Skip to content

What do we need to do?

Privacy policy – You must make sure the relevant privacy policies deal with how you will process Covid-19 data. You should have an employee privacy policy and this may already deal with health data (if it doesn’t, it should). You might also need to look at privacy policies for customers, visitors and suppliers. This ensures that processing is lawful, fair and transparent.

Lawful processing conditions – You will need to consider which processing conditions you are relying on (remembering that you need both an Article 6 condition and an Article 9 condition – this is the part of the GDPR which deals with special category data). As a lot of the data you collect will be about employees, you can’t use consent so you will have to find another lawful reason under GDPR which allows you to process the data.

Appropriate policy document – When you are considering your Article 9 processing conditions, remember you must also have an “appropriate policy document” in place.

Processing record – Finally make sure your processing record is up to date with information on what data you collect and use.

Related FAQs

Can I ask for relief from KPIs or service credits under a contract with a public sector body if the Covid-19 outbreak means that I am having difficulty in performing it?

The Cabinet Office has published a useful Procurement Policy Note (“PPN”) on relief available to suppliers due to Covid-19 (available here). In brief, you should not be penalised by a public sector body, if, in the current circumstances, you are unable to comply (fully or partly) with your contractual obligations. Public sector bodies are expected to work with suppliers and, if appropriate, provide relief against current contractual terms. This is in order to maintain business and service continuity and avoid claims being accepted for other forms of contractual relief, such as the occurrence of a force majeure event.

The types of relief that may be available to suppliers to the public sector will depend on the existing contracts in place. Some contracts may have a payments by result mechanism, whereas others may be based on certain key performance indicators (KPIs) being met. Other contracts may not include any such mechanisms and therefore it will be a matter for discussion between suppliers and the public sector body.

The PPN provides that, rather than a supplier seeking to invoke a clause that would permit the supplier to suspend performance of its obligations (such as a force majeure clause), public sector bodies should first work with the supplier to amend or vary the contract. Any changes should be limited to the particular circumstances and considered on a case-by-case basis. Changes could include:

  • Amending the contract requirements
  • Varying timings of deliveries
  • Relaxing KPIs or service levels
  • Extending time for performance (e.g. revising a contract delivery plan), and/or
  • Preventing the public sector from exercising any rights or remedies against the supplier for non-performance (e.g. liquidated damages or termination rights).

These should only be temporary variations and the contract should return to the original terms once the impact of the Covid-19 outbreak on the contract has ended. Discussions with the public sector body about any changes that are agreed should be documented, in a variation signed by both parties.

A public sector may also need to take account of regulation 72 of the Public Contract Regulations 2015, to ensure that any changes to a contract (even of a temporary nature) do not trigger a requirement to conduct a new tender process. Whilst this may be unlikely to be the case with temporary variations, suppliers should still bear this in mind when discussing any changes to a contract with a public sector body.

If you are a supplier to a public sector body and you are currently struggling to meet your contractual obligations, we recommend that you take legal advice as to whether it might be possible to take advantage of the flexible approach that the PPN requires public sector bodies to adopt – it could be that you can avoid service credits or other financial deductions, or the need to serve formal notices such as “force majeure” or other relief notices.

 

 

In a situation where a building has a B1 EWS1 rating but the insurance companies are either refusing to quote or saying the cladding is a fire risk (due to the result of the intrusive survey for the EWS1 rating) and quadrupling insurance premium, is there anything that will help with this situation in the Building Safety Act or the secondary regulations when they come in or do you think it is something case law will have to address?

The amount an insurer charges for providing cover is a critical aspect of the underwriting process. The premium must be sufficient to cover expected claims but must also take into account the possibility that the insurer will have to access its capital reserve –it is risk assessment based and the greater the risk, the higher the premium. Historically, insurers of high-rise buildings would have only had to prepare for a loss caused by damage to just a few flats within a building. That is because the design and construction of that building, with the right materials and fire safety provisions in place, should have limited the spread of fire and allowed the damage to be contained –or at least make this an extremely low risk. Now we know that many buildings have been designed, built and signed off in a regulatory system that an independent Government review has found was not fit for purpose. Premiums will reduce overtime but will be dependent upon the perceived level of risk reducing as the regulatory regime, BSA and BSR become more established.

What rules has the European Commission introduced?

The Commission has provided guidance as to measures which Member States can introduce without notification. These include:

  • Measures which apply to all businesses within a Member State (for example the furloughing measures introduced by the UK Government)
  • Measures providing support direct to consumers
  • Measures which are already exempt from the notification requirement (discussed further below).

To respond to the crisis the European Commission has also issued a temporary framework to provide a basis for emergency aid to be notified for approval. The framework is initially in place until 31 December 2020. The Commission continues to keep this under review and has twice widened its scope to allow more types of aid to be notified. The type of measures covered include:

  • The provision of guarantees (including guarantees for 100% of loans)
  • The provision of loans at low interest rates, at zero interest rates or subordinated to senior debt
  • Measures to support liquidity needs or to alleviate difficulties caused by the current crisis
  • Measures to recapitalise businesses
  • Measures to assist sectors hit particularly hard by the current crisis (eg transport)
  • Measures targeted at COVID-19 such as research and development or production of products related to tackling the virus

The Commission has approved a UK Government “umbrella” notification to allow UK public authorities to adopt the measures permitted by the Commission framework. Therefore public authorities in the UK can use the Framework without notifying individual measures or schemes to the Commission.

What are the data protection implications of holding Covid-19 health data?

The ICO is providing new guidance to organisations regarding data protection and coronavirus, which can be accessed here: https://ico.org.uk/for-organisations/data-protection-and-coronavirus/

Information about the Covid-19 health status of individuals is special category data under the GDPR. This means it is high risk which has implications for how you use it, store it and keep it secure.

You will already hold health data about your employees as this is necessary to provide a safe, accessible place to work and to make reasonable adjustments to the workplace. You now need to make sure that the information you gather about your employees, visitors to your sites, customers and suppliers about Covid-19 is processed in accordance with data protection laws.

What should I be mindful of in relation to pregnant workers? Is there a right to suspend?

Yes, but as a last resort. In summary, the law requires employers:

  • to assess the workplace risks posed to new or expectant mothers or their babies;
  • to alter the employee’s working conditions or hours of work to avoid any significant risk to them;
  • where it is not reasonable to alter working conditions or hours, or would not avoid the risk, to offer suitable alternative work on terms that are not “substantially less favourable”;
  • where suitable alternative work is not available, or the employee reasonably refuses it, the employer should consider whether it is appropriate to suspend the employee on full pay.