Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

EDPB Clarifies Privacy Rules for COVID-19

By Philip N. Yannella, Katie Morehead & Stephanie I. Awanyai on March 17, 2020
Email this postTweet this postLike this postShare this post on LinkedIn

The successful management of COVID-19 relies on the quick analysis and collection of health data, which can raise privacy issues particularly in the European Union.  In order to help data controllers manage their COVID-19 response plans under the General Data Protection Regulation (GDPR) and other EU privacy laws, the European Data Protection Board (EDPB) released a statement discussing how governments and companies can process personal data in response to COVID-19.As the EDPB explains, Article 6 of the GDPR allows controllers to process personal data without consent of the data subject if the processing is necessary to protect the vital interests of the data subject or of another natural person, or if processing is necessary for the performance of a task carried out in the public interest. These exceptions would allow, for example, the government to process the travel history of an infected person in order to track the source of infection.

The EDPB Guidance also makes clear that Article 9 of the GDPR would allow processing of special categories of personal data such as health information without a data subject’s consent if “processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health[.]” This would allow employers to ask employees if they have the virus and document this, thereby preventing the spread of the virus to other employees.

The EDPB Guidance also addresses the use of electronic communication data to combat COVID-19. For example, in South Korea, the government has been using cell phone location data to track the location of those who are infected ensure they remain quarantined. The government has made the location data of those infected with COVID-19 public so that others may avoid contact with them. In Europe, location data can be tracked for purposes of combatting COVID-19, but the tracking is subject to the following privacy constraints.

First, the ePrivacy Directive allows for location data to be used by an operator when the location data has been made anonymous. The EDPB recommends that public authorities take this approach first when considering using location data. Second, the ePrivacy Directive allows for member states to introduce legislative measures for the purpose of national security or public security. The member state may then collect the location data, but is obliged to put in adequate safeguards such as granting individuals the right to judicial remedy.

The EDPB statement makes clear that European privacy law should not pose a barrier to the processing of health and other personal information to combat the threat of COVID-19.

Philip N. Yannella

yannellap@ballardspahr.com | 215.864.8180 | view full bio

As Practice Leader of Ballard Spahr’s Privacy and Data Security Group, and Practice Leader of the firm’s E-Discovery and Data Management Group, Philip N. Yannella provides clients with 360-degree advice on the transfer, storage, and use…

yannellap@ballardspahr.com | 215.864.8180 | view full bio

As Practice Leader of Ballard Spahr’s Privacy and Data Security Group, and Practice Leader of the firm’s E-Discovery and Data Management Group, Philip N. Yannella provides clients with 360-degree advice on the transfer, storage, and use of digital information.

Phil regularly advises clients on the Stored Communications Act (SCA), Computer Fraud and Abuse Act (CFAA), EU-US Privacy Shield, General Data Protection Regulation (GDPR), Defense of Trade Secrets Act, PCI-DSS, Telephone Consumer Protection Act (TCPA), New York Department of Financial Services Cybersecurity Regulations, ISO 27001 compliance, HIPAA Security Rules, and FTC enforcement activity, as well as eDiscovery issues—leveraging his experience serving as National Discovery Counsel for more than two dozen companies in nationwide litigation. He harnesses his deep knowledge of privacy, data security, and information governance laws to help multinational companies develop global information governance programs to comply with overlapping, and sometimes conflicting, laws. Phil serves on the advisory board for the ACC Foundation’s Cybersecurity Survey, the largest survey of in-house counsel on cybersecurity issues.

Email
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    CyberAdviser
  • Organization:
    Ballard Spahr LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo