteria for the Government’s self-employment income support scheme?

You will be eligible if you are a self-employed individual or a member of a partnership and you:

  • have trading profits of up to £50,000
  • earn the majority of your income from self-employment
  • have submitted a Tax Return for 2019
  • have traded in the tax year 2019/20
  • are trading when you apply for a grant, or would be except for Covid-19
  • intend to continue to trade in the tax year 2020/2021
  • have lost trading/partnership profits due to Covid-19

 

What if a contractor is deemed to be employed?

The fee payer that pays the fee to the contractor’s PSC for the services (end user client or agency) will be responsible for operating PAYE and deducting NIC’s. The fee payer must also pay employer NIC’s and where applicable the apprenticeship levy so there will be additional costs involved in the event of a change to employed status for tax purposes.

If the assessment concludes that the contractor is self-employed, the PSC can continue to be paid gross.

I'm self-isolating and understand that it takes some time to get a Lasting Power of Attorney registered. What can I do in the meantime to enable someone else to operate my bank account and pay my bills?

The Office of the Public Guardian is continuing to accept applications to register Lasting Powers of Attorney but their usual estimated timescale of eight to ten weeks is likely to be affected by the current situation.

Consequently, an alternative or interim measure if you need something quickly is to execute a General Power of Attorney to authorise someone to act as your Attorney to undertake day to day financial transactions for you. The General Power of Appointment only needs to be executed by you in the presence of a witness (not the Attorney) to be valid and does not need to be registered with the Court of Protection. However, the Power of Attorney would cease to have effect if you become incapable of managing your affairs. It should be seen as a stop-gap only.

How is an establishment defined?

The definition of a relevant establishment is a question of fact for an Employment Tribunal. Guidance from case law says that ‘establishment’ should be interpreted very broadly (so as to avoid employers escaping the need to collectively consult), and may consist of:

  • A distinct entity
  • With a certain degree of permanence and stability
  • Which is assigned to perform one or more tasks
  • Which has a workforce, technical means and a certain organisational structure to allow it to do so

However, there is no need for it to have the following:

  • Legal, economic, financial, administrative or technological autonomy
  • A management which can independently effect collective redundancies
  • Geographical separation from the other units and facilities of the undertaking