Awdurdod annibynnol y Deyrnas Unedig a sefydlwyd i gynnal hawliau gwybodaeth er budd y cyhoedd, annog cyrff cyhoeddus i fod yn agored a hybu preifatrwydd data i unigolion.

We understand that organisations have lots of new measures to put in place so that they can re-open safely to the public. For many, this includes collecting customers’ and visitors’ personal information for the first time, to support the various contact tracing schemes in the UK.

Whilst asking for contact details has been voluntary so far, new measures have been brought in to oblige certain organisations to ask for this information. Our guidance reflects these changes.

It doesn’t need to be complicated – just choose the process that best suits your business.

Follow our five simple steps to help ensure that data protection is not a barrier to your recovery.



Ask for only what’s needed

You should only ask people for the specific information that has been set out in government guidance. This may include things like their name, contact details and time of arrival for example.

You should not ask people to prove their details with identity verification, unless this is a standard practice for your business, eg ID checks for age verification in pubs.


Be transparent with customers

You should be clear, open and honest with people about what you are doing with their personal information. Tell them why you need it and what you’ll do with it. You could do this by displaying a notice in your premises, including it on your website or even just telling people.

If you already collect customer data for bookings, you should make it clear that their personal data may also be used for contact tracing purposes.


Carefully store the data

You must look after the personal data you collect. That means keeping it secure on a device if you’re collecting the records digitally or, for paper records, keeping the information locked away and out of public sight.

See our guidance on simple security measures you can take here.


Don’t use it for other purposes

You cannot use the personal information that you collect for contact tracing for other purposes, such as direct marketing, profiling or data analytics.


Erase it in line with government guidance

You should not keep the personal data for longer than the government guidelines specify. It’s important that you dispose of the data securely to reduce the risk of someone else accessing the data. Shred paper documents and permanently delete digital files from your recycle bin or back-up cloud storage, for example.

We have published further detailed guidance on this topic. If you need more help, we’re here to answer your questions. Ring us on 0303 123 1113.

You should check government guidance to see whether you are required to collect this information. Government guidance has been published and varies for EnglandNorthern Ireland, Scotland and Wales.