Welcome Guest! The IOSH forums are a free resource to both members and non-members. Login or register to use them

Postings made by forum users are personal opinions. IOSH is not responsible for the content or accuracy of any of the information contained in forum postings. Please carefully consider any advice you receive.

Notification

Icon
Error

Options
Go to last post Go to first unread
Elfin_Safety  
#1 Posted : 28 August 2024 08:42:38(UTC)
Rank: Forum user
Elfin_Safety

A query on follow up to accidents involving members of the public, and how their contact details are used.

We have a large number of visitors to our site and when first aid is required we use the same accident books as for employees. Personal details are collected should there be a requirement to report via RIDDOR or to identify the person as part of any investigation or claims process.

My approach is that these are the only reasons we hold these details and that they should not be used to contact the individual (e.g. to enquire how they are doing or follow up on the severity of an injury) unless they have expressed consent for this (which it is currently not part of our procedure to ask them to do).

Does this tie in with how you understand accident forms used for non-employees interact with GDPR?

thanks 1 user thanked Elfin_Safety for this useful post.
Ballard-Sheriff30666 on 03/09/2024(UTC)
Roundtuit  
#2 Posted : 28 August 2024 09:24:10(UTC)
Rank: Super forum user
Roundtuit

The legitmate business interest under which you have made the record is to identify an incident affecting an individual that occurred on insured premises.

As you state it is not to get in contact with the injured party and any external communication or enquiry should be directed through the offices of your insurers.

thanks 4 users thanked Roundtuit for this useful post.
Elfin_Safety on 28/08/2024(UTC), Ballard-Sheriff30666 on 03/09/2024(UTC), Elfin_Safety on 28/08/2024(UTC), Ballard-Sheriff30666 on 03/09/2024(UTC)
Roundtuit  
#3 Posted : 28 August 2024 09:24:10(UTC)
Rank: Super forum user
Roundtuit

The legitmate business interest under which you have made the record is to identify an incident affecting an individual that occurred on insured premises.

As you state it is not to get in contact with the injured party and any external communication or enquiry should be directed through the offices of your insurers.

thanks 4 users thanked Roundtuit for this useful post.
Elfin_Safety on 28/08/2024(UTC), Ballard-Sheriff30666 on 03/09/2024(UTC), Elfin_Safety on 28/08/2024(UTC), Ballard-Sheriff30666 on 03/09/2024(UTC)
toe  
#4 Posted : 30 August 2024 10:03:14(UTC)
Rank: Super forum user
toe

On a slight tangent, this is a great example of how we apply the practicalities of the law.

So, a member of staff or the public cannot refuse to give their personal details under the Data Protection Act 2018 (GPDR is a European thing) when reporting an accident in a workplace. To add, a date of birth is also needed for RIDDOR requirements. They also cannot exercise their right as the data subject to be forgotten or that the data be deleted once it has been retrieved, as the data is being kept for legal reasons. The DPA 2018 is regarded as subordinate legislation to the HSAWA 1974.

However, it's crucial to understand that personal data must be confidential and kept secure at all times and should only be accessible to individuals with a legitimate interest. Therefore, it would be good practice or even maybe a requirement to ensure that the data retrieved is protected under the DPA.

Echoing Roundtuit’s comment above, when it comes to contacting an injured non-employee, it's always best to consult with your insurer first. They can advise you when it's appropriate to do so. It's not a matter of ‘expressed consent’.

thanks 3 users thanked toe for this useful post.
Elfin_Safety on 30/08/2024(UTC), Ballard-Sheriff30666 on 03/09/2024(UTC), aud on 05/09/2024(UTC)
Users browsing this topic
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.