Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Can we apply for a loan under the CBILS?

If you are running a business, yes you can.  Please see our Funding and Finance FAQ’s.

We are hearing that Banks are more likely to advance monies on the basis of known income, so for example notified legacies, where there may be a time lag in them being received or against investments where, if they were realised now, would crystallise a loss.  Asking for a loan which will need to repaid from future services or trading income should be carefully considered in particular where the charity does not operate to create a surplus which would allow this.

Who do the Procurement Policy Notes (PPN) apply to?

All three of the PPNs are effective immediately and apply to the following Contracting Authorities:

  • Central Government Departments
  • Executive agencies
  • Non-departmental public bodies
  • Local authorities
  • NHS bodies
  • The wider public sector

In regards to PPN03/20, those in scope organisations that do not currently use procurement cards are advised to immediately put in place arrangements using the relevant Crown Commercial Service Agreement (Lot 2 of RM3828 Payment Solutions).

What is the penalty for failing to comply with the individual consultation obligations?

Failure to comply with the individual consultation obligations could render the dismissal unfair and expose you to a financial penalty of the lower of up to 1 years gross pay or the maximum statutory limit (currently £88,519).

Are any suppliers exempt from this?

Small suppliers (defined by reference to certain financial indicators) are temporarily exempt from these new restrictions until 30th March 2021 in order to account for the difficulties to small suppliers during the Covid-19 pandemic.

There are also certain industries that are exempt from these restrictions (for example financial services).  The Secretary of State may also create further exemptions framed by reference to kinds of company, supplier, contract, goods or services or in any other way.

Can I use my Business Interruption insurance to make a claim?

The FCA’s test case in the Supreme Court ruled overwhelmingly in favour of policyholders.  However, business interruption cover generally has the prerequisite of physical damage or loss to the property (or in some circumstances, the presence of a notifiable disease at the property or within a certain radius of it), to recover losses caused by the interruption to your business. The onus is on insurers to re-assess those claims which are impacted by the Supreme Court’s judgment and to make contact with the policyholders regarding next steps. If you have not already made a claim, in the first instance the terms of any policy should be checked carefully to see whether business interruption cover is provided.