All businesses are required by law to have a QR Code from the NZ COVID Tracer app displayed in a prominent place at or near the main entrance to their workplace. The QR Code must be for the Government endorsed NZ COVID Tracer app (other QR Codes are not sufficient to meet the legal requirements). People can then use the app on their phone to record their movements.
If you have different parts of your business, you may want to consider different QR codes for each. For example, MPI recommends that for hospitality businesses with dine in and takeaway components, that there is a different QR Code for each.
You must also have systems and processes in place to ensure that people scan in using the QR Codes or otherwise provide a contact tracing record. The simplest way of doing this is by providing a register.
You should also consider the following:
- Accuracy: How you’ll ensure the register is complete, and is being used and maintained correctly.
- Minimising shared surfaces: How you’ll prevent customers or staff from touching common surfaces, or using common equipment (eg pens and paper), in order to enter details. Where possible, you could have specified staff taking details verbally from people and writing them down. This will also address the privacy security concern noted below.
- Location: Where the register will be located and who is best placed to enter the information.
- Zoning: Whether you divide your workspace/premises into zones and limit movement between the zones.
As you will be collecting personal information about individuals, you need to ensure you comply with the Privacy Act. This includes the following:
- Collection and consent: You need to let people know that you are collecting the information and what you are going to do with it. As part of the information gathering process, you should let people know that the information may be provided to Government if requested for contact tracing purposes.
- Security: You need to keep the register secure. If you are using pieces of paper, these need to be stored securely and not accessible by anyone who does not need access. This also means not passing the register around to complete, so everyone can see each other’s details.
- Access: If a person requests access to the information held about them, you need to respond to that request. More information on dealing with access requests is available here.
- Deletion: You should delete the information after 60 days.
- Use and disclosure: Generally, you can only use the information for the purpose for which you got it. This means only providing it to the Government if requested for the purposes of contact tracing a confirmed or suspected case of COVID-19.
More information about the requirements of the Privacy Act is available on the Privacy Commissioner’s website here.
This is not a chance to freely add people to your mailing list. If you are collecting contact tracing information, you can generally only use it for contact tracing purposes. If you would like to sign people up to your mailing list, then you must ask them separately.