Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

I have essential workers who do home visits. How do I assess the risks?

The fundamentals of risk assessment remain the same as for any other foreseeable risk.

Focus on risk controls which reflect Government guidance; social distancing (2 metres) and avoiding contact with occupiers if possible, high-quality PPE – disposable overalls, gloves and fluid repellent surgical face masks, ready access to antibacterial wipes for surfaces, tools and equipment and plentiful hand sanitizer.

If a member of staff does not inform me that they ought to be self-isolating will I still be liable for a fine?

Potentially no.

If an employer is not put on notice that the circumstances of a worker or agency worker are such that they ought to be self-isolating, by either the worker or agency worker themselves or another member of staff, then there ought to be a reasonable excuse, and potentially, no fixed penalty notice will be issued.

What guidance has the CMA issued about how it expects businesses to behave in response to the global pandemic?

On 30th April 2020, the CMA issued a guidance note setting out its views about how the law operates in relation to refunds.

Where a contract is not performed as agreed, the CMA considers that in most cases, consumer protection law will generally allow consumers to obtain a refund.

This includes the following situations:

  • Where a business has cancelled a contract without providing any of the promised goods or services
  • Where no service is provided by a business, for example because this is prevented by Government public health measures
  • A consumer cancels, or is prevented from receiving any services, because Government public health measures mean they are not allowed to use the services.

In the CMA’s view, this will usually apply even where the consumer has paid what the business says is a non-refundable deposit or advance payment.

This positon reflects the CMA’s previous guidance which they had issued in relation to the requirement of fairness in consumer contracts under the Consumer Rights Act 2015, which was that a clause in a contract that gives a blanket entitlement to a trader to cancel a contract and retain deposits paid is likely to be unfair, and therefore unenforceable – it would be unfair to a consumer to lose their deposit if the contract is terminated without any fault on their part, and if they had received no benefit for the payments made.

The CMA’s latest guidance therefore confirms their view that the Covid-19 outbreak does not change the basic rights of the consumer, and that they should not have to pay for goods or services that they do not receive.

What is my legal position if emergency legislation to tackle the outbreak makes performance of a contract illegal or impossible?

As the coronavirus outbreak continues to develop, we have seen many countries begin to implement emergency procedures and legislation in an attempt to control the spread of the disease.

These have included bans on gatherings and public events, closures of shops, bars, restaurants and public spaces, and full lockdowns which restrict all but key workers to their homes except in certain limited circumstances.

This has a direct impact on businesses and their ability to operate. So what happens if a contract becomes impossible to perform because of emergency legislation?

For example:

  • If you are a hospitality business, you have agreed to host an event, and gatherings are prohibited
  • If you are a manufacturer or service provider, and your staff are required to remain at home, making performance of the contract impossible
How do I set the hours that my employees will work under the Flexible Furlough Scheme?

Employers and employees can decide the split of the hours of work and the hours of furlough. There is no maximum or minimum requirements. You can change the arrangement, by agreement, from time to time.

When claiming for employees who are flexibly furloughed, you should not claim until you are sure of the exact hours they will work during the claim period.