Published on PublicTechnology.net (https://www.publictechnology.net)

Home > ‘Don’t create your own records of customer status’ – ICO warns venues on Covid Pass data-protection duties

‘Don’t create your own records of customer status’ – ICO warns venues on Covid Pass data-protection duties

Written by Sam Trendall on 16 December 2021 in News
News

Regulator updates guidance after introduction of new measures

Credit: Lufc83/CC BY-SA 3.0 [1]

After the introduction of domestic vaccine status checks, businesses have been warned not to keep records of customers’ vaccination or testing information.

As of 6am yesterday, the presentation of an NHS Covid Pass is a condition of entry for nightclubs and some large events, including concerts and sports fixtures.

Following the implementation of the measures across England, the Information Commissioner’s Office has published update guidance to help businesses in scope of the new rules to keep on top of their data-protection responsibilities.

Venues that perform only visual checks on digital or hard-copy documents are advised that this does not constitute the processing of personal data and GDPR is not applicable in this case. 

Those that use a scanning app to automatically validate users’ passes are engaged in personal-data processing, the ICO advised, and must thus ensure compliance with GDPR and all other data-protection statutes. 


Related content

  • Scotland will not extend vaccine passports to pubs, restaurants and theatres [2]
  • Wales to require Covid passes for nightclubs and large events [3]
  • NHS Covid Pass to be rolled out to 12- to 15 year-olds [4]

This includes establishing a lawful basis for the processing – in this case the legal obligation to do so is likely to be sufficient. 

Other considerations include being open and transparent about how, why, and what data is collected, and that staff can answer customers’ questions about data collection and processing. Firms are also reminded to ensure that all processes are secure, and that only the official NHS Covid Pass Verifier app is used to scan customer’s passes.

Whether status checks are digital or only visual, businesses are instructed: “Don’t create any of your own lists or records with your customers’ status.”

“Data protection is one of a number of factors to consider when… implementing Covid-status checks,” ICO guidance said. “You should take into account: employment law and your contracts with employees (if you are considering checking employees’ COVID status); health and safety requirements; and equalities and human rights, including privacy rights.

“You should also consider other regulations specific to your sector, as well as current public health advice and the latest government guidance in your part of the UK.”

The NHS Covid Pass is available via the NHS app, where it can also be downloaded as a document that be printed or displayed offline. Citizens can also request a letter to be sent to them which, as with the digital versions, will include a secure QR code.

The passes provide evidence of all doses received of a coronavirus vaccine – including third and booster jabs. The passes are also available for anyone who has recorded a negative test in the previous 48 hours.

The certifications are, however, no longer issued on the basis of natural immunity, where someone has recorded a positive test in the prior 180 days.

 

About the author

Sam Trendall is editor of PublicTechnology. He can be reached on sam.trendall@dodsgroup.com [5].

Tags
Data [6]
Policy [7]
Categories
Business and industry [8]
Public order, justice and rights [9]
#block-views-events-popup-block{ position: fixed; bottom: -30px; padding: 25px 22px; width: 360px; max-width: calc(100% - 30px); text-align: center; border-radius: 0 4px 0 0; color: #fff; background: rgb(0, 170, 200) none repeat scroll 0% 0%; -ms-transform: translateY(100%); -webkit-transform: translateY(100%); transform: translateY(100%); -webkit-transition: all .35s ease-in-out; transition: all .35s ease-in-out; z-index: 2; } #block-views-events-popup-block.show{ bottom:10px; transform:none; -webkit-transform:none; } #block-views-events-popup-block a.btn.btn--outlineWhite { border-color: #fff; color: #fff; background: transparent; } #block-views-events-popup-block .events-popup-close{ position: absolute; cursor: pointer; top: -30px; left: 0; height: 32px; padding: 7px 20px; border-radius: 4px 4px 0 0; color: #fff; background: rgb(0, 170, 200) none repeat scroll 0% 0%; font-size: 13px; } #block-views-events-popup-block .events-popup-close .icon--events-popupClose{ padding-left: 10px; font-family: inherit !important; } #block-views-events-popup-block .icon--events-popupClose:before { content: ''; width: 12px; height: 12px; margin: -1px 7px 0 0; background: url(https://www.publictechnology.net/sites/www.publictechnology.net/themes/pubtech_override/img/close-thin.svg) center no-repeat; background-size: 10px; vertical-align: middle; position: absolute; left: 10px; top: 10px; } #block-views-events-popup-block .views-field.views-field-nid .field-content{ display:none; }

