Covid-19 (Coronavirus) privacy notice
This privacy notice is an addendum to our corporate privacy notice, and explains how Achieving for Children (as Data Controller) may use your personal data, specifically in relation to the Covid-19 (Coronavirus) pandemic.
Personal information we hold about you
You may have already provided information for a specific reason, and we would usually seek to inform you that the data provided would be used for a different purpose. Due to the rapidly emerging situation regarding the current pandemic, this will not always be possible. If we already hold information regarding vulnerability, we may share this for emergency planning purposes or to protect your vital interests by sharing with services both inside and outside AfC.
In this current crisis, we may need to ask you for sensitive personal information that you have not already supplied, including your age or if you have any underlying illnesses or are vulnerable. This is so that Achieving for Children can assist and prioritise its services.
We have published a separate privacy notice on the records we maintain to support NHS Test and Trace.
Why we may need to share your personal information
In this current pandemic, we may share your information with other public authorities, emergency services, and other stakeholders as necessary and only when necessary in a proportionate and secure manner. Contact with you to obtain consent before sharing will not be required for all the reasons described in this notice. Please be assured that protection of personal data remains a priority at this time after the health and safety of everyone.
We will only share your personal information where the law allows, and we always aim to share the minimum data necessary to achieve the purpose required. Further, the information will only be used for the purposes listed and retained for limited specific times.
The UK General Data Protection Regulation (GDPR) and Data Protection Act 2018 allow us to share information for a wide variety of reasons. These are known as our ‘lawful basis to process data’.
Data protection laws facilitate valid information sharing, especially in times of emergency which often requires more collaborative working. The lawful basis for processing data at Achieving for Children during the COVID-19 pandemic are as follows:
- Fulfil an explicit statutory or government purpose
- Protect the public
- Satisfy external regulatory requirements
- Safeguard children and individuals at risk, and
- Protect our staff
We also have a duty to comply with the obligations set out in other legislation. The list below shows some common examples, but is not exhaustive:
- Care Act (2014) – this allows Achieving for Children to share data to promote individual wellbeing, support individual need for care and promote the integration of health and social care.
Children’s Act (1989) – this allows Achieving for Children to share data to safeguard and promote the wellbeing of children.
- Homelessness Reduction Act (2017) – this allows Achieving for Children to share data as part of taking reasonable steps to help applications secure accommodation.
- Civil Contingencies Act 2004 Part 1 Local Arrangements for Civil Protection – Civil Protection – Disclosure of information 6 (1) A Minister of the Crown may make regulations requiring or permitting the ‘provider’ to disclose information on request to another person or body listed in any Part of that schedule known as the ‘recipient’.
Lawful basis for processing your personal data
- UK GDPR Article 6 (1) (c) – processing is necessary for compliance with a legal obligation to which the controller is subject.
- UK GDPR Article 6 (1) (d) – processing is necessary in order to protect the vital interests of the data subject or of another natural (living) person.
- Recital (more detailed explanation) 46 – The processing of personal data should also be regarded to be lawful where it is necessary to protect an interest which is essential for the life of the data subject or that of another natural person. Processing of personal data based on the vital interest of another person should in principle take place only where the processing cannot be manifestly based on another lawful basis. Some types of processing may serve both important grounds of public interest and the vital interests of the data subject as for instance when processing is necessary for humanitarian purposes, including for monitoring epidemics and their spread or in situations of humanitarian emergencies, in particular in situations of natural and man-made disasters.
- UK GDPR Article 6 (1) (e) – processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Article processing of special categories of data
- UK GDPR Article 9 (2) (c) – processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent.
- UK GDPR Article 9 (2) (g) – processing is necessary for reasons of substantial public interest.
- UK GDPR Article 9 (2) (h) – processing is necessary for the purposes of preventative or occupational medicine, where is it necessary for the provision of social care, the provision of health care or treatment or for the management of a health or social care system.
- UK GDPR Article 9 (2) (i) – processing is necessary for reasons of public interest in the area of public health, such as protecting against cross-border threats to health or ensuring high standards of quality and safety of health care.
Data Protection Act 2018 (DPA):
Part 2, Chapter 2
- Section 7 (2) – Data Controller that is ‘public authority’ or ‘public body’ for the purposes of GDPR when performing a task carried out in the public interest or in the exercise of official authority vested in it.
- Section 8 – Lawfulness of processing: public interest
Schedule 1, (Special categories of Personal Data), Part 1 (Conditions relating to Employment, Health and Research etc),
Paragraph 3 Public Health
- This condition is met if the processing is:
necessary for the reasons of public interest in the area of public health and
- carried out by:
- or under the responsibility of a health professional, or
- another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law.
Schedule 1, (Special categories of Personal Data), Part 2, Substantial Public Interest Conditions
Paragraph 16, Support for individuals with a disability or medical condition
This condition is met if the processing:
- can reasonably be carried out without the consent of the data subject
- is necessary for reasons of substantial public interest.
Paragraph 18, Safeguarding of children and of individuals at risk
1. This condition is met if the processing is:
- necessary for the purposes of:
- protecting an individual from neglect or physical, mental or emotional harm, or
- protecting the physical, mental or emotional well-being of an individual,
- the individual is:
- aged under 18, or
- aged 18 or over and at risk,
- the processing is carried out without the consent of the data subject for one of the reasons listed in sub-paragraph (2), and
- the processing is necessary for reasons of substantial public interest.
2. The reasons mentioned in sub-paragraph (1)(c) are:
- in the circumstances, consent to the processing cannot be given by the data subject
- in the circumstances, the controller cannot reasonably be expected to obtain the consent of the data subject to the processing.
3. For the purposes of this paragraph, an individual aged 18 or over is ‘at risk’ if the controller has reasonable cause to suspect that the individual:
- has needs for care and support,
- is experiencing, or at risk of, neglect or physical, mental or emotional harm, and
- as a result of those needs is unable to protect himself or herself against the neglect or harm or the risk of it.
Your rights and access to information
You have several rights with respect to your personal data and these remain all intact during the current coronavirus pandemic. To request a copy of your data, please read the Individual Rights Requests page on this website and then submit your request using your preferred method of contact.
If you have any questions or concerns about the way we process personal data, please contact our Data Protection Officer: firstname.lastname@example.org