In light of the ongoing COVID-19 pandemic across the globe, the European Data Protection Board recently released a statement regarding GDPR’s applicability in this time of crisis. The EDPB stressed that, even in these exceptional times, GDPR rules and regulations must be adhered to; they are perhaps more important now than ever. Below we list considerations that should be taken into account to guarantee the lawful processing of personal data during this time of crisis.
Organizations may be collecting information from personnel in an effort to manage the impact of COVID-19 that would not typically be collected. In an effort to manage the impact of the COVID-19 outbreak. For example, companies may collect information such as whether their staff have self-isolated or self-quarantined by collecting device location data. This information would be considered personal data, and as much as it pertains to individuals’ health, it would likely fall within special categories of personal data (“SCD”), which are subject to additional protections under GDPR.
Organizations may want to collect as much information as possible from individuals relating to COVID-19; however, the GDPR requires that they only collect as much personal data and / or SCD as is strictly necessary for the purposes being pursued.
Prior to collecting any personal data and/or SCD from individuals, organizations should have a clear purpose in mind, as well as a clear understanding of what personal data and/or SCD, and level of detail, is required to fulfil this purpose.
For example, if your organization is trying to determine whether your employees should be self-isolating at home, it may be sufficient to ask questions such as whether the employee, or anyone within the employee’s household, is displaying symptoms of COVID-19 or is an individual considered to be at high risk to experiencing severe COVID-19 complications on a ‘yes’ or ‘no’ basis, as opposed to asking for detailed and specific information.
The GDPR requires organizations to have a legal basis for processing personal data. Such legal basis includes legitimate interests, contractual necessity or legal obligation, or other country-specific legal basis (as outlined by that country).
Because COVID-19 related information likely would be considered SCD, then a further condition must be satisfied, such as: employment-related obligations, preventative or occupational medicine or public interest in the area of public health.
You should review your existing privacy policy and notices to ensure that these provide the necessary information regarding the data being collected and the purposes of processing.
If you are collecting new categories of personal data and/or SCD from individuals and using such data for new purposes, it will likely be necessary to update privacy notices to reflect the new changes in the collection of data from individuals.
There are a number of other issues that you should consider from a data protection compliance perspective, including:
Organizations should continue to monitor guidance issued by the EDPB, as well as the guidance of national data protection regulators in the countries in which organizations have a presence. Please feel free to contact us with any questions you may have about GDPR or other data privacy regulation compliance!