Problem Gambling Foundation tightens privacy rules after email breach
Tue, 11th Aug 2026 (Today)
PGF Services has completed an investigation into a privacy breach involving a client email. The inquiry found human error and process failures.
The breach happened when an email invitation was sent to a group of clients without using blind copy, making recipients' email addresses visible to others. A follow-up message then caused further harm by making the email thread more visible.
The immediate cause was that client email addresses were entered in the recipient field instead of the blind copy field. The investigation also identified broader weaknesses in instructions and staff training for email communications.
The review also found problems with how the distribution list had been assembled. A data migration affecting the Client Management System meant the list included people who had not been in contact with the service for several years, adding to the distress caused by the incident.
PGF Services notified the Office of the Privacy Commissioner on the day of the breach. The organisation said the regulator later confirmed the incident was a notifiable privacy breach and provided advice on obligations and next steps.
Actions taken
PGF Services has apologised to affected clients and asked recipients to delete the original email. It also removed email contact permissions for clients who requested this and closed files where requested.
The service reviewed how the distribution list was created and changed its bulk email procedures. Changes included updated requirements and training for bulk email communications, as well as a compulsory second-person check before bulk emails are sent.
It also reviewed consent forms, email permissions, engagement dates, and records relating to inactive clients. Staff later took part in a post-incident debrief and received further internal communication aimed at reducing the risk of a similar error.
Record retention
The investigation also prompted questions from some clients about deleting clinical records. PGF Services sought advice from Health NZ Privacy and was told that clinical records cannot be deleted because they must be retained under health record requirements, including a minimum 10-year retention period.
The organisation can close or discharge active involvement and remove non-essential contact permissions when requested. Clients also retain the right to request access to their information and seek correction of information they believe is inaccurate.
The message to clients included an apology from senior leadership. "Again, on behalf of PGF, I am very sorry that this occurred and for the impact it has had on you. Thank you to those of you who raised your concerns with us. Your complaints have helped us identify important changes to strengthen our privacy processes," said Bridgitte Thornley, Clinical Director, PGF Services.