
If there is no possible way for employees to work remotely and they are physically required to attend work, there are still questions about whether COVID-19 testing should be mandatory and introduced to the workplace.
In preparation of this, we thought it would be useful to provide you with some top tips from a GDPR perspective.
Considerations employers should be making
Necessity
Before employers start processing personal data they should be looking at why it is necessary to do so? Employers should ensure that the reason they are processing the data falls into one of the 6 lawful bases as set out in Article 6 of UK GDPR;
- Consent
- Contract
- Legal obligation
- Vital interest
- Public tasks
- Legitimate interest
In this scenario (COVID-19 testing in the workplace), would ordinarily fall under ‘legitimate interest’ and ‘legal obligation’. These lawful bases would apply as the employers will be aiming to provide a safe working environment to all employees.
As I am sure you can appreciate, each employer’s scenario will be slightly different. Before deciding that there is a legitimate reason for embarking on COVID-19 workplace testing, the context of each case needs to be considered. Some questions employers could be asking themselves are:
- As a result of COVID-19 workplace testing is this actually going to provide a safe working environment? Will this processing activity impact the outcome?
- Have I considered any other less intrusive methods?
DPIA’s
Before starting any new data processing activity employers should be completing a Data Protection Impact Assessment (DPIA) especially when processing special category data. A DPIA will allow employers to;
- Assess the risk of processing the personal data and help to mitigate against these risks
- Demonstrate to the ICO and the data subjects that as an employer they are GDPR compliant and care about how personal data is processed
- Be assured that the personal data being processed will be held securely
- Understand who will have access to this data and why?
- Be compliant with retention guidelines
- Ensure that the personal data being stored is RELEVANT, employers do not want to get into the habit of storing too much personal data about data subjects that is not relevant to that particular situation. This is a risk that can easily be identified through a DPIA.
Accuracy
Accuracy is another key principle of GDPR, it is vitally important that employers are:
- Keeping data on file that is up-to-date
- Only holding the data for the necessary amount of time
Open discussion
One of the 7 principles of The GDPR is ‘transparency’, employers should ensure that they are being transparent with their employees about any data implications that could occur during this activity. Employers should also explain how the testing process will work.
It is our recommendation that this should be in writing and delivered in a manner that is clearly understood to employees. We emphasise ‘clearly’, as it is a GDPR requirement that the data subject clearly understands how their data is being processed and why. Employers may decide that including this activity within their staff privacy notice will suffice; it could be added as an additional provision. Again, we must stress that employers will need to make their employees aware that they had amended the privacy notice.
Some of the key points employers should communicate to employees are:
- Why the testing is necessary
- What data is collected and stored
- How employers will use the data
- Who it may be shared with
- Retention period
The communications sent to employees should also include a reminder of their rights in relation to processing personal data, one recommendation of how to achieve this is directing them to the ICO website.
Any readers who have listened to our previous webinars will know that we recommended employers consult with their data subjects before the processing activity commences, this is not mandatory but is seen as good practice. In this example, we appreciate that due to the time sensitive nature and safety aspects employers need to consider, it may not be possible to conduct a full consultation, as employers would ordinarily do. If a small consultation can still take place, allowing employees to raise any data-related concerns, before this processing activity starts, that would be ideal.
Confidentiality
It goes without saying that the personal data being processed needs to be kept confidential at all times. This is especially prevalent as much of the data being stored is classed as ‘special category’ This situation may allow for a slight degree of flexibility as employers may need to inform other staff of a positive result being returned as they themselves may then need to isolate/follow the necessary guidance.
However, employers should ensure that they are not oversharing and that there is a very definite need to share this information. Unless the employee gives consent for their name to be given (it is recommended you receive this in writing), the name would not be seen as ‘pertinent’ information to divulge.
How we can support you?
If you need further help with Data Protection or have specific queries about this blog, please do not hesitate to get in touch. Our DPO service can provide as little or as much help as you need. You can find out more on this link or call our team on 01924 827869. You could also join our next DPO webinar, take a look at the events coming up.






