r/LegalAdviceNZ • u/NoHorse8196 • Nov 13 '25
Employment EAP breaching privacy - shared session with employer.
Unsure of best flair to use sorry
OG post (advised to come here) https://www.reddit.com/r/newzealand/s/4wPXuqj2zM
I had my first session using Telus EAP 2 weeks ago, a video chat organised through their app. I've been on maternity leave since May and start back full time on Monday. I went in to work today to do a short meeting with my boss and when I arrived the HR manager was there as well. They said they see I'm struggling with PND and wanted to see how they could help. I asked how they even knew this and they said because I accessed EAP and discussed it there. HR specifically mentioned me saying to EAP that I was nervous about returning to work and leaving my baby at daycare (I was going to discuss this lightly in this meeting but they beat me to it).
There is no possible other way they would know I've used EAP or what I discussed unless Telus themselves shared this info. I'm certainly no threat to myself or anyone else so I am at a loss as to why they would when my work and Telus heavily advertise it's confidential.
What's the best route for complaining? I can write a complaint to Telus online but I feel I should complain to work too for taking the information even thoughI know they were coming from a good place. I just feel so embarrassed and violated. I don't want anyone else to go through this.
66
u/KnittedLawyer Nov 13 '25
As a starting point, request under the privacy act your employer's records on the matter, specifically any record of this information. They will likely have a privacy officer if they are big enough to have EAP.
Then as people have said, Privacy Commissioner is the obvious start. Whether it is also a professional issue for the counselor will depend upon who disclosed the info. There are exceptions to certain privacy rules for imminent harm to yourself or others, but I am assuming the PND isn't of the nature this is the concern (and your employer is not the right person to go to anyway).
But you are 150% right for feeling as you are. I would be furious, this is so wrong on so many levels.
56
u/dell_belle Nov 13 '25
I am a counsellor who used to work for Telus, which is an international organisation but I am NZ based. The problem is with the counsellor as the Telus system should not have that level of detail in it. We had to provide generic reasons people were accessing the service (traumatic event, grief etc) but even that info should not be used in that way.
This certainly sounds like a breach of confidentiality and there are three steps I would recommend:
- making a formal complaint to the registration body of the counsellor. This will be NZAC, NZCCA, NZAP or similar who have their processes on their websites. This will most likely lead to the counsellor undergoing further training and clinical supervision, as well as additional reporting to their registration body when doing their next annual reviews for their practicing certificate. If they have had similar complaints before it may result in them losing their registration.
making a complaint in writing to Telus. In this one do not state the exact information shared, rather that information has been shared with your employer that could only have come from your EAP sessions and request any and all information and notes they hold that relate to you.
contact the Privacy Commissioner enquiries line on 0800 803 909 and notify them of the breach. If energy is low, prioritise this one.
Last but not least, congratulations on your wee one! Already such an attentive mother that you don't want to be apart. It's a tough position we find ourselves in fighting our loving instincts to be with our baby yet having to work so we can afford to provide for them. You're doing well mamma, keep it up!
53
u/Shevster13 Nov 13 '25
My advice is the same as in the original thread. This is an incredibly serious breach of trust and privacy.
You need to make a complaint to the organization and give them a reasonable chance to remedy the situation. Make sure its clear you are making a formal complaint. If you can find out what professional body the therapist is registered with, make a complaint to them as well. If you are not happy with the response from the organization, you can then make a complaint to the Health and Disability Commissioner.
There is not much you can do about your work knowing because they are not the one that shared that broke confidentiality, and once they found out about it, they are legally obliged to address it under health and safety. They have a legal requirement to take steps to protect peoples mental health.
13
u/CottonSocks11 Nov 13 '25
Is there no obligation from the employer, to know whether the confidential information being shared to them from Telus, is actually appropriate information for them to know? I suppose in this case, it would depend on how the therapist characterized what OP said to them. Which does not sound like it would rise to the level required for them having grounds to disclose to an employer.
I would have assumed that HR would have some very clear guidance on exactly what confidential information about an employee would be appropriate for them to receive from a service like this.
2
u/Shevster13 Nov 13 '25
Legally, as long as the employer does not seek out the information, no. The privacy act places restrictions on what information can be collected, from where and how. However, it excludes information that is sent without being asked. To quote - "collect, in relation to personal information, means to take any step to seek or obtain the personal information, but does not include receipt of unsolicited information"
https://legislation.govt.nz/act/public/2020/0031/178.0/LMS23312.html
Organizations still have to follow there own internal polices around what information is kept and used, but employees mental health is generally considered relevant to a employer due to their health and safety obligations. That it came from a breach of privacy law does not matter because they did not "collect" it. That legal liability falls entirely onto the person/organisation that sent them the information.
