{"id":40355,"date":"2020-03-26T09:57:45","date_gmt":"2020-03-26T08:57:45","guid":{"rendered":"https:\/\/zuniclaw.com\/covid-19-didnot-suspend-gdpr-dont-get-your-hopes-up\/"},"modified":"2025-05-15T13:33:10","modified_gmt":"2025-05-15T11:33:10","slug":"covid-19-personal-data-protection","status":"publish","type":"post","link":"https:\/\/zuniclaw.com\/en\/covid-19-personal-data-protection\/","title":{"rendered":"COVID-19 did(not) Suspend GDPR &#8211; Don&#8217;t Get Your Hopes Up"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"40355\" class=\"elementor elementor-40355 elementor-33378\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-564c1d92 e-flex e-con-boxed e-con e-parent\" data-id=\"564c1d92\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6117bbd9 elementor-widget elementor-widget-text-editor\" data-id=\"6117bbd9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>To perform more successful treatment of the infected patients and spread awareness about the coronavirus and protection methods, data concerning the health of citizens is more exposed than usual. In this blog, we will take a glance at the issue of conflict between the two fundamental civil rights: <strong>the right to healthcare<\/strong> and the <strong>right to the protection of personal data<\/strong>.<\/p><p>In the previous few weeks, <a href=\"https:\/\/zuniclaw.com\/en\/covid-19-report\/\"><strong>the coronavirus \u2013 COVID-19<\/strong><\/a>became the burning topic on newspaper cover pages all around the globe. The state of emergency declared on a global level, caused the need for adjustment to the new circumstances, evoked by the pandemic. In only a couple of days, national government authorities issued numerous decisions in order to suppress the virus and preserve the public health. Along with those which are widely familiar due to the media attention they attract, such as shutting down the hospitality businesses or curfew, some of the introduced measures are especially significant from the privacy law aspect.<\/p><\/div><\/section><div class=\"av-special-heading av-3dxnb1q-3986942f0efd06777c4eeb960ee75146 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-14 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">EU Legal grounds<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>Article 9 of the <a href=\"https:\/\/gdpr-info.eu\/\" target=\"_blank\" rel=\"noopener\">General Data Protection Regulation (GDPR)<\/a> classifies health-related data into the special category of personal data, which is under a higher level of protection. Whereas the processing of data not labeled as \u201cspecial\u201d is allowed as long as one of the six legal grounds are fulfilled, processing of this type of data is prohibited. There is an exception to every rule, so GDPR previses when this one can be bypassed.<\/p><\/div><\/section><section class=\"av_textblock_section av-k87gs5e6-fa0bff473bf62ab13b02e797351804f0\"><div class=\"avia_textblock\"><p>Processing of sensitive data can be performed, for example, if it is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health, for the protection of vital interests of society or to comply with another legal obligation.<\/p><\/div><\/section><div class=\"av-special-heading av-347g50u-79cf95b9d7f15797d1610a0d7031cb36 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-17 el_after_av_textblock el_before_av_image av-inherit-size av-linked-heading\"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">State of Emergency<\/h2><\/div><div class=\"avia-image-container av-lj4yeuq-20053e1958c876129d948c2d80ea3126 av-styling- avia-align-center avia-builder-el-18 el_after_av_heading el_before_av_textblock \"><div class=\"avia-image-container-inner\"><div class=\"avia-image-overlay-wrap\">\u00a0<\/div><\/div><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>If we consider the matter of data protection from the aspect of employment, it is indisputable that the employers around the world implement various protection measures in order to secure their employees and business premises. Due to the aspiration to fulfill the requirements in this direction, employers meet the challenge concerning lawful personal data protection. Personal data treatment might change during a state of emergency, which inevitably raises the question: <strong>what types of data can be collected and how can they be used? <\/strong><\/p><p>European Data Protection Board (EDPB) answered this question by issuing the <a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/our-documents\/other\/statement-processing-personal-data-context-covid-19-outbreak_en\" target=\"_blank\" rel=\"noopener\">Statement on the Processing of Personal Data in the Context of the COVID-19 Outbreak,<\/a> which implies the importance of the European Data Protection Law application even during the state of emergency. Hence, the EDPB Chair emphasizes that provisions regarding this matter by no means interfere with the performance of exceptional measures aimed at mitigation of the coronavirus. Therefore, data processors (including the employers) are obliged to preserve a certain level of collected data protection, independently of the state of emergency.<\/p><\/div><\/section><div class=\"av-special-heading av-2e5skem-d321635801d25a245c426695503bf459 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-20 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">Always Keep In Mind<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>GDPR declares <strong>essential principles<\/strong> that have to be implemented when collecting health-related data, as listed below.<\/p><p><strong>Lawfulness: <\/strong>legitimate legal ground.<\/p><p>Consent of data subject for data processing, in the context of COVID-19, does not play an important role. Therefore, the employer is obliged to identify the legal basis for data disclosure in every particular case, i.e. to examine whether the exceptional measures are justified.