The privacy rules on the controls of the green pass in the company

Time: 08/Mar By: kenglenn 629 Views

Vincenzo Tiani Le regole per la privacy sui controlli del green pass in azienda

Economy From 15 October, the green certificate verification for those who work is triggered. Here are the aspects to pay attention to for the protection of workers' data

With the loosening of the grip of Covid-19 thanks to the increase in the number of vaccinated people, we are slowly returning to ordinary life, including that in the office or in the company. All this is possible thanks to the green pass, the certificate that is obtained in case you have recovered from Covid-19, have been vaccinated or have had a negative swab in the last 48 hours.

Unfortunately, out of the ordinary uses immediately spread, leading the Guarantor for the protection of personal data to publish a series of indications for both the public and private sectors, to which the indications of the government were added. The main issue remains the difficult management of health data, given the need to balance different needs such as the right to the protection of personal data, the right to health and the right to return to work. So let's do a bit of order to understand what changes from October 15th.

What is the normative source?

The regulatory source is the decree law of 21 September 2021, number 127 which provides for urgent measures to ensure the safe performance of public and private work by extending the application scope of the Covid-19 green certification and strengthening the screening system. The provisions will be effective from October 15th to December 31st until further modification.

What changes from October 15th?

Both in the public and private sectors, employees, but also outsiders and collaborators, must possess and show the green pass to authorized personnel upon request.

In the private sector, "employers define [...] the operating procedures for organizing checks, [...] also on a sample basis, providing priority, where possible, for such checks to be carried out at the moment of access to the workplace [...] ".

Do all employees have to have the green pass?

No. ** Excluded are "** subjects exempt from the vaccination campaign on the basis of suitable medical certification issued according to the criteria defined in the circular of the Ministry of Health".

How is the check carried out?

The check is carried out by designated personnel using the Verification C19 app. The VerificationC19 app, free and available for iOs, Android and Huawei Store, "graphically shows the verifier the effective validity of the Certification as well as the name, surname and date of birth of the holder of the same". There are three possible results: green screen if the certificate is valid in Italy and Europe, blue if only in Italy and red if it is not valid, it has expired or in case of reading error. The app does not need to be connected to the internet during verification except once a day.

It is therefore important to use only the official app and not others and employees cannot be asked to deliver or send their green pass as already reported in some cases. Even if this would streamline the access procedures to the workplace, we must not give in to comfort by sacrificing the rights that we want to protect.

What are the personal data known to the verifier and the employer?

The company and the verifier only know if the certificate is valid. The verifier will only see the name, surname and date of birth of the person to whom the green pass belongs to verify that it matches the identity of the person showing the document. Instead, he will not see any information on its duration. This way you will not be able to know if the certificate is generated by a vaccine, a cure or a tampon, which have different deadlines. Furthermore, the aforementioned personal data are only viewed but not stored on the device. As suggested in the government guidelines, if only the paper green pass is available, it will be advisable to fold the sheet so as to show only the code and hide the personal data that you do not want to show.

Anyone can check?

No. In the company, the persons in charge of ascertaining and contesting breaches of obligations must be appointed with a formal deed that prescribes the limits and instructions relating to the processing of personal data, as required by article 29 of the Gdpr. Even if there is no registration of the green pass information through the app, the person in charge could still decide to write down information and personal data of the controlled employees. To avoid misunderstandings or abuses, it is important that the instructions for those in charge are clear and precise, as a guarantee for the company and employees.

Can teachers ask students if they are vaccinated?

No. The Guarantor has recently raised the problem arising from some reports concerning teachers who tried to obtain from students, both minors and adults, information on their vaccination status. Given that students of the first two cycles of education, elementary and middle school, are not even required to have a green pass, the law currently does not allow teachers or school staff to request information on the vaccination status of students or their family members and joint. As underlined by the Guarantor, clearly identifying unvaccinated students, due to impossibility or free choice, could favor dynamics of exclusion and discrimination.