Update your privacy policy
One of the most important steps in ensuring compliance is to keep an updated privacy notice, whereby the new processing activities intended to be used in the fight to prevent the spread of the virus are carefully reflected. As anticipated above, the legal grounds for processing under art. 6 of the GDPR and the guaranteed under art. 9 of the GDPR should also be mentioned. When selecting a legal ground under art. 6 of the GDPR, you may come to the conclusion that you have a legal obligation to process certain data or to make certain reports to competent authorities. It may also be that the processing of data is necessary to protect the vital interest of the employee in discussion or of another natural person or even for the company’s legitimate interest. In the latter case, it is important not to forget to run a necessity and proportionality test. The fundamental rights and freedoms of employees could be at stake and you should ultimately consider the need to implement strict safeguards to mitigate a disproportionate impact. When selecting a guarantee under art. 9 of the GDPR, as the Romanian data protection authority reminded in their recently published guidance, that the processing may be necessary to comply with your obligations under health and safety regulations or the collection may be necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats.Make sure your employees know what to do
Furthermore, it is not only a complete privacy notice that matters, but also a really good awareness program. Employees should always be informed about what they need to do in order to limit the spread. They should at least be informed of the following aspects:» measures that must be taken by an employee in case he/she has a suspicion of contagion (e.g., immediately go home and alert the competent authorities);
» hygiene-related recommendations for the employees (e.g. to wash hands on a regular basis, avoid crowded places, avoid unnecessary meetings or travels, the list of restricted travel areas etc.);
» specific symptomatology of COVID-19 and the measures that must be taken into account by the employees in case of any sign of illness (e.g., immediately inform the employer or the authorities);
» measures taken by the employer in order to ensure confidentiality.
Don’t tell everybody the name of the possibly affected co-worker
If an employee decides to open up about a concern he/she may have in relation to a possible infection, it is possibly best to have a dedicated team for this, in order to keep such health-related information on a need-to-know basis. Implementing a secured line for this aim has also been a trendy recommendation amongst privacy professionals. Furthermore, if you have a confirmed case among your personnel, it is probably best to avoid the public display of the individual’s name, due to the possible consequences of such disclosure. It is indeed true that during the declared state of emergency, the right to private life is restricted, but no law provides for an express derogation in this respect. And most certainly no law allows gateways to bullying and discrimination. Companies must make a serious assessment before giving away a confirmed case’s name among their peers. In all cases, this shouldn’t be done, unless essential.DIY, but with let the authorities do their job
When identifying a case, companies are encouraged to communicate with the competent authorities, in order to ensure they maintain a healthy and safe environment for the employees. In order to avoid immediate threats, discussions on direct contacts with the infected employee could also be engaged, in order to ensure isolation at home of potential cases. An “act first, ask later” type of approach may come in handy sometimes, but such behaviour cannot and will not justify any processing activity. Also, when allowing the employees to work from home, secured connections should also be a concern. Technical measures should be in place in order to ensure the integrity of the used IT means or at least the employees should be reminded of how they are allowed to use their gear. Last but not least, if the internal plan is doubled by questions on recent travel history or symptoms, it is advisable to perform a data protection impact assessment if the processing is likely to result in a high risk to the rights and freedoms of employees. If you decide to monitor the health of your employees on a large scale and by using intrusive potentially inefficient means (for example, thermal scans or daily HR talks on symptoms), such monitoring may fail the test and result in fines, if not treated seriously. Activating action plan When implementing step plans in the fight against the novel coronavirus, you should have in mind the following mantras:» Run awareness programs within the company. Teach your employees what a responsible contact means. Let them come to you in need.
» Ensuring the lawfulness and legitimacy of the new processing activities.
» Keeping an updated privacy notice is always a good idea – an informed employee is a protected employee.
» Public health does not justify the irrational collection of large amounts of data of your employees. Don’t store your information for too long either.
» Collected data in the context of the pandemic should be circulated internally only on a need-to-know basis.
» Ensuring secured lines for the employees to safely disclose if they see a threat to their peers’ health is safer and cleaner.
» Don’t name names without firstly assessing if that’s really necessary - don’t expose your employees to the risk of being bullied!
» Instead of asking everybody if they had contact with an employee at risk, it is maybe better to ask the employee at risk of his/her whereabouts.
» Thermal scans will most probably be considered too invasive and not necessary.
» When letting your employees work from home, it is maybe best to remind them of your Acceptable Use Policy.
Last but not least, managing the risks related to the COVID-19 and trying to prevent the spread of COVID-19s do not imply assuming hypothetical risks of non-compliance with GDPR. In this sense, employers should ensure they document any decision-making process regarding measures implemented to manage COVID-19, which involves the processing of personal data. Also, any data processing in the context of preventing the spread of COVID-19 must be carried out in a manner that ensures the security of the data, in particular where health data is concerned. In the end, don’t forget the data minimisation principle. Only the minimum necessary amount of data should be processed to achieve the purpose of implementing measures to prevent or contain the spread of COVID-19. The rest of the activities in the context of the effort related to preventing the spread and the healing of COVID-19 disease, it is the public authorities’ responsibility, So, if it’s the physician or the authority’s duty, then you probably shouldn’t do it yourself. You can read and download this legal alert in PDF format here.