Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

If there is an outbreak of coronavirus in a workplace – will it be RIDDOR reportable?

The reporting requirements relating to cases of, or deaths from, COVID-19 under RIDDOR apply only to occupational exposure, that is, as a result of a person’s work.

You should only make a report under RIDDOR when one of the following circumstances applies:

  • an accident or incident at work has, or could have, led to the release or escape of coronavirus (SARS-CoV-2). This must be reported as a dangerous occurrence
  • a person at work (a worker) has been diagnosed as having COVID-19 attributed to an occupational exposure to coronavirus. This must be reported as a case of disease
  • a worker dies as a result of occupational exposure to coronavirus. This must be reported as a work-related death due to exposure to a biological agent
I am dealing with an estate where the bank has sent me an indemnity to obtain the funds. Will the bank accept my signature without it being witnessed by my solicitor?

If you have obtained a Grant of Probate or Grant of Letters of Administration there should be no need to complete an indemnity, merely an account closure form. If however you have not yet obtained a Grant but the bank is willing to release funds then they will generally require an indemnity to be executed. Several banks and building societies including Barclays, Lloyds, HSBC and Santander have signed up to the British Banking Association’s voluntary Bereavement Principles, one of which is to support the bereaved according to their personal needs and work with you to resolve everything as quickly as possible.

If the indemnity requires a solicitor to act as a witness, you should contact the bank to see what they are willing to do to get around the problem, given the current situation.

Can NHS or local authority workers be furloughed?

It is envisaged that employees of organisations falling into the first two categories set out above and won’t be eligible for the job retention scheme in relation to the majority of their employees. It is envisaged that NHS Trusts for example are going to require their staff to be working at full capacity where possible. However, the guidance doesn’t definitely exclude public sector organisations from furloughing employees and notably the government expects such organisations to use public money to continue to pay staff and not furlough them, rather than say requires. In reality, it is difficult to see how such an organisation will be able to rely on the scheme, but the guidance doesn’t completely rule it out.

What has been the response from the Competition and Markets Authority (CMA)?

The CMA is the government body that is responsible for protecting consumers from unfair trading practices. It has announced programme of work to investigate reports of businesses failing to respect cancellation rights during the Coronavirus pandemic.

Based on the complaints received by them from consumers, the CMA has identified three sectors of particular concern:

  • Weddings and private events
  • Holiday accommodation
  • Nurseries and childcare providers

The CMA has expressed concern about the number of complaints that it has received about businesses seeking to retain deposits for cancelled events, undue restrictions being placed on use of vouchers provided for cancelled bookings, and payments being demanded to hold open nursery places.

The CMA has said it will prioritise investigation of these sectors, and then move on to other sectors.

What are the changes to the law?

On 25th June 2020, the Corporate Insolvency and Governance Act, among other things, introduced new restrictions on suppliers of goods and services to terminate the contract in the event that the customer enters an insolvency process.  This has very important consequences for many businesses as it could expose them to greater financial risks.