Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Do I have to continue to pay furloughed staff while furloughed? Can I wait until I receive the money from the government?

To qualify for a grant under the scheme you must pay your furloughed staff the wages you are claiming for. Failure to do so may result in a HMRC investigation and/or claims from furloughed staff for unlawful deductions from wages and possibly constructive dismissal claims.

Normal benefits including non-monetary benefits should continue during furlough unless the individual has agreed in writing to reduce or remove a benefit during this time.

Employers are expected to apply for one or more of the financial support schemes available to be able to continue to pay staff.

Court proceedings haven’t yet been issued – what should I do?

Parties still need to comply with the various Protocols that apply and will be expected to exchange information in the usual way. Court proceedings can be issued electronically.

Should I pay my apprentice to continue training?

Employers should ensure that apprentices are paid at least the Apprenticeship Minimum Wage, National Living Wage or National Minimum Wage (AMW/NLW//NMW) as appropriate (and taking into account the new rates which will take effect from 1 April 2021) for training carried out where their wage received through the Coronavirus Job Retention Scheme does not cover this.

My business involves providing services to consumers. What are my legal obligations in relation to deposits paid by consumers for services that I have been unable to perform due to government restrictions?

Many businesses that supply directly to consumers have been concerned to understand their legal position in relation to services that have been cancelled, or that they have been unable to perform, because of the Covid-19 pandemic, and in particular how to deal with deposits paid by consumers for such services. With some degree of restriction on the hospitality and tourism sectors likely to remain in place for some time, such questions will remain important for the foreseeable future.

Would you suggest using a different name for a MHFA, maybe a MH champion, to encompass the wider pro-active role?

This may be a good idea – whatever name they are given, it is essential that MHFAs are empowered to take a proactive approach to organisational mental health and that they have the bandwidth to be able to discharge their responsibilities.  The name should reflect the culture of the organisation, the key aspect is awareness and accessibility – identifying a name for your company that supports this is key.