Re: Is the QR code check part of the app in a legal requirement for venues?
"Any data gathered via the QR coding cannot be pinpointed to an individual (supposedly)"
The way it works is that the device retains the QR code and the system periodically broadcasts a list of QR codes for tainted (in absence of a better word) premises. The app then matches this list against the codes it's gathered and warns the user so the data gathered from the QR codes never leaves the device. Allegedly. And by now I think HMG is well aware that it would never weather the consequences if it proved to be otherwise.
In fact I think they're missing a trick here. The app registers the user's home postcode and the system broadcasts lists of postcodes which are considered to be hotspots so it can warn the user if and when their own postcode is put on the list. There's no mention of the QR codes including the premises postcodes; if they did it could alert the user tot he fact thet they're now in a hotspot even if the particular premises aren't tainted.