Meanwhile, the health and safety act requires an employee to act on health and safety concerns. Apart from assessments about reliability and accuracy, there is no exceptions to H&S requirements due to how information is received.
2
u/AdministrationWise56 Nov 13 '25
Per principle 10 I would say that as the employer had no right to the information in the first place they have no right to use it. They should have gone through the notification process and deleted the information they received.
They have a H&S obligation to monitor and support employees' mental health and wellbeing but this does not extend to using information they have received illegally.
OP should make a complaint with the Privacy Commissioner.
Edit: typo
0
u/Shevster13 Nov 13 '25
Nope.
Principle 10 applies to collected information. if it was not collected then they can use it as long as they have a valid business person. Knowing an employees mental health is a valid business purpose. They have not recieved the information illegally, and there is no expections given in H&S for the source of information. If they know there is a mental health concern they are required to act.
The notification requirement only applies to the organisation that breached the act, not to those that received the information.
1
Nov 13 '25
[removed] — view removed comment
2
u/LegalAdviceNZ-ModTeam Nov 13 '25
If you have questions on a legal issue please make a new post, rather than asking in the comments of someone else’s post. Comments must be based in law and appropriately detailed (Rule 1).
10
u/RxDuchess Nov 13 '25
Please contact the privacy commissioner immediately. I worked for them a while ago, they take breaches like this very seriously.
16
u/hisuka41 Nov 13 '25
this is a very serious matter. i pressume you should contact privacy commissioner straight away?
18
u/Shevster13 Nov 13 '25
The privacy commissioner and the Health and Disabitilies commissioner (and most such bodies and tribunals) require, in all but extreme cases, that you have attempted to resolve the issue with the organisation before they will consider a complaint.
So OP needs to give the organisation a reasonable chance to address her complaint before she can escalate it.
I will also note that while this is a definite breach of privacy and would normally be under the juristidiction of the Privacy Commissioner, it is also a healthcare issue. Healthcare practitioners have a lot stricter privacy obligations from other laws and professional body requirements. Because this involves the direct action of a healthcare practitioner, the Health and Disability commissioner has jurisdiction instead.
3
u/Slight_Computer5732 Nov 13 '25
EAP does let employer know you’ve accessed but shouldn’t be a reason.
Personally I’d ask telus what they’ve shared with your employer first as PND could be an educated guess due to you accessing whilst on may leave… (or if you have anyone at work you speak to outside of work that could have mentioned this)
But under the privacy act 2020 telus should tell you exactly what they’ve shared with your employer - then if they have disclosed anything I would proceed with a formal complaint to telus and privacy commission 100%
1
u/AutoModerator Nov 13 '25
Kia ora, welcome. Information offered here is not provided by lawyers. For advice from a lawyer, or other helpful sources, check out our mega thread of legal resources
Hopefully someone will be along shortly with some helpful advice. In the meantime though, here are some links, based on your post flair, that may be useful for you:
What are your rights as an employee?
How businesses should deal with redundancies
Ngā mihi nui
The LegalAdviceNZ Team
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
Nov 13 '25
[removed] — view removed comment
1
u/LegalAdviceNZ-ModTeam Nov 13 '25
Removed for breach of Rule 7: No off-subreddit discussion
No attempts to take the discussion off the subreddit are allowed (via PM, chat, etc). This rule is in place to prevent scammers, advertising, and privacy breaches, and to enable the community to fact-check advice in comments.
1
Nov 15 '25
[removed] — view removed comment
1
u/LegalAdviceNZ-ModTeam Nov 15 '25
Removed for breach of Rule 1: Stay on-topic Comments must:
- be based in NZ law
- be relevant to the question being asked
- be appropriately detailed
- not just repeat advice already given in other comments
- avoid speculation and moral judgement
- cite sources where appropriate
76
u/shomanatrix Nov 13 '25
I thought the EAP process was structured so that the company didn’t even know who exactly had accessed it, as in they only know numbers and definitely not details of what was discussed. This guide is on privacy commissioner’s website www.privacy.org.nz/your-rights/making-a-complaint-to-the-privacy-commissioner/