Covid-19 Update: We are continuing to provide our usual services whilst maintaining the safety of clients and colleagues. Read our latest update here.

Complete the form below to ask us a question or make an enquiry. We’ll get back to you via phone or email as soon as possible.

Insights

Data protection: European Data Protection Board issues statement that may inform the ICO’s approach during the coronavirus pandemic

Posted on 31st March 2020 in Intellectual Property, Employment, Coronavirus Pandemic

Posted by

Jill Headford

Partner and Solicitor
Data protection: European Data Protection Board issues statement that may inform the ICO’s approach during the coronavirus pandemic

On 20 March the EDPB made a statement on processing of personal data in the context of coronavirus. The European Data Protection Board (EDPB) is the European body tasked with providing guidance aimed at ensuring consistent application of data protection regulations throughout member states.

During the Brexit transition period and likely afterward, EDPB statements will inform the Information Commissioner’s Office (ICO) approach. While the ICO have already provided some detail on their own website, the EDBP statement provides useful additional detail for businesses and organisations unsure of their data protection obligations during the pandemic.

The EDPB acknowledged that tackling the disease should be supported but said that controllers and processors must still process personal data lawfully.

With regard to restricting data subjects’ rights (i.e. allowing data controllers to do things otherwise not usually permitted) emergency is a legal condition which may legitimise restrictions provided they are proportionate and limited to the emergency.

The EDPB highlighted that the GDPR already allows authorities and employers to process personal data in an emergency without consent. For example where they have lawful authority, where it is necessary for reasons of substantial public interest in the area of public health and to protect an individual's vital interests. The GDPR specifically refers to the control of an epidemic at recital 46.

In an employment context, processing may also be necessary for compliance with a legal obligation such as health and safety or in the public interest (to counter threats to health).

The EDPB remind data controllers that the law must still be adhered to, so personal data should be processed for specified and explicit purposes and privacy notices need to inform data subjects about how the pandemic may change how their personal data is processed. Data protection policies should still prohibit data from being unlawfully disclosed. If decisions are taken to process data as a consequence of the epidemic these should be documented.

A copy of the EDPB statement can be viewed here

The ICO’s guidance can be viewed here

Company & Industry

Related Insights

Insights

Supreme Court delivers judgment on whether iPhone users entitled to compensation

Posted on 12th November 2021 in Intellectual Property

In a very clear judgment handed down on 10 November 2021, the Supreme Court has confirmed that, in order to claim compensation from an organisation which has breached its requirements as a data controller under the Data Protection Act 1998 (“the Act”), an individual must prove that the failure has caused material damage or distress to the individual concerned.

Posted by

Oliver Kent

Trainee Solicitor
Insights

Homeworking and the importance of cybersecurity

Posted on 25th March 2021 in Intellectual Property, Coronavirus Pandemic

Having staff working remotely has presented significant challenges for many businesses, but one of the most difficult to address is the increased cybersecurity risk. As many companies did not have sufficient opportunity to prepare for the transition to homeworking, they may not have identified potential cybersecurity issues. Moreover, it is now much harder to monitor staff and ensure they are following safe practices.

Posted by

Jill Headford

Partner and Solicitor