Can an employer request staffs' coronavirus vaccination status?
With reports of Goldman Sachs asking their staff to disclose their coronavirus vaccination status, this raises the question of whether this is lawful. Can employers ask employees about their vaccination status and then retain that data?
Advice from the Information Commissioner’s Office’s (ICO) is that under the UK GDPR, employers collecting vaccination status information from employees must be doing so because it is necessary and relevant for a specific purpose.Where this is the case, the ICO confirms that there is a lawful basis for processing it. That said, before collecting vaccination status data, where the use of it is likely to result in a high risk to individuals (such as denial of employment opportunities), employers must first carry out a data protection impact assessment. This would need to consider why such data is needed, and the reason here must be clear and compelling. Whilst an employer may be able to justify collecting it in relation to making the workplace safe, particularly where there’s a health and safety risk to clinically vulnerable individuals, keeping it for monitoring purposes only would be much more difficult to justify.
Where an employer does decide to collect vaccination status data, they should only collect the information required for the purpose for which they’re collecting it and hold it for no longer than necessary. They must also be open and transparent and so should tell employees exactly what data is being collected, why they need it, what they’re using it for, how they will securely store it, for how long it will be retained and who will be able to access it (an employer can’t just share an employee’s vaccination status with other staff as that would breach the UK GDPR and duties of confidentiality). The collection of this data must also not result in any unfair or unjustified treatment of employees. Then, the position must be kept under continuous review.
Related Topics
-
Changes to NDAs from 1 October 2025
From 1 October 2025 non-disclosure agreements (NDAs) will become unenforceable if they prevent victims of crime from making certain disclosures. What does the new law say?
-
When will you have to register your new business for MTD?
The timetable for mandatory use of Making Tax Digital for Income Tax Self-Assessment (MTD ITSA) by existing businesses is well established. But when must you use MTD ITSA if you start a new business or create a new income stream?
-
EU law change for virtual events: how will it affect you?
Your business organises live events online, charging delegates a fee to attend. What are the rules about charging VAT and what changes took place on 1 January 2025 that will affect you if EU delegates attend your sessions?