Hospitality sector is failing on contact-tracing obligations
Summary
A little over a month since bars, cafes, pubs and restaurants in England were allowed to reopen under a loosening of the Covid-19 lockdown restrictions, thousands are failing to comply with the General Data Protection Regulation (GDPR) and data protection compliance rules associated with the mandated collection of customer information. Currently, hospitality businesses are obliged to collect their customers’ contact details to assist in tracking and tracing any Covid-19 flare-ups, and although the majority are complying with the spirit of this requirement, new research undertaken by security software firm TAAP and data compliance specialist OSP Cyber Academy suggests that many are unwittingly breaching the law and putting themselves at risk of fines or legal action. The most common failings uncovered in the joint study were the use of inadequate pen-and-paper systems to record customer information, and failure to train staff in how collected data should be used and stored, and for how long. Covid has brought a whole new issue for small businesses like pubs and cafes which are not used to handling customers’ personal data.” TAAP CEO Steve Higgon added: “After the hospitality sector reopened, we asked our staff to make notes on the systems used to record their data when they went out. To protect small hospitality businesses better against such risks, TAAP and OSP have developed a new secure identification feature for TAAP’s Visitor Book app, which was originally designed as a contactless receptionist service, and uses the QR code-scanning feature of a smartphone to generate unique visitor or customer IDs.