jQuery(window).load(function() { if(jQuery('#event-popup-nid').length){ var eventId = jQuery('#event-popup-nid').text(); jQuery.cookie('eventPageId',eventId); var countCurrentValue = parseInt(jQuery.cookie('countCurrentName')) || 1; var combinedValueValue = eventId+'-'+countCurrentValue; var countCurrentValue = parseInt(jQuery.cookie('countCurrentName')) || 1; jQuery.cookie('combinedValueName',combinedValueValue); const result = combinedValueValue.split('-'); if( result[1] <= 3 ) { jQuery('section#block-views-events-popup-block').addClass('show'); countCurrentValue = parseInt(result[1]) + 1; jQuery.cookie('countCurrentName',countCurrentValue); combinedValueValue = eventId+'-'+countCurrentValue; jQuery.cookie('combinedValueName',combinedValueValue); } jQuery('.events-popup-close').click(function(){ jQuery('section#block-views-events-popup-block').removeClass('show'); }); } });

(function(e,t,o,n,p,r,i){e.visitorGlobalObjectAlias=n;e[e.visitorGlobalObjectAlias]=e[e.visitorGlobalObjectAlias]||function(){(e[e.visitorGlobalObjectAlias].q=e[e.visitorGlobalObjectAlias].q||[]).push(arguments)};e[e.visitorGlobalObjectAlias].l=(new Date).getTime();r=t.createElement("script");r.src=o;r.async=true;i=t.getElementsByTagName("script")[0];i.parentNode.insertBefore(r,i)})(window,document,"https://diffuser-cdn.app-us1.com/diffuser/diffuser.js","vgo"); vgo('setAccount', '253344499'); vgo('setTrackByDefault', true); vgo('process');
Close
Sign up for our free daily newsletter
Register here
6472
Dods PublicTechnology.net is a Merit Group plc title

Quick Links

  • Home
  • News
  • Opinion
  • Features
  • Private Sector Insight
  • Cyber Week
  • White Papers
  • Events
  • On Demand Webinars
  • Partner Directory
  • About
  • Contact

Services

Dods People Dods Political Intelligence Dods ResearchDods EventsDods Training

Media & Publishing

PoliticsHome Parliament MagazineHolyroodThe House MagazineCivil Service WorldTraining Journal

About Dods

Dods Group Part of Merit Group Privacy Policy Terms & Conditions Advertising Sponsorship
Privacy PolicyTerms & ConditionsAdvertisingSponsorship Subscriptions
  • Registered office: 11th Floor
  • The Shard
  • 32 London Bridge Street
  • London SE1 9SG
  • Company number: 04267888
  • © Merit Group plc 2021

Source URL: https://www.publictechnology.net/articles/news/%E2%80%98don%E2%80%99t-create-your-own-records-customer-status%E2%80%99-%E2%80%93-ico-warns-venues-covid-pass-data

Links
[1] https://creativecommons.org/licenses/by-sa/3.0/deed.en
[2] https://www.publictechnology.net/articles/news/scotland-will-not-extend-vaccine-passports-pubs-restaurants-and-theatres
[3] https://www.publictechnology.net/articles/news/wales-require-covid-passes-nightclubs-and-large-events?utm_medium=email&amp;utm_campaign=Daily%20email%2020th%20of%20September&amp;utm_content=Daily%20email%2020th%20of%20September+Preview+CID_1bae49dd01a78d86d16897d0d6938b42&amp;utm_source=Email%20newsletters&amp;utm_term=Wales%20to%20require%20Covid%20passes%20for%20nightclubs%20and%20large%20events
[4] https://www.publictechnology.net/articles/news/nhs-covid-pass-be-rolled-out-12-15-year-olds
[5] mailto:sam.trendall@dodsgroup.com
[6] https://www.publictechnology.net/tags/data
[7] https://www.publictechnology.net/tags/policy
[8] https://www.publictechnology.net/categories/business-and-industry
[9] https://www.publictechnology.net/categories/public-order-justice-and-rights