This year has been an incredibly tough one for most people in all walks of business and indeed in life with everyone facing a situation that has never been seen in our lifetimes.  Knowing how to navigate through it is incredibly difficult and organisations have inevitably struggled as a result.

This time last year organisations were faced with a very difficult prospect ahead of them trying to work out how Brexit was to take effect and what impact that would have on them.  That concern is still very real and yet for many is at the back of their minds as they try and deal with the constant changes, rules and regulations around coronavirus.

The Government have provided guidance for organisations on what changes they need to make in advance of Brexit taking place on New Years Eve this year with Jo O’Donovan, Commercial Solicitor at WBW Solicitors, recommending that organisations go through the guidance and questionnaire to ascertain what changes they may need to make. 

‘It is easy to forget that even through these hard times it is still of great importance to protect customers and clients alike.  Although the General Data Protection Regulation is EU legislation, its content has in effect been incorporated into UK law under the Data Protection Act 2018 (“the Act”).  Under that Act, an obligation is placed on organisations to protect Personal Data (ie any identifiable data relating to a person) from unlawful or unauthorised use.’

‘The pandemic has led to a number of increased risks which could lead to Personal Data being processed unlawfully or without authorisation and all organisations should consider this carefully.’

On Site

One risk factor for organisations is Personal Data taken on the organisations site.  This is especially difficult when we are seeing a significant increase of Personal Data being provided to organisations to allow for the Track and Trace to take effect. These organisations may not have taken Personal Data historically and may be unaware of their obligations under the Act.

Legally speaking, the Personal Data being provided to the Government is officially a Legal Obligation and therefore there is no concern over whether that information can be taken and provided.  How the information is taken however can potentially create an element of risk and so organisations ought to consider carefully how they deal with the Personal Data. 

Where data must be taken on site, scanning the Test and Trace App is a perfect solution for organisations as it means they do not take the data themselves.  However, in a situation where Personal Data needs to be taken from the customer/client in a public setting it is important for the organisation and subsequent employees to protect that information.  We have seen throughout the last 6 months’ situations where organisations have taken Personal Data which has then been visible to other customers.  This is a direct breach the Act as it is unlawful processing.  Organisations need to remember that Personal Data should be protected from unlawful or unauthorised processing or else they could be falling foul of the Act. 

Working from home

Consideration needs to be given to how employees will handle Personal Data when working from home.  Thought should be given to all aspects where Personal Data could be shared, lost, or breached.  For example, where any physical documentation with Personal Data is being stored, whether the employee may be in a room with a third party discussing an individual, whether the computers or laptop are personal ones and whether they have appropriate firewalls etc.  A Working from Home Policy may be particularly helpful in this situation to assist the employee to understand where their parameters are and also evidence how you need them to protect Personal Data.  The added benefit of such a document being you are also providing details on how you expect them to work. 

Online services

Many organisations have moved their services online for the purpose of continuing to provide a service to their customers.  This is a brilliant option and shows real foresight to allow services to continue.  Thought should however be given to how Personal Data may be shared on such a site.  If for example an organisation has decided to run a zoom class, will the customers/clients be able to see each other.  Will they be able to take screen shots or have they been asked not to?  If photographs are taken to post on social media to increase marketing awareness have all of the individuals consented to this?  This is even more important if children may be the subject of such Personal Data.

Pressurised working

The ICO have confirmed they have seen in increase in human error during the pandemic because of increased pressure and workloads during an unprecedented time.  Such errors include using CC instead of BCC on emails.  It is important to remind employees and associates of the importance of their data protection obligations and that they should take care when dealing with Personal Data.

What if I breach data protection laws during the lockdown?

The ICO have stated that they are understanding of the issues which organisations are facing.  They have seen and expect to see organisations slipping in their obligations.  It is unlikely they will hold an organisation to task for a minor breach especially during these times and they do appreciate the difficulties organisations are under but it is important to note that the law still allows for the ICO to hold organisations to account for any breaches.  This includes the potential for fines of up to £10m or 2% of annual global turnover. 

Whilst one would hope that such actions will only be taken under circumstances where there are persistent and/or obvious breaches the law still continues even if normality doesn’t and if an organisation processes Personal Data, it is their responsibility to keep that safe.

What should I do?

Stop and take a breath.  Organisations may find it helpful to write a list of where they take Personal Data and where a potential breach could occur in their organisation.  By going over such a list they can assess how to protect the risks that each aspect can pose and ensure they have the appropriate policies (ie Privacy Policy, Working from Home Policy etc) in place to inform the customer/client and employees of how the organisation will deal with those issues.  This is a healthy exercise for any business to do which also can be put towards evidence of compliance with data protection laws in the event a complaint is made to the ICO.  The ICO website also has lots of very helpful information to guide businesses through data protection.

If you have any questions on your data protection obligations please do not hesitate to get in touch with Jo O’Donovan, Commercial Solicitor, on 01626 202347 or joO’Donovan@wbw.co.uk. WBW Solicitors has offices in Newton Abbot, Exeter, Torquay, Paignton, Bovey Tracey, Launceston, Honiton, Exmouth and Sidmouth.

This article is for general information only and does not constitute legal or professional advice. Please note that the law may have changed since this article was published.