Info center: privacy & COVID-19

Collecting health data through questionnaires

The issue of implementing questionnaires which gather health data and other information about the existence of risk factors, to both employees, collaborators and visitors, does not have a unified approach by the European Data Protection Authorities. While some authorities expressly prohibit such methods of systematic and general data collection, others allow organizations to make their own assessment and to decide…

Disclosing COVID-19 diagnosis

Companies explore whether they can disclose that someone has been diagnosed with COVID-19, in their efforts to protect staff and the general public. This article describes recent opinions published by EU Data Protection Authorities on the issue. Statement of the European Data Protection Board The EDPB, in its Statement on the processing of personal data in the context of the…

Legal basis for processing health data

Because health data represents a special category of data, the GDPR allows processing only in exceptional situations indicated in Art. 9(2). In the context of measures aimed at containing the spread of COVID-19, organizations are asking which is the correct basis (the exemption) which would allow them to collect data about the health situation of employees. This article sums up…