New guidance has been released asking employers to allow their employees to work from home where possible, so long as the business needs will not be disrupted. In light of this, we thought it would be useful to provide a summary of what risks employers should be considering from a data protection perspective, should their staff be working from home.
Everyone has an obligation to ensure that data protection guidelines are still followed when working from home, employees should be adopting the same mind set at home as they do in the office.
What risks should employers be considering?
- Lack of data protection measures – Home working environments must have the correct technological and organisational measures in place to ensure that security risks are non-existent. Some points to consider are;
-
- Keeping data confidential
- Keeping data records accurate and up-to-date
- Ensuring that all data can be accessed when it is needed
- Considering how employees use shared networks either at home or in a public place if working from a location.
- Facilitating data subject rights requests – ordinarily data would be held centrally. When working from home this can result in hard copy files being used outside of the office environment and employees may be using their own devices therefore, posing a challenge to employers as they could struggle to accurately and quickly respond to requests and collate relevant data records.
- Forgotten rules – when employees are working from home it is worth reminding them about their obligations surrounding data retention and accuracy, as this can easily be forgotten when working from home.
- Failure to report data breaches – there may be a knock-on effect on the number of breaches that are reported because of a homeworkers fear of the repercussions or have a reduced perception of the risks surrounding them. This could therefore impact employers as they could be missing statutory reporting deadlines by not effectively managing their breaches.
- Policies lacking information about homeworking – employers should have policies and documents in place on how they are managing their data. These documents may not have incorporated homeworking and could pose a risk to employer’s data protection obligations.
- Storage of equipment – employers should discuss with employees about how they should store equipment and access details whilst at home. If they are travelling between home and work, is the device secure during travel?
What can employers do to reduce risk and improve data protection?
- Carry out a DPIA – complete a data protection impact assessment (DPIA). These do not need to be lengthy complicated documents but will adequately highlight any areas of homeworking that would pose a risk therefore allowing employers to put measures in place.
- Inform employees – regularly update employees on their obligations surrounding data protection whilst working from home, stressing the implications organisations could face if breaches occur.
- Software and hardware support – make sure that devices are protected and have the right level of access for that member. Work out a way that support can be accessed from home if needed.
- Update policies – review related policies and procedures and update these in line with homeworking arrangements. When informing staff of the changes highlight the main areas of change and ask them to familiarise themselves with these. If employers are implementing new data processing activities (specifically surrounding home working and monitoring employees staff activity) privacy policies will need updating.
- Conduct regular gap analysis – identify any remaining areas of improvement on a regular basis by conducting regular gap analysis on processes and procedures.
If you would like any more information on how FusionHR can help, with your data protection needs, whether that is gap analysis or policy updates, please call 01924 827869. If you are already a DPO client, please email your consultant to discuss this further.






