COVID-19: Remote Working and Data Protection
As measures to control and prevent the spread of COVID-19 continue to be implemented, the number of employees working remotely will continue to increase. Now more than ever, it will be necessary for organisations to ensure that they can meet their legal obligations in ensuring the security of the personal data of their clients, customers and staff.
Technical and Organisational Measures
Under both the GDPR and the Irish Data Protection Act 2018, data controllers are required to determine and implement “technical and organisational measures” in order to ensure a level of security appropriate to the harm resulting from:
- Accidental or unlawful destruction;
- Loss;
- Alteration;
- Unauthorised disclosure; and
- Unauthorised access.
Data controllers are often unsure as to what implementing such “technical and organisational measures” means in practical reality. While to an extent dependent on the nature of the personal data being collected and processed, in general this requirement obliges controllers to implement internal data breach and data security policies, minimise processing of personal data to the greatest extent possible, ensure transparency with regard to the purpose and legal basis for such processing, and anonymising personal data if possible.
Naturally, deciding upon the “technical and organisational measures” which an organisation may be required to implement will involve making a determination as to the purpose, scope and context of data use, the costs of implementation, and the category of the risk of the rights of individuals to whom the data relates.
For employees who have already commenced or are due to commence working remotely, it is therefore of critical importance that they be made aware and be provided with a copy of their organisation’s internal data security and / or data breach policies. Employers should therefore be reviewing these policies to ensure that they are updated and appropriate, while also making an increased effort to ensure that the data which they collect or process is both secure and limited what is necessary.
Keeping Personal Data Safe While Working Remotely
Often the most effective security measure an organisation can put in place, is to ensure that all employees are aware of their responsibilities. Employee training about the risks of data compromise and their role in preventing it and how to respond in the event of any issues that arise can often be the most effective first line of defence.
Where remote access is granted to an employee allowing them access to their employer’s network from home or from an off-site location, it is necessary to be aware that giving such access creates a potential weakness in the overall system. This is particularly the case where access at home or off-site is from a wireless network. In light of this, recent guidance published by the Data Protection Commission has highlighted that employees should be instructed to comply with the following provisions as far as reasonably possible:
- Employees should take extra care that devices, such as laptops, tablets, phones etc are not lost or misplaced and should be stored in a safe location that is not within easy access to individuals outside the organisation;
- Every device used remotely should not be left unattended and a lock screen should be set when the employee’s device is not in use or after several minutes of inactivity;
- Every device used remotely should have the necessary system and software updates as well as anti-virus updates;
- Controls such as anonymisation and encryption to restrict access to the device should be in place as well as the use of Multifactor authentication for such access;
- Passwords should not be written down and left in convenient places, and should not be shared amongst colleagues;
- Unexpected email attachments should not be opened unless first screened by anti-virus software;
- There should be the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
- All workflow should originate from work email accounts rather than personal ones for work-related emails involving personal data. Where a personal email is used content and attachments should be encrypted, and personal and confidential data should be avoided as subject lines;
- Only trusted networks or cloud services which comply with any company / organisational rules and procedures about cloud or network access, login and data sharing should be used;
- Locally stored data should be adequately backed up in a secure manner; and
- When a device that is being used remotely is lost, immediate steps should be taken to ensure that the remote memory wipe facility is activated and employees allocated such devices should be familiar with the relevant procedures.
How we can help
If you have any queries or concerns, or would like to discuss the above in further detail, please feel free to contact Joe McVeigh or Lee Taren in our Privacy & Data Security Team.
This article is for general information purposes. Legal advice must be obtained for individual circumstances. Whilst every effort has been made to ensure the accuracy of this article, no liability is accepted by the author for any inaccuracies.