Skip to content

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

Related FAQs

Forcing annual leave

Employers have a statutory right to require employees to take annual leave at their direction, subject to providing staff with notice equal to at least double the length of the leave that you are directing them to take (e.g. 10 days’ notice for five days leave). However, this measure is not likely to achieve any urgent cost savings or alleviate immediate cash-flow pressure as holidays would need to be paid.

Clearly, annual leave can be taken on furlough so you could have staff on furlough and annual leave.

What first steps would you recommend to creating a strategy to integrate pro-active mental health first aid across the workforce?

The Thriving at Work Report and the recent NICE Workplace Mental Health Guidelines provide a good baseline for what all organisations should be doing on workplace mental health – this includes some guidance on training. There does need to be a plan in place and we recommend taking a holistic view of the integration of mental health first aiders into a business – ie it should be one component in a strategy that also comprises training for line managers, awareness training and education for all staff, peer support, and a documented framework for support and signposting.  It is also worth ensuring you have senior manager sponsorship, strong links with Occupational Health if available and also raising awareness via any works councils or employee forums helps ensure there is buy in at all levels.

What can I do as an employer if employees are known to be breaking the National Lockdown rules?

This will depend on the particular facts and the employee’s circumstances but an employee should co-operate with the employer so far as is necessary to enable compliance with any statutory duty or requirement relating to health and safety.

In addition, conduct outside of work can result in an employee’s dismissal if the conduct pertains to the employment relationship. If an employee breaches the lockdown rules and it affects their ability to work, such as it being no longer safe for them to attend work, or the reputation of the employer, these may be grounds for disciplinary action and subsequent dismissal.

How much data can I gather?

You also need to consider other aspects of data protection.

Be proportionate – only gather and use Covid-19 data where you need to.

Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.

Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to  make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).

Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.

Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.

Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.

Is it possible to apply for a grant of probate at the moment?

Yes. The system for Probate Applications has moved on-line and continues to be available as well as by post. However, if you need to complete an Inheritance Tax Return IHT400 you are likely to experience problems collating information due to delays in many organisations being able to provide you with current values while their offices are closed and staff working remotely. Property valuations will be particularly problematic where surveyors or valuers are unable to attend properties to undertake non-urgent work. If you cannot wait, you must use your best endeavours to be as accurate as possible as regards the information you provide in the IHT400 and follow up by providing HMRC with actual values as soon as you can do so. HM Courts and Tribunal Service is however warning that delays can be expected at this time.