Coronavirus

Data Protection Authorities for France and the Netherlands have weighed in on the use of temperature taking in the fight against the spread of COVID-19.

Netherlands’ Autoriteit Persoonsgegevens:

“We hear that all kinds of organizations use different means to check people quickly for fever. Not only with a thermometer, but also with thermal cameras”

“That’s not allowed. This is a serious offense under [GDPR] . If this happens, we will enforce.”

“We don’t want to wake up in a few months in a society with a kind of Chinese situation, in which the employer is constantly watching you and can even see your care data and have all kinds of consequences.”

  • Employers may not check people’s temperature and process their health data.
  • Consent as a legal basis is not possible in an employment relationship, because an employee may feel pressured to give permission.
  • Only a doctor should do health tests and process the medical data of personnel.
  • You may not check temperature of visitors or vendors either. Consent here is not possible because there is no equivalence here either. The visitor will feel compelled to agree.
  • Employees of companies that measure temperature should report this to the works council and to the data protection officer.
Spain’s Agencia Española Proteccíon Datos:

Continue Reading Temperature-Taking Under GDPR: Guidance from Spain, the Netherlands

The New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) issued an advisory to hospitals and other healthcare organizations that cybercriminals are targeting them with phishing campaigns, ransomware, and other malicious
Continue Reading New Jersey Issues Best Practices for Healthcare Industry to Combat COVID-19 Cyberattacks