Skip to content

What security will be required for CBILS?

At the discretion of the lender, the Scheme may be used for unsecured lending for facilities of £250,000 and under.

Lenders were required to demonstrate lending additionality (i.e. lending that without the Scheme, wouldn’t have otherwise taken place). The Scheme has been extended to those businesses who would have previously met requirements for a commercial facility and would not have been eligible for CBILS.  As a result  it is suggested that all viable small businesses affected by Covid-19, and not just those unable to secure regular commercial financing, will now be eligible should they need finance to keep operating.

Primary Residential Property cannot be taken as Security under the Scheme. If the lender can offer finance on normal commercial terms without the need to make use of the Scheme, they will do so.

Related FAQs

Can employers reduce their pension contributions?
  • Yes, if contributions to a defined contribution (“DC”) scheme exceed statutory minimum for auto-enrolment purposes, it may be possible to reduce employer contributions to the statutory minimum, but not further.
  • However, the processes required for reduction of DC employer contributions will necessitate obtaining legal advice:
    • Reducing employer contributions may require changes to the employment contracts of affected staff (as does the furlough process).
    • Reducing employer contributions may also require negotiation with trade unions or other staff representative forums.
    • Where group personal pensions are used, the contractual format may not permit changes of employer contributions, and hence it may also be necessary to enter into a new contractual arrangement. Choosing a new group personal pension plan is a not insignificant task in itself.
    • Employers with at least 50 employees are required to conduct a 60-day consultation process with affected employees if they propose to reduce employer contributions (but please see below).
    • Finally, it may require a change to the scheme rules and engagement with the scheme trustees if the scheme is operated under trust.
  • For DB schemes, specific considerations apply (see the last section, below).
How much data can I gather?

You also need to consider other aspects of data protection.

Be proportionate – only gather and use Covid-19 data where you need to.

Keep data to a minimum – you shouldn’t gather more data than you need. You need to know someone has Covid-19 but you don’t need to know all their symptoms. Data minimisation also applies to who gets access to the data. It’s unlikely that a spreadsheet, accessible to everyone updating them on the health status of all employees, would be appropriate. Data should be shared on a need to know basis. You need to balance the privacy of individuals against your duty of care to be responsible with regards to the data of your employees, visitors, customers and suppliers.

Keep it up to date – make sure you update data. People’s health status will change and if you keep a record of this, you need to  make sure it is accurate and up to date (although this doesn’t mean you should batter individuals with constant requests for updates on health status. Again, be proportionate).

Identify individuals only when you need to – although you will need to know who has Covid-19, that doesn’t mean you need to tell everyone in the organisation. As soon as you can, you should remove personal data from any information you gather. For example, you might want to update employees on the health status of their fellow employees but you probably don’t need to name individuals and even if you feel it is necessary, you should keep the information you provide to a minimum. Removing personal identifiers in a document is also a good data security technique.

Keep the Covid-19 health data secure – Covid-19 data will be special category data and deemed high risk. This means that if you have a breach of this data you will need to notify it to the ICO. A breach could happen by someone losing a print-out of the names of Covid-19 employees, customers or visitors. It could also happen if you set access rights to lists of Covid-19 sufferers open to more people than need to know the information. The risk of ICO enforcement action increases with the potential harm the disclosure could cause. Although the ICO has indicated that it will be understanding about the impact of Covid-19 on normal operations, this doesn’t mean that they will not prosecute you if the breach is sufficiently serious.

Destroy the data once you don’t need it – Finally, of course, make sure that you delete data at the end of your needs. This might last longer than the pandemic, for example if you have an insurance claim or ongoing litigation. If you do need to keep it, consider whether or not you can delete some of the data to minimise what you hold.

How should an employer handle personal information in relation to NHS Test and Trace?

Employers will be collecting and sharing health information. Health information is sensitive and higher data protection standards apply. Here are a few key pointers.

  • Update privacy notices to cover the new collection and sharing of employees’ information and provide these to the workforce. Be transparent and fair.
  • Identify the legal basis and condition for use of this information and put any required paperwork in place. The ICO guidance will help. For some conditions such as the employment condition, an Appropriate Policy Document (APD) will be required. The ICO has an APD template.
  • Only use the information for the purpose of managing the workforce during the pandemic.
  • Only collect or share information if it’s necessary – if it’s a targeted and proportionate way of achieving your purpose.
  • Make sure any health information collected and shared is accurate – there may be serious consequences if it’s not.
  • Work out how long the information must be kept for. Keep a record of that period and act on it at the appropriate time.
  • Security is very important – there may be malicious actors trying to trick employers and employees. Make sure employees know how to identify a genuine NHS Test and Trace contact. Keep the information secure. Use the ICO’s data sharing checklists** and keep a record of the disclosures made and why. Control external disclosures – only certain authorised members of staff should make them.
  • Make sure individuals can still exercise their data protection rights – that’s also very important. Keep data protection records up-to-date and ensure any exports of personal information outside the UK are compliant.
  • Before introducing employer-led testing like taking temperatures, thermal imaging or other potentially intrusive tests, work out if a data protection impact assessment (DPIA) is required. It will be if the intended processing is ‘high risk’. If it is, then carry out a full DPIA. It will help address the issues systematically and mitigate risks.
  • All this demonstrates ‘accountability’ – it shows affected individuals and the ICO that the employer is complying with data protection requirements.

If you need further help, please visit the ICO’s data protection and coronavirus information hub or ask our data protection team.

** Please note that this link is to the ICO’s existing checklists and data sharing code of practice. We will update the link to the ICO’s new checklists after they are published.

What is the guidance for doctors working during the pandemic?

The General Medical Council (GMC) have published guidance online for doctors during this time of uncertainty.

 

Alongside this, their website displays guidance for temporary registration to approximately 15,000 doctors, who left the register or gave up their licence to practise in the last three years.

 

These clinicians have been contacted to assist with the growing pandemic, outlining the process they would follow and informing them of their right to opt-out. The Secretary of State for Health can ask the GMC to grant such registration under Section 18a of the Medical Act 1983, in an emergency.

I would like to make a Lasting Power of Attorney. How do I and my Attorney(s) get our signatures witnessed and who can be my Certificate Provider?

As with a Will, your solicitor can take instructions by telephone, Skype or a similar tool. Your solicitor can then post or email the documentation to you. As with Wills, your signature and those of your proposed Attorneys will need to be witnessed, but in this case only by one other person. However, there are specific requirements as to who can witness your signature. The witness must be aged 18 or older and cannot be your Attorney but they can be your Certificate Provider.

Your Certificate Provider must either be someone you have known personally for at least two years or an appropriate professional. However, they must not be your Attorney and they must not be a member of your family or the partner, boyfriend or girlfriend of a member of your family or a business partner or employee of yours.

Also, if you are living in a care home, the Certificate Provider cannot be the owner, manager, director or employee of the home you live in.

Given the current restrictions on movement, if you have regular medical checks you could ask your GP or another medical professional to witness your signature and act as your Certificate Provider when you go to see them or they come to you. Alternatively, if someone you have known for two years or more is dropping off essentials, they could act as a witness and Certificate Provider remembering to retain the necessary distance and protective measures.

Concerning your Attorney(s) you cannot act as their witness. Otherwise, anyone aged 18 or older can act as their witness, including the other Attorney. Ideally, a witness to your or your Attorney’s signatures should not be a family member for the sake of impartiality and to avoid disputes. If necessary they can be.