• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Home
  • About
  • Contact

Daily Business Magazine

A magazine complement to the Daily Business website

  • Life, Arts & Leisure
    • Creative
    • Festival
      • Festival Reviews
    • Film
    • Food & Drink
    • Stage Shows
    • Life
    • Leisure
      • Rio Recommends – dog walks and cafes
    • Homes
    • Style
    • Travel
  • Opinion
    • Bill Magee
    • Craig Alexander Rattray
    • Karen Harvie
    • Keith Anderson
    • Russell Dalgleish
    • Terry Murden
  • Interviews
  • Notebook
  • Working Life
    • Careers & Management
    • Finance and legal
    • Technology
      • Tech Talk
    • Well Being
  • Daily Business News
    • All Content

Covid puts privacy compliance to the test

January 23, 2022 by Sean Morris Leave a Comment

Coronavirus is likely to remain a data protection headache for UK businesses in the year ahead, writes SEAN MORRIS


News headlines in recent weeks have highlighted how a number of large UK employers, including IKEA and Next, have changed sick pay entitlements for unvaccinated staff. But, as yet, not much attention has been given by the media to data protection implications when businesses gather information about vaccination status. 

Health information is special category personal data and ICO guidance makes clear that businesses are required to comply with all the UK GDPR requirements whenever processing vaccine status. 

It could be a difficult year for employers collecting and using this information without completing the necessary steps to ensure data protection compliance, Should John Edwards, the new UK Information Commissioner, make this an enforcement priority.

Public consultation on the ICO’s new Regulatory Action Policy will close on 24 March 2022, after which some indication of the ‘direction of travel’ can be expected.

Data security and breaches are very likely to remain a key area of the ICO’s enforcement activity, with the health sector having reported the largest number of breaches to the regulator in Q2 2021/2022. Already the ICO has published a preliminary paper on specific issues such as end-to-end encryption, and in the coming months further publications of its work on data security, such as online safety, are expected. 

For UK businesses, keeping up-to-speed with a succession of updates from the ICO will probably be the main challenge in 2022, particularly given the likelihood of detailed new guidance on data protection issues relating to marketing and employment. 

It was back in March 2020 that the ICO consultation on the draft direct marketing code of practice ended.  Also, a separate consultation on updating the Employment Practices Code concluded in October 2021 which addresses various issues including employment records with information about health, and monitoring of workers, where there have been considerable changes to business practices because of the Coronavirus pandemic. 

As we all know, advances in technology have facilitated increased home working, and hybrid working arrangements are ‘the new normal’ for many UK businesses. 

Additional security risks

But inevitably this model produces additional data security risks.  On the one hand, businesses are required to have appropriate security arrangements in place for when home-working staff access customer personal data, for example, and at the same time, businesses must consider privacy, and balance these security measures with safeguards that protect against inappropriate monitoring of staff.  

Updated guidance, it is hoped, will be more of a help than a hindrance for management, given the considerable upheaval which they continue to deal with arising from the pandemic.  However beneficial the new guidance proves to be in the long run, its publication will in the short term require reviews and (most probably) updates of operational practices and policies, and further training for staff to ensure compliance, imposing additional strain on limited resources for businesses.  

For better or worse, it may be that before issuing updated guidance, the ICO awaits outcomes from last year’s government consultation on changing UK data protection laws following Brexit. 

The Department for Digital, Culture, Media & Sport (DCMS) consultation, titled “Data: A new direction,” prompted the ICO to acknowledge that the government’s freedom to adapt laws could enable UK businesses to employ risk-based, practical approaches to meeting their GDPR data protection obligations, for example when transferring data from the UK.  

The DCMS package of global data protection aims to boost growth, increase trade and improve healthcare and public services.  It includes new multi-billion pound global “data adequacy” partnerships, initially with six priority territories (the USA, Australia, the Republic of Korea, Singapore, the Dubai International Finance Centre and Colombia) with potential future partnerships with other fast-growing economies (such as Kenya, India, Brazil and Indonesia).  

As yet, no announcements have been made about when outcomes from the DCMS consultation will be published.  Certainly some of the DCMS proposals would likely be welcomed by most UK businesses: for example, they have consulted on whether to introduce a fee structure (modelled on the Freedom of Information Act 2000) for subject access requests. 

But other proposed changes, such as bespoke UK standard contractual terms (SCCs) for personal data international transfers (which DCMS refer to as International Data Transfer Agreements (IDTAs)) will yet again require businesses to take legal advice before updating and/or reviewing operational practices to ensure data protection compliance.  

However much the current government is keen to pitch those changes as post-Brexit opportunities which are pro-business, in the short term they are likely to be viewed by many UK businesses as further challenges to be overcome in the year ahead. 

So much to think about.

Sean Morris is a legal manager at  Navigator Law, a Vialex company

On Wednesday 16 March,  a Navigator Law Spring Series Webinar will include a summary overview of ICO enforcement actions in 2021 and an update on any announcements from the ICO and the new Information Commissioner.  It will be delivered via Zoom and is free of charge to attend.  Places can be booked online , by email or telephone: 0333 2400 308.

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)

Related

Filed Under: Finance and legal, Sean Morris, Working Life Tagged With: GDPR

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar



Editor’s Pick

Reston Station

Reston back on track after half a century

Julena Drumi

… [More...] about Reston back on track after half a century

Angus Grossart

Obituary: Sir Angus Grossart

Terry Murden

… [More...] about Obituary: Sir Angus Grossart

Terry Murden

Late call to replace Lord Smith | SNIB and the bottle bank

Terry Murden

… [More...] about Late call to replace Lord Smith | SNIB and the bottle bank

Edinburgh-Park-Tapestry-with-Celia-Joicey-Director-Dovecot-Studios

Weaving culture into Edinburgh’s office life

Julena Drumi

… [More...] about Weaving culture into Edinburgh’s office life

Advertising



Footer

  • All Content
  • Site Map
  • Privacy Policy
  • Facebook
  • Twitter
  • Instagram
  • Email
  • LinkedIn
  • WordPress

Copyright © 2022 · Design by jPAD Consulting · Magazine Pro · Genesis Framework

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
 

Loading Comments...