What do we need to do?
Privacy policy – You must make sure the relevant privacy policies deal with how you will process Covid-19 data. You should have an employee privacy policy and this may already deal with health data (if it doesn’t, it should). You might also need to look at privacy policies for customers, visitors and suppliers. This ensures that processing is lawful, fair and transparent.
Lawful processing conditions – You will need to consider which processing conditions you are relying on (remembering that you need both an Article 6 condition and an Article 9 condition – this is the part of the GDPR which deals with special category data). As a lot of the data you collect will be about employees, you can’t use consent so you will have to find another lawful reason under GDPR which allows you to process the data.
Appropriate policy document – When you are considering your Article 9 processing conditions, remember you must also have an “appropriate policy document” in place.
Processing record – Finally make sure your processing record is up to date with information on what data you collect and use.
Related FAQs
The current guidance issued by Mr Justice Hayden confirms that remote hearings may be conducted using the following facilities and that this will be the default position until further direction:
- By way of an email exchange between the court and the parties;
- By way of telephone using conference calling facilities;
- By way of the court’s video-link system, if available;
- The use of the Skype for Business App installed on judicial laptops;
- Any other appropriate means of remote communication, for example BT MeetMe, Zoom or FaceTime.
The FCA’s test case in the Supreme Court ruled overwhelmingly in favour of policyholders. However, business interruption cover generally has the prerequisite of physical damage or loss to the property (or in some circumstances, the presence of a notifiable disease at the property or within a certain radius of it), to recover losses caused by the interruption to your business. The onus is on insurers to re-assess those claims which are impacted by the Supreme Court’s judgment and to make contact with the policyholders regarding next steps. If you have not already made a claim, in the first instance the terms of any policy should be checked carefully to see whether business interruption cover is provided.
The government released further clarification on the Coronavirus Job Retention Scheme on 4 April. The wording referred to concerning public sector organisations and organisations receiving public funding remains the same.
The revised guidance does provide a helpful insight into how HMRC will deal with applications made to it for assistance under the scheme. It appears that there won’t be a particularly forensic approach adopted by HMRC. The guidance says you can furlough staff if you cannot maintain your current workforce because your operations have been severely affected by coronavirus.
It goes on to say that all employers are eligible to claim under the scheme and the government recognises different businesses/organisations will face different impacts from coronavirus. The need to demonstrate the impact of coronavirus on your business/organisation is not one of the criteria businesses/organisations are going to need to satisfy, so the government does not appear to intend to set a specific test to determine if a business/organisation is “severely impacted by coronavirus”. It is hoped that this should provide additional comfort to publicly funded organisations facing significant restrictions to their operations during the Covid-19 crisis.
It is where the need for a role at a specific site, or the number of people performing a role, has ceased or diminished or the site closes down.
- The Pensions Regulator has published regularly-updated guidance for employers.
- It will take “a proportionate and risk-based approach towards enforcement decisions … with the aim of supporting both employers and savers”. In other words, the law remains the same, but the Regulator will show restraint in enforcement against breaches.