Search

How can we help?

Icon

Remote working: How to stay Data Protection-Compliant

In recent years, there has been a very significant movement from office-based to remote working, driven initially by the increasing attraction as an employee retention tool of flexible working and, of course, accelerated in a truly unforeseeable way by the COVID-19 pandemic. Even though no longer subject to legal constraints on movement and where work can be carried out, many businesses have continued using a distributed workforce, and, for a sizeable number, remote working is now the norm rather than the exception.

Remote working, with its advantages, also carries risks, a significant one being cybersecurity and, in particular, data protection compliance. The fact that a data breach takes place away from office premises when an employee is working in an internet café, in their house or wherever will not in any way relieve their employer – be they a data controller or a data processor – from the significant financial and reputational repercussions of that breach.

So, what should organisations do to reduce the cybersecurity and data protection risks of home working to the same (well, hopefully, in a well-run business) low level as with office-based working? These are some areas to consider:-

Employee Awareness

First and foremost, businesses must ensure all relevant policies are up-to-date and reflect changes in working practices – for example cybersecurity and confidential information policies – and that these are reviewed and revised frequently.

However, there is no point in having state of the art policies unless employees are aware of and follow these, and the key to this is, of course, regular employee training. For the Information Commissioner’s Office (ICO), this is a key employer obligation.

Systems and Equipment

Ideally, a corporate virtual private network (VPN) should be in place to prevent, to a high degree, unauthorised access to sensitive and confidential data and information. Through a VPN, employees’ connections from remote working locations to the organisation’s servers can be encrypted, allowing safe and secure network access. For obvious reasons, use of public Wifi without a VPN is very inadvisable and there are risks of unauthorised access even with home Wifi which are significantly reduced by use of a VPN.

It is not always economically feasible for an organisation to issue all its remote working employees with company-issued laptops but this is the safest solution. If employees are allowed to use their own devices, it is important that their own data and the organisation’s data are kept separate and that (through proper training) they understand the risks of inadvertently moving the organisation’s data into their personal storage, which is quite easily done when using a single device. Password security is particularly important when personal devices are being used and many employers use – wisely – multi-factor authentication (for example, having to add a passcode provided by text message after entering the password) for additional security.

Jon Chapman

Senior Consultant

View profile

+44 118 960 4683

Businesses must ensure all relevant policies are up-to-date and reflect changes in working practices, and that these are reviewed and revised frequently.

Common Sense

It is important that employees understand that working remotely will never be as secure as an office environment and adapt their behaviours accordingly. Much of this is common sense. A few key messages:-

  • Don’t mix work and personal emails – because when this happens, the possibility of a security breach increases significantly. Recent high profile incidents (for example, Suella Braverman using personal email six times for work emails) emphasise the dangers of this!
  • When at work, you are with work colleagues who are under confidentiality constraints. In another remote working location, even at home, you are not. Don’t drop your guard and keep a ‘work head’ on – so avoid discussing sensitive matters in earshot of others, be particularly careful with phone and video calls, don’t leave sensitive documents lying around on your printer or elsewhere and so on.
  • Confidential waste is still confidential waste, even at home. It does not go out with your cardboard recycling! If you cannot have it destroyed properly and irretrievably, it needs to go back to the office for shredding.

Remote working is here to stay and, with correct planning and management and applying the above principles, associated cybersecurity and data protection risks can be reduced to typical business risks.

It is also recommended that organisations who have employees who work remotely consult the ICO guide on this issue.

About this article

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Jon Chapman

Senior Consultant

View profile

+44 118 960 4683

About this article

Read, listen and watch our latest insights

art
  • 24 November 2017
  • Employment

Failing to evidence right to work is not an excuse to dismiss an employee

In Baker v Abellio London Ltd, the EAT overturned the ET’s original finding of a fair dismissal for illegality. The ET had accepted that a Jamaican national with the right to live and work in the UK was fairly dismissed after his employer had suspended, and eventually dismissed him, after failing to provide documentary evidence of his right to work.

art
  • 24 November 2017
  • Employment

Union bids for recognition with end user not employer

This week a trade union, IWGB, has applied for statutory recognition to represent a group of receptionists, security officers and porters who work at the University of London even though these workers are employed by Cordant Security, a facilities management company with the contract to provide services to the University.

art
  • 17 November 2017
  • Employment

Pension scheme did not discriminate workers

In Dr Parker v MDU Services Ltd, the claimant alleged that her employer’s pension scheme indirectly discriminated against workers who had a combination of full and part-time service.

art
  • 17 November 2017
  • Employment

Deliveroo: Late substitution leads to a win against the run of play

The Central Arbitration Committee (CAC) has finally given its decision on whether a particular group of Deliveroo riders – those in the Camden/Kentish Town area of North London who are paid per delivery – are workers of Deliveroo or are independent suppliers of services to Deliveroo.

art
  • 13 November 2017
  • Employment

Will Uber work in the area again?

The Employment Appeal Tribunal (EAT) has today upheld the ET decision that when the Uber drivers were in the work area, available for work and with Uber app switched on, they were workers with rights to national minimum wage, sick pay and holiday pay.

art
  • 13 November 2017
  • Employment

Michael Sippitt comments on Uber losing UK legal appeal against drivers’ rights

Taxi-hailing firm Uber has lost its appeal on Friday (10 November) against a ruling that its drivers should be classed as workers rather than self-employed.