<\/p><\/div><\/section><section class=\"av_textblock_section av-k87gupqj-d581418d561f811ec8828aae6b5a9821\"><div class=\"avia_textblock\"><div><p>For example:<\/p><p>The \u201ccompliance with a legal obligation\u201d ground will be appropriate if the collecting is necessary for complying with EU law or national law of the member state. Or, \u201clegitimate interest pursued by the controller or a third party\u201d would be considered as convenient if applicable in a particular case.<\/p><\/div><\/div><\/section><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>Vice versa, the simple use of \u2018protection of vital interests\u2019 as a legal ground most likely would not be enough.<\/p><p><strong>Transparency:<\/strong> notifying employees.<\/p><p>In accordance with this principle, the data subjects which personal data refer to shall be informed by the employer on which data is disclosed to whom, what is the purpose of data collecting and how long is the retention period.<\/p><p>Besides that, the employer is authorized to share the information on the presence of the virus within the company but shall avoid naming the infected employee, unless that is unavoidable. Furthermore, it is advisable to set up a special corona virus-related hotline, which would likely encourage the employees who suspect that they might be infected to seek help privately and without spreading panic among the rest of the personnel.<\/p><p><strong>Minimization:<\/strong> collecting and processing only necessary data<\/p><p>Every employer shall collect only indispensable data, in order to assess the risks of the virus spreading and to implement safety measures.<\/p><p>To clarify, we provide some examples.<\/p><\/div><\/section><div class=\"avia-image-container av-k87cs5fh-3555678d98462cd26203d52ff3800ee5 av-styling- avia-align-center avia-builder-el-24 el_after_av_textblock el_before_av_textblock \"><div class=\"avia-image-container-inner\"><div class=\"avia-image-overlay-wrap\"><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-22082 avia-img-lazy-loading-not-22082 avia_image \" src=\"https:\/\/zuniclaw.com\/wp-content\/uploads\/2020\/03\/imageedit_27_4707165805.jpg\" sizes=\"(max-width: 840px) 100vw, 840px\" srcset=\"https:\/\/zuniclaw.com\/wp-content\/uploads\/2020\/03\/imageedit_27_4707165805.jpg 840w, https:\/\/zuniclaw.com\/wp-content\/uploads\/2020\/03\/imageedit_27_4707165805-300x181.jpg 300w, https:\/\/zuniclaw.com\/wp-content\/uploads\/2020\/03\/imageedit_27_4707165805-768x464.jpg 768w, https:\/\/zuniclaw.com\/wp-content\/uploads\/2020\/03\/imageedit_27_4707165805-705x426.jpg 705w\" alt=\"\" width=\"840\" height=\"508\" \/><\/div><\/div><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>However, a company shall delete all collected data related to the coronavirus once the pandemic passes and the virus itself no longer represents the threat.<\/p><\/div><\/section><div class=\"av-special-heading av-2076fim-dec1ddcd6ae619e60422ff2cc798ce18 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-26 el_after_av_textblock el_before_av_image av-inherit-size av-linked-heading\"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">When is Sharing Allowed?<\/h2><\/div><div class=\"avia-image-container av-lj4yeuq-2bf3eaed81a39df8ecbe7142252b8df7 av-styling- avia-align-center avia-builder-el-27 el_after_av_heading el_before_av_textblock \"><div class=\"avia-image-container-inner\"><div class=\"avia-image-overlay-wrap\">\u00a0<\/div><\/div><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>As mentioned, health-related data requires a higher level of protection, by their nature and sensibility. This raises the question of the usage restriction regarding this type of data, as well as the justification of their revelation to third parties. In this respect, the majority of the national data protection authorities agree \u2013 infected employee\u2019s personal data can be disclosed only if it is necessary, in order to protect public interests and public health, for instance:<\/p><p>1. Sharing with subjects required to be involved in order to implement certain health and safety measures, or<\/p><p>2. Sharing with government authorities and organizations, when mandatory.<\/p><\/div><\/section><div class=\"av-special-heading av-1gzngdq-c7766a0a2351f4ee1ef251db64099ef1 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-29 el_after_av_textblock el_before_av_image av-inherit-size av-linked-heading\"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">Comparative Country Insight<\/h2><\/div><div class=\"avia-image-container av-lj4yeuq-b36282fd65f0a1087fe52a9ec6f93f36 av-styling- avia-align-center avia-builder-el-30 el_after_av_heading el_before_av_textblock \"><div class=\"avia-image-container-inner\"><div class=\"avia-image-overlay-wrap\">\u00a0<\/div><\/div><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><h3>European countries<\/h3><p>\u00a0<\/p><ul><li><strong>UK<\/strong> complied their actions with the Statement by EDPB: the employer shall undertake all the necessary measures to protects the employees and holds the right to be notified if an employee is potentially infected. Furthermore, employers whose businesses include direct contact with the clients may demand from all the visitors to comply with instructions by the competent authorities before entering the business premises of the employer.<\/li><li>In <strong>France<\/strong>, the employer has the authorization to collect corona virus-related data referring to the employees, only upon the request of competent authorities, but not before implementing all the prescribed measures of protection and work organization during the epidemic.<\/li><li><strong>Italian<\/strong> authorities prescribe that the detection and repression of COVID-19, by all means, is the exclusive mission of the civil protection subjects and professional healthcare institutions, in accordance with the legislation. Therefore, employers shall refrain from performing self-initiated measures regarding data collection.<\/li><\/ul><ul><li><strong>Spanish<\/strong> data protection authority issued a statement entirely in accordance with the one by EDPB, highlighting which requirements need to be fulfilled, in relation with data collecting and processing during the coronavirus epidemic: a) <strong>legitimate legal ground<\/strong> \u2013 referring to article 9 of GDPR, Spanish Data Protection Law and Labor Law, and b) <strong>data minimization<\/strong>.