Vaccine Passports and how businesses can go wrong

Rob Masson, CEO, The DPO Centre comment on vaccine passports. Offers practical advice on how organisations can protect themselves when considering requests for health information

“Business owners need to ask what can be lawfully requested from customers and staff without overstepping data protection legislation? These are important questions to ask, especially for consumer facing organisations and the hospitality sector.”

“Organisations need to discuss the balance between an individual’s right to privacy and the wider impact on the public’s health.”

“For example, retailers don’t currently stop customers at their doors and ask anything about their health. So will it be seen that the Covid-19 passport is a necessary invasion into our privacy?”

“Current legislation classifies data relating to the health of an individual held by a company as ‘special category’ data. This is more stringently regulated and anyone collecting this type of data must follow strict guidelines to ensure it is processed securely.”

“First, if it is important to your business to ask either your customer or your staff whether they have either had the vaccine or have received a negative Covid-19 test, what is the legal basis for requesting and processing this information? Secondly, how should this data be securely held and for how long? Finally, who can access this information and for what reason? If the Information Commissioner comes knocking on your door, can you justify why the information was requested and retained?”

“It is vital businesses understand their exposure to personal data and privacy risk as it impacts every part of their business from employees to clients, partners and wider stakeholders.”

Notes to Editors

For further information please contact la@dpocentre.com [07788676913]


Attached Media


About The DPO Centre

Founded in 2017 by Rob Masson, The DPO Centre is the UK’s leading independent data protection resource centre, offering expert advice and ensuring organisations have access to the level of knowledge and expertise they require to comply with the highest standards of privacy and data protection.  Follow the DPO Centre on LinkedIn https://www.linkedin.com/company/dpo-centre/ The DPO Centre’s services include: • Providing outsourced Data Protection Officers on a ‘fractional’ basis (so 1 to 8 days per month) that become integral and trusted members of the client’s team • Interim and overflow resources to support and extend existing compliance teams • EU and UK representation as required by Article 27 of the GDPR • and a full range of privacy and data protection consultancy and training services to companies across all sectors in the UK.