A group of Anthony Collins Solicitors (ACS) experts from across our various client sectors have gazed into their crystal ball and given us a view on how 2021 is looking.
We’ve seen claims that data protection laws can be put aside during the coronavirus crisis, and conversely, that complying with data protection rules would tie the hands of those trying to help out or adapt their work during this time. These are both myths, which we are happy to provide clarity on, and advise on good practice in light of the ways the coronavirus is affecting our working lives.
Like many things, the truth is somewhere in the middle, and the key message to employers is that while the UK’s data regulator, the Information Commissioner’s Office (ICO), have said they’ll show understanding if resources are directed away from tasks such as responding to SARs (subject access requests) within legal timescales, the data protection laws still very much apply and breaches will be taken seriously.
However, the rules do not prevent organisations from changing how they work in order to protect people’s health, as long as appropriate controls are in place.
Those controls are especially important now that the new normal for many office-based workers is working from home. Some will have already worked from home occasionally, but for others, it will be a completely new experience, and the data security risks are amplified with such a large proportion of the workforce currently based at home. This applies to charity and church volunteers too, with many meetings now taking place remotely.
Organisations that are now using increased homeworking should assess and mitigate the risks through secure processes as well as proactive and supportive management of your people.
- Wherever possible, reduce the reliance on paper documents, and where paper is used, it should be stored and disposed of securely, not in regular household waste or recycling;
- Consider if you can reduce the amount or type of data that employees need to handle while at home. Can some aspects of jobs be done differently, at least for the short to medium term?
- Where your normal processes rely on obtaining consent, remote working will mean that consent is now obtained over the phone or email, which is perfectly acceptable, as long as a clear audit trail is kept for your records;
- Provide your employees with secure, tried and tested, systems for remotely accessing your computer systems, so their work is still protected by all the controls they would have if working in the office, including firewalls and encryption;
- In particular, personal email addresses or social media accounts should not be used as a substitute for company email addresses and accounts;
- Review, and update if necessary, your policies around ‘BYOD’ (bring your own device) if staff are using their own laptops and PCs;
- The use of video-calling platforms can reduce the feeling of distance between colleagues, but it can also be an unnecessary invasion, and could cause embarrassment and even a safeguarding risk, depending on who could unknowingly wander into shot, so consider your rules for the use of cameras, and whether there is an expectation to use them;
- Video-calling platforms also bring potential new security risks, which should be assessed before using anything you’ve not used before, such as Zoom. There may be a temptation to rush to use new technologies in times of crisis, but due diligence should always be done first;
- Organisations may feel inclined to introduce new methods of monitoring employees who are working remotely, but employers should be honest and transparent about this, and ensure the monitoring is lawful and proportionate, and again, due diligence should be done on any software that might be used.
It isn’t enough to provide secure processes; companies must ensure their employees are trained in how, as well as why, to use them. Good communication and management should help reduce the risk of people finding shortcuts around the secure systems, either to make their job easier, or for more worrying reasons.
- Train employees in your secure systems and good practice to protect confidentiality at home. This includes ensuring computers are locked when not in use, especially if inquisitive children are around, and being aware of, and avoiding, other people overlooking their screen or overhearing confidential conversations.
- Remember that “home assistant” devices, like Alexa and Google Home, are listening too! These should be switched off if sensitive conversations are being held nearby.
- Despite secure systems and training, people do still cause data security breaches. Most often through human error, which may be more likely when employees feel stressed or distracted by worries, which is very likely in these unprecedented times. Sometimes, employees purposefully cause data breaches, and this is often aggrieved employees, who intend to hurt their employer, or plan to leave the organisation and take data with them. Both of these types of data breaches – in error and on purpose – could be reduced by careful management, and support, of employees working from home.
Luton Borough Council was prosecuted by the HSE late last year following an incident at a high school in which an assistant headteacher was attacked by a pupil and left with life-changing injuries.
This ebriefing looks at the proposal to set out 'public procurement principles' in the proposed procurement legislation.
Happy New Year - our first newsletter of 2021! Throughout this year we will continue to bring you news and developments relating to the charities sector.
Local authorities should be wary of reserving contracts for local suppliers, as recommended by Procurement Policy Note (PPN) 11/20. Other contracting authorities may want to maximise their use of this
Most housing practitioners have perhaps been waiting for this news since the latest lockdown was announced by the Prime Minister on 4 January 2021.
Climate change and biodiversity is an area where significantly faster changes are needed on a global and local basis.
Chris Lloyd Smith, Adrian Leonard and Lisa Whitehouse discuss the planning opportunities available to owners of businesses and how to prepare for unforeseen events.
In their 3rd podcast of the series, Chris Lloyd-Smith and Maria Ramon discuss a number of problems with and difficulties that can arise in mediation and the mechanisms they use to overcome them.
Our previous round-up began by sharing the news that two vaccines had shown very promising test results. Here we are, not even a month later, and the first vaccines have already been administered!
To receive invitations to our events, as well as information and articles on legal issues and sector developments that are of interest to you, please sign up to Newsroom.