Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Can I ask my employees to travel for work during the national lockdown?

As above, people must not leave their home unless they have a ‘reasonable excuse’ and travelling should be limited to their local area. Employees may leave their home and local area to travel for work if they cannot reasonably work from home. You should attempt to reduce the number of journeys they make.

What is happening about court and arbitration hearings?

The courts are seeking to adapt to our new circumstances and have urgently been looking to introduce new ways of working. The courts have been testing out different ways of holding court hearings. The advice is changing almost daily and some courts have been developing local practices. Going forward the court, the parties and their representatives will need to be more proactive about all forthcoming hearings.

Everyone involved in the case is to consider as far ahead as possible how future hearings should best be undertaken and work collaboratively. It will normally be possible for all short, interlocutory, or non-witness, applications to be heard remotely. Some witness cases will also be suitable for remote hearings. The parties just need to ensure that everyone involved can use the technology suggested.

The courts have been looking at and held remote hearings using, non-exhaustively, BT conference call, Skype for Business, court video link, BT MeetMe, Zoom and ordinary telephone call. Bundles for the hearing will be prepared and circulated electronically.

If the hearing cannot be held remotely because the parties do not have the requisite technology or the length of the hearing combined with the number of parties or overseas parties, representatives and/or witnesses make it undesirable to go ahead with a hearing in court at the current time, then it may be that the case will need to be adjourned. We are hearing of trials being adjourned and that they will not be re-listed before at least September.

HMCTS has advised that several priority courts will remain open during the coronavirus pandemic to make sure the justice system continues to operate effectively. It publishes a daily operational update from the courts and they aim to update it by 9am. The link is https://www.gov.uk/guidance/hmcts-daily-operational-summary-on-courts-and-tribunals-during-coronavirus-covid-19-outbreak.

Also, the courts have circulated a civil listing priority list with Priority 1 listing work which must be done and which includes injunctions, any applications in cases listed for trial in the next three months, any applications where there is a substantial hearing listed in the next month and all Multi Track hearings where parties agree that it is urgent.

In the Priority 2 list, which consists of hearings which could be done, are enforcement of trading contracts, trial involving the survival of a business or the insolvency of an individual, small and fast track trials where the parties say they are urgent, and appeal in these kinds of cases.

Similarly, in arbitration proceedings, the parties and arbitrators are being encouraged to utilise technology to make sure that hearings take place. We have heard of Zoom being used very successfully for multi-party proceedings.

Can I still have my domestic gas appliances tested during the coronavirus outbreak?

Yes. The Health and Safety Executive has stated (as quoted from the Gas safe register site):

“Landlords have a legal duty to repair and maintain gas pipework, flues and appliances in a safe condition, to ensure an annual gas safety check on each appliance and flue, and to keep a record of each safety check.

“If you anticipate difficulties in gaining access as the Covid-19 situation progresses, you have the flexibility to carry out annual gas safety checks two months before the deadline date. Landlords can have the annual gas safety checks at their properties carried out any time from 10 to 12 calendar months after the previous check and still retain the original deadline date as if the check had been carried out exactly 12 months after the previous check.

“You are encouraged to arrange your annual gas safety checks as early as possible, as a contingency against tenants being in self-isolation for 14 days (in line with current guidelines), or gas engineers being unavailable due to illness. The two-month period to carry out annual gas safety checks should provide adequate resilience in most situations.

“In the event you are unable to gain access to the property, e.g. persistent refusal of access due to vulnerable tenants self-isolating, you will be expected to be able to demonstrate that you took reasonable steps to comply with the law, and that you are seeking to arrange the safety check as soon as all parties are able. This will need to include records of communication with the tenant, and details of your engineers attempts to gain access.”

Many Registered Providers have been suspending all gas and electrical testing where internal access is required, continuing checks in communal areas and are carrying out emergency repairs only, whilst void works are suspended and staff are working from home. This does not comply with the legislation, or the guidance.

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

What type of bundle will be required by the COP for a remote hearing?

Physical bundles may not be regarded as safe for public health and there are obvious difficulties in providing them with the current restrictions in place. Electronic bundles should be provided in PDF format, preferably paginated, indexed and bookmarked. The bundles should only contain documents and authorities that are essential to the issues required to be decided at the remote hearing and should be filed with the court by email.