Today (July 4th) the hospitality sector (most likely including your local pub) has started to re-open after the three-month lockdown, closed doors and no business.
Government guidelines are asking businesses where there is a 'higher risk' of COVID-19 transmission (like Pubs, Bars Cafes, Restaurants etc) to collect information on their patrons (customers) to be used as part of the Governments 'Track and Trace' system. The idea is if anyone in the Pub (for example) becomes infected then the Pub would then release the contact information of anyone who visited the Pub on the same day (or the same time) to the NHS Track and Trace to allow them to contact the other patrons and ask them to enter isolation (as well as find out who else they may have come into contact with).
To many this provides a large concern around privacy, they've never had to give out this level of information to these types of businesses before, and some have tried to minimise their privacy profile - even with the Government.
The exact information collected on customers is likely to be the following;
For staff:
For Customers
It's likely that anywhere that requires a booking such as Hairdressers, Restaurants, Hotels etc will collect this information when you reserve. Many already do so as part of the process of reservation pre-COVID-19. The exception here is that a restaurant would have only previously asked for your name. This information could be collected over the phone or if the system to book is online then done so through this.
Pubs, on the other hand, are far less likely to have this information in advance.
My thoughts are that this will be done paper-based and with card/pen - Most Pubs will be set up for social distancing, reduced seating and following the Government guidance for 'At table service only'.
This route and a paper-based system - while it makes it a harder job in the future if there is an infection to quickly report it to the NHS this information is likely to be at less risk when stored properly. The larger risk here is that cards may not be collected properly and that staff member may not correctly store the cards securely.
The alternative more digital route for a Bar such as Wetherspoons etc (Where App-based ordering is already in effect).
Now, this route certainly makes it easier for staff - It's all securely held and only authorised people would have digital access to the stored records. The downside here is that we know that digital app adoption for ordering in bars (such as the Weatherspoons app) isn't taken up by everyone. Theirs reminds those that choose not to have smartphones or don't have the ability to use a phone or app requiring assistance from staff.
The Downsides to both and any option (in my opinion) to collect this information are:
Honestly, it all depends on how it's implement and the type of customers that come into contact with.
Locations with pre-booking - Hotels, Restaurants, Hairdressers etc - Very likely to be easy implementation and high accuracy of data kept.
Pubs/Bars etc - I don't think it'll work - Inaccurate information supplied and difficulty collecting it.
For sure - This is adding a lot more personal data into the mix of companies that are only now having to drum up procedures that have to be organised and kept for three weeks. If we don't see a few cases of this information not be deleted/destroyed after three weeks, or accidentally emailed to someone, found in a dumpster etc I'd be surprised.
A lot of UK companies, especially small such as non-chain Pubs I don't believe ever really adopted GDPR (Or rather the UKs Data Protection Act 2018) - They won't have someone trained in it, very unlikely to have a named staff member responsible. Very unlikely to have procedures already in place to keep data secure (outside hopefully of their staff members) and this will just lead to an increase in accidents around personal data (or more likely in my opinion they won't bother to collect it in the first place).
Unlikely again in my opinion. This is a 'Wartime effort' to protect people - I imagine the first we'll hear from the ICO will be in 5-10 years when a large corporation has kept all of this data for 5-10 years and has been using it for marketing purposes and it 'accidentally' gets leaked or hacked.
You can read the Governments exact guidance and more detail here

© 2023 Innatus Digital Ltd
Company Registration no. 12849413
Registered in England Wales