The new NHS Covid pass offers businesses an easy way of discovering an individual's Covid status but there are legal issues to consider first, particularly in relation to data protection and discrimination.

What is the NHS Covid pass?

The NHS Covid pass is available in England to individuals aged 18 or over. The current requirements for obtaining a pass are as follows:

  • 2 doses of the Moderna, AstraZeneca or Pfizer vaccine: 2 weeks after second dose
  • 1 dose of the Janssen vaccine: 2 weeks after single-dose vaccine
  • negative PCR test or rapid lateral flow test within the past 48 hours: as soon as result is available;
  • positive PCR test within the past 6 months: after self-isolation has finished and up to 180 days after taking the test.

The NHS Covid pass is already being used for some large events in England (on a trial basis) and fully vaccinated individuals are able to use it as evidence for overseas travel. It was made widely available in England from 19 July.

What does the NHS Covid pass look like and how would we check it?

The government have provided various  examples of valid NHS Covid passes. Most users are likely to have obtained a digital version of the pass through the NHS app. This shows a barcode, a green stripe across the bottom of the screen and the date of expiry. The digital NHS Covid pass is time limited (even where an individual is fully vaccinated) but can be renewed.

It is possible to verify the barcode by using a separate app released by the Department of Health and Social Care named NHS COVID Pass Verifier. The app is freely available to download and allows a camera to scan an individual's barcode on a device or printed out copy. Used for domestic purposes, the  app will either confirm the barcode is valid or expired. The verifier will see the individual's name, and either a green tick to confirm the QR code is valid and the date when the pass expires or a grey box stating the QR code is not recognised or has expired.

Which businesses are supposed to be using the NHS Covid pass?

The government has encouraged use of the pass in England for customers in high–risk settings. These are events and other settings where people are likely to be in close proximity to a significant number of people from outside their household for a prolonged period of time. The  guidance gives the following examples:

  • crowded, unstructured indoor settings such as nightclubs and music venues;
  • large unstructured outdoor events such as business events and festivals;
  • very large structured events such as business events, music and spectator sport events.

The guidance is clear that essential services and retailers, in particular businesses that were able to stay open during lockdown, should not be using the NHS Covid pass.

The government considers that nightclubs should currently be using the NHS Covid pass as  the socially responsible thing to do until late September when evidence of full vaccination will be compulsory.

Can we use the NHS Covid pass for staff?

The emphasis so far has been on using the pass for customers and visitors, not staff. The government position on using the pass for staff is currently unclear. A government  press release heralding over 10 million downloads of the official NHS app stated the app would help allow people to 'start returning to workplaces' as well as travelling and attending large events but, at the same time, government sources are reported to have denied that workplaces will be encouraged to use the NHS Covid pass for staff.

The working safely guidance, which includes detailed guidance for different types of setting, only specifically mentions the use of the NHS Covid pass in the guidance for  events and attractions and restaurants, pubs, bars, nightclubs and  takeaway services (specifically for nightclubs) and only in connection with customers rather than employees.

However, pending further clarity in the guidance, employers could consider introducing use of the NHS Covid pass as an additional safety measure for staff, especially given that the legal rules on social distancing and mask wearing have been lifted. It may be attractive in a number of situations including:

  • as an extra safety measure in settings where staff have to spend prolonged periods in close proximity to customers;
  • as part of a gradual reopening of the office, where staff could show a pass on arrival or continue working from home if they do not have a valid pass to cover that day; and
  • where employers have decided to implement lateral flow testing for staff and wish to exempt fully vaccinated individuals and those with assumed immunity from any repeat testing policy.

Employers should note, however, that the NHS Covid pass is designed for use in settings in England. Other parts of the UK have different arrangements.

How to comply with data protection law?

The Information Commissioner's Office (ICO) has recently published data protection  guidance on using the NHS Covid pass.

The ICO guidance explains that it is possible for business to use the NHS Covid pass to allow access to workplaces without processing any data, by choosing not to scan the barcode and by making sure that none of the information is written down or stored in any way. This approach involves someone simply looking at the pass at the point of entry, without using the scanner and without keeping any records.

If staff are denied access, for example due to an expired NHS Covid pass, it may be more difficult to avoid record keeping in roles where the employee cannot return to work from home, although it will be up to the employer to decide how absence is recorded in these circumstances.

If the employer chooses to scan the barcode, or to create any records of any kind about someone's Covid status, the employer will be processing special category health data. This means that, to comply with data protection law, the employer would need to do the following:

  • Identify the legal basis for collecting the data. The safest legal bases will be compliance with legal obligations and/or 'substantial public interest'. This means that preventing the spread of the virus and complying with the duty of care to employees need to be at the root of the justification rather than, for example, customer or staff preference or boosting confidence.
  • Carry out a data protection impact assessment. This sets out the proposed ways that data will be processed, the risks to data subjects, and the ways in which such risks will be mitigated (e.g. by limiting the number of people who have access to the record, only keeping records for as long as they are necessary, and complying with the other GDPR principles).
  • Respect the principles of transparency, proportionality and security. Don't hold on to the details for longer than necessary. Tell employees why you are processing their information, how the information will be stored, how long it will be retained and who will be able to access it.

What equalities issues arise using the NHS testing pass for staff?

Using the NHS Covid pass raises fewer discrimination issues than a compulsory vaccination programme, because it provides other routes to demonstrating Covid status. Using the pass could nonetheless still indirectly disadvantage individuals with characteristics that are protected under the Equality Act 2010 (EqA), so the equalities issues need to be considered. The main groups who could be disadvantaged, their potential claims under the EqA and the mitigating steps you could take to reduce risk are set out below.

