
The UK government has admitted that it launched a Test and Trace programme across England without completing the expected privacy checks. The Test and Trace programme has been running since the end of May without a “Data Protection Impact Assessment” (DPIA), a process required by GDPR for any project that poses a high risk to the personal data of the individuals involved.
The DPIA process is designed to identify and minimise data- related risks . But when the Test and Trace programme was launched, reports emerged that the government was not carrying out appropriate assessments in line with the GDPR.
The public health program identifies all people who have come into contact with a person diagnosed with coronavirus and collects personal information such as names, gender, zip codes, email and phone numbers.
In a statement released at the start of the program, health authorities also said that the information collected could be used for alternative purposes, such as research COVID-19. However, patients have “limited” rights to request data deletion.
Since the launch of Test and Trace, the Open Rights Group (ORG) has been in contact with the government, through data protection lawyer Ravi Naik , to request that the GDPR DPIA procedure be applied to the program. Two weeks ago, the organization threatened legal action if its request continued to go unanswered.
In a letter to ORG, the Department of Health and Social Care (DHSC) admitted that, while a DPIA is required, the scheme effectively launched in May without a privacy assessment. According to the DHSC, the DPIA process is “now in the final stages of completion”.
Program staff have already contacted more than 155,000 people who may have been infected with the virus.

The failure to carry out the necessary checks to ensure the scheme GDPR compliant was due to the speed with which it had to be rolled out, the DHSC said in the letter. To reduce the burden on the NHS and to lift lockdown restrictions as soon as possible, Test and Trace had to be launched very quickly.
The DHSC argued that despite the lack of a DPIA, there was no misuse of patient data.
Jim Killock, director of ORG, said the illegal use of data is a separate issue from the illegal launch of a national program.
“We didn’t say we saw that there was illegal data processing,” Killock said. “We said the government doesn’t know whether the processing is or isn’t legal because it failed to operate the program legally from the beginning.”
Whether the data is being processed in accordance with GDPR regulations has yet to be clarified, according to Killock. However, the expert identified other potential risks.
For example, the DHSC admitted that the Test and Trace programme had been run in collaboration with three organisations. Individual to be sharing data on social media. companies have been found Details of patients have appeared on Facebook and WhatsApp . The Information Commissioner's Office (ICO) said it was looking into the issue.
“You have tens of thousands of people’s data moving through this system, and it’s about people who are infected or at risk of infection (due to contact with patients),” Killock said. “This is very sensitive data and can be used in fraud, because it’s very valuable to criminals. There’s a lot of risk, so the processes need to be done right.”
There is not much else ORG can do now that it has pushed the government to admit that the Test and Trace programme was launched without proper privacy controls. Killock says the Information Commissioner should now take up the case.
The coronavirus lockdown is very important and requires speed, but that doesn't mean that related programs can bypass GDPR procedures and data at risk user. Killock said the Information Commissioner must be tough with the government to prevent this from happening again.