<\/li><\/ul><\/div><\/section><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>\u00a0<\/p><h3>Non-European countries<\/h3><p>\u00a0<\/p><p><strong>Chinese <\/strong>authorities prescribed the employer\u2019s obligation to obtain the prior consent of the data subject for collecting its personal data regarding its health condition. Similarly, <strong>Australian<\/strong> law requires that the data subject has to explicitly approve collecting of its health-related data, with a particular regulation regarding the use and disclosure of the collected data. On the other hand, in <strong>Hong Kong<\/strong>, personal data can be processed without data subject\u2019s consent if that is necessary to avoid physical or mental harm to third persons.<\/p><\/div><\/section><div class=\"av-special-heading av-43d97y-686ab272dec928af5bb865aed3db334f av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-33 el_after_av_textblock el_before_av_image av-inherit-size av-linked-heading\"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">What About Digital Privacy?<\/h2><\/div><div class=\"avia-image-container av-lj4yeuq-742496a6ce2d838f5e05c991e10c2330 av-styling- avia-align-center avia-builder-el-34 el_after_av_heading el_before_av_textblock \"><div class=\"avia-image-container-inner\"><div class=\"avia-image-overlay-wrap\">\u00a0<\/div><\/div><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>The Statement by EDPB regulates the specificities regarding electronic communication data, such as location data. Privacy and Electronic Communications Directive (hereinafter: <strong>Directive<\/strong>) regulates this matter, by explicitly prescribing that location data can be processed solely when they are made anonymous, or with the consent of the data subjects. In cases when it is not possible to only process anonymous data, the Directive authorizes the state members to establish specific measures in order to protect national and public security.<\/p><p>Not only European countries used this possibility, but some parts of Asia, also. For example,<strong> Italian<\/strong> authorities cooperate with mobile operators, who share location data with the Ministry of Health, providing it with information on the number of citizens violating prescribed movement restrictions. The <strong>Polish<\/strong> government launched an app intended to quarantine citizens. From time to time, the app requests the mobile phone owner to take a geo-located selfie, so that authorities can be sure that their orders are not being violated.<\/p><p>An interesting measure was implemented in <strong>Hong Kong<\/strong>, in relation to citizens recently arrived from other countries \u2013 the authorities provide them with wristbands that record the individual\u2019s location and inform the competent authorities if the person does not comply with the quarantine order. <strong>Singapore<\/strong> made all the data about infected citizens public, and the next step was launching an app that makes the location of the victims of coronavirus visible, so they can be tracked. It is redundant to say \u2013 the legitimacy of this kind of measure is definitely questionable.<\/p><\/div><\/section><div class=\"av-special-heading av-lb5hym-eaf96cdbc8d2aba0e916ec54acc5cb37 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-36 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">The Republic of Serbia<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>When it comes to domestic emergency legislation, no measures prescribe any exceptions in the area of data protection. Unlike the above-mentioned countries, Serbian authorities did not issue any explicit statements regarding personal data <strong>\u2013 <\/strong>except for the appeal to the citizens to comply with the instructions issued by the authorities. It is questionable whether the lack of reaction is accidentally delayed, or the government did not realize the need for such regulations. The answer from the Serbian authorities should be provided as soon as possible.<\/p><\/div><\/section><div class=\"hr av-k89zlrzj-eb57aeda3409167d1dcbcad61bbf7071 hr-invisible avia-builder-el-38 el_after_av_textblock el_before_av_textblock \">Once the pandemic of COVID-19 is over, many aspects of life surely will be significantly affected, but data protection does not have to be. Employers shall timely ensure that all the safety rules and procedures are in place so that the effects of the epidemic on employment relationships are reduced to a minimum. The personal data of the employees shall remain highly protected by following the GDPR rules, as well as the emergency instructions issued by the government authorities.<\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>In other words \u2013 keep your employees safe, in every way.<\/p><\/div><\/section>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>To perform more successful treatment of the infected patients and spread awareness about the coronavirus and protection methods, data concerning the health of citizens is more exposed than usual. In this blog, we will take a glance at the issue of conflict between the two fundamental civil rights: the right to healthcare and the right [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":66984,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[126],"class_list":["post-40355","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-privacy-data-protection-en"],"_links":{"self":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/40355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/comments?post=40355"}],"version-history":[{"count":6,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/40355\/revisions"}],"predecessor-version":[{"id":66991,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/40355\/revisions\/66991"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/media\/66984"}],"wp:attachment":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/media?parent=40355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/categories?post=40355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}