Employees who are too young to have been double vaccinated. This is a diminishing group. These employees may regard themselves as being put at a disadvantage because (unless they've previously tested positive using a PCR test and gain the pass through assumed natural immunity) they will have to submit to regular testing in order to obtain a pass. This could therefore be indirect discrimination against younger employees. This could be justifiable as a proportionate means of achieving a legitimate aim if there are workplace safety reasons to use the pass.

Employees who cannot accept the vaccine for medical or belief reasons. As explained in our vaccination FAQs, the numbers falling into these categories are likely to be small. As with employees who are too young to have been double vaccinated, these employees may also regard themselves as being put at a disadvantage because (unless they've previously tested positive using a PCR test and gain the pass through assumed natural immunity) they will have to submit to regular testing. This may be justifiable as a proportionate means of achieving a legitimate aim if there are workplace safety reasons to use the pass. If there are medical reasons why a person cannot submit to testing, employers would need to consider this on case-by case-basis.

Employees not vaccinated in England. The pass only shows that an individual is double vaccinated if they had both doses in England. Using the pass therefore has the potential to be indirectly discriminatory on grounds of race/nationality, especially for example in relation to employees who have only recently started work in England or are working here temporarily. Employers could easily mitigate this risk by accepting alternative evidence of vaccination.

The 'digitally excluded'. It is possible to obtain a paper copy of the NHS Covid pass, but only if you are double vaccinated. Paper copies cannot be used to show test results. There may be some arguments about whether this system disadvantages certain groups, especially the very elderly, but they are unlikely to be relevant when using the NHS Covid pass for staff as opposed to customers.

Voluntary or compulsory?

Employers keen to use the NHS Covid pass but also to avoid risk could begin by making use of the pass voluntary to begin with, using the same social responsibility angle the government is applying to nightclubs and large events settings.

A voluntary approach reduces the risk of discrimination claims as there is no disadvantage to those who don't volunteer. It also mitigates any data protection risks arising from the creation of records and processing of health data, because individuals volunteering to share information are much less likely to make a data protection complaint and a policy is more likely to be proportionate if there is no mandatory element.

Some workforces may find they have a very high uptake of the vaccination making the ongoing use of the NHS Covid pass unnecessary. Some employees who are not vaccinated may agree to voluntary regular testing as a result of wanting to be seen to do the right thing.

If an employer decides that a voluntary approach is not sufficient, then it could consider making the use of the pass compulsory. For employees who are unvaccinated, this will mean compulsory lateral flow testing unless they have already tested positive for COVID-19 in a PCR test in the previous six months. Employers will need to consider how staff should obtain the tests, whether they should do the tests at home or as part of an ongoing workplace testing programme, and any national minimum wage issues – see our  workplace testing FAQs for more information. Employers will also need to consider difficult issues about pay if an employee does not take a lateral flow test in time to achieve a valid pass. Any approaches taken, including regarding disciplinary action, should be recorded in a written policy communicated to staff in advance. It would also be advisable to ensure that employers consult with employees about the use of the Covid pass as part of their consultation on health and safety arrangements.

What if we make it compulsory and then someone refuses?

If use of the NHS Covid pass is mandatory, employers should have a written policy outlining the rationale and how a refusal would be dealt with e.g. classed as a failure to follow a reasonable management instruction resulting in disciplinary action. In the event that an employer dismisses an employee for refusing to co-operate, employees may bring claims relating to data privacy or discrimination (see above) and employees with more than two years' continuous employment would also be eligible to bring an unfair dismissal claim. It would then be for an Employment Tribunal (ET) to assess the reasonableness of the employer's decision to dismiss.

Before moving to discipline or dismiss an employee, employers would of course need to discuss the problems and look for solutions. For example, an employee may have been advised not be vaccinated for medical reasons and may be finding repeated testing challenging. Solutions might include allowing an exception, redeployment to another role, or potentially keeping the employee working from home where possible.

How do we know if individuals are exempt from vaccination or testing?

In the government's July 2021 review of whether Covid passports should be mandated, the government said that it will also allow individuals to demonstrate their exempt status in exceptional circumstances where a clinician recommends vaccine deferral or that vaccination is not appropriate and where testing is also not recommended on clinical grounds. The government guidance currently states that individuals with medical reasons precluding vaccination or testing may be asked to self-declare their medical exemption. We await further guidance on this position.

In summary: practical considerations

  • Consider the possible use of the NHS Covid pass in the context of your risk assessment. Is a voluntary approach sufficient alongside other measures, or do your circumstances justify a mandatory approach?
  • Decide if you need to scan barcodes or keep records. Can you avoid data protection requirements by simply looking at the pass on entry without writing anything down? When using the pass for staff, do you really need to verify the pass by scanning the barcode?
  • Explain your proposals to staff as part of your ongoing engagement/consultation with staff on health and safety measures. See our  article on the end of lockdown restrictions for the latest on risk assessments and consultation.
  • Plan on how staff Covid passes will be checked on entry in a way that minimises disruption to shift times and without putting other aspects of health and safety at risk, for example by creating crowds at entrance barriers.
  • Consider any relevant policies regarding sick pay and absence management, bearing in mind that regular testing could result in more staff needing to isolate.
  • Ensure staff are trained on the various different ways an individual can demonstrate their status, for example by having a paper copy of the NHS Covid pass.
  • Ensure staff are trained on how to deal with an individual claiming to be exempt. Consider any processing of special category health data as a result.
  • Ensure that staff are aware that other health and safety measures remain in place.
  • Keep any policy under review in line with the changing situation with COVID-19.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.