Law 25 Confidentiality Incident Log: Your Obligations
Document every confidentiality incident involving personal information.
The essentials
A confidentiality incident is any unauthorized access, use or communication of personal information, or its loss: an email sent to the wrong recipient, a stolen computer, ransomware, an employee looking at a file without a valid reason.
Since September 22, 2022, every incident must be recorded in a log, no exceptions. If the incident presents a serious risk of injury, you must also promptly notify the CAI and the individuals concerned (ss. 3.5 to 3.8, Act P-39.1).
The log must be kept for at least five years after the date you became aware of the incident, and provided to the CAI on request.
The decision path when an incident happens
Incident détecté ou soupçonné
Accès, utilisation ou communication non autorisés, ou perte d'un renseignement personnel
1. Contenir
Couper l'accès, isoler le poste, tenter le rappel du courriel
2. Évaluer : risque de préjudice sérieux ?
Sensibilité du renseignement, conséquences possibles, probabilité d'utilisation préjudiciable
Pas de risque sérieux
Consigner au registre
Tout incident va au registre, avec l'évaluation du risque documentée. Conservation : au moins 5 ans.
Risque sérieux
Registre + notifications
En plus du registre : aviser la CAI et les personnes concernées avec diligence, et prendre des mesures pour réduire le préjudice.
What the law says
Law 25 requires businesses to record every confidentiality incident involving personal information in a log.
A confidentiality incident includes:
- Unauthorized access to personal information
- Its unauthorized use or communication
- Its loss
- Any other event that compromises its confidentiality or security
The log must contain:
- A description of the incident
- The date or period of the incident
- The individuals affected
- The measures taken to reduce the risks and prevent it from happening again
- The communications sent to the individuals concerned and to the CAI
⏱️ This log must be kept for at least 5 years after the date of the incident.
For a small business
Even in a small organization, an incident can happen: an email sent to the wrong recipient, a lost paper document, a compromised online account.
A simple, up-to-date, centralized log allows you to:
- Respond quickly to your legal obligations
- Demonstrate due diligence in the event of an investigation
- Improve internal security
Good to know
Some incidents must be reported to the CAI and to the individuals concerned, in particular when the incident presents a serious risk of injury. Failing to do so can lead to significant penalties.
Concrete examples
Example 1: An online store notes in its log that an employee sent a client statement to the wrong email address on February 14, 2025.
The incident was corrected by contacting the client, deleting the erroneous email and reminding the team of the verification procedures before sending.
Example 2: A physiotherapy clinic discovers that a former employee still had access to the patient management software 3 months after leaving.
The incident is documented, access is revoked immediately, and a new procedure for deactivating accounts when employees leave is put in place.
The log and notification: two separate obligations
Many businesses believe a minor incident does not need to be documented. That is wrong: every incident goes in the log, even one with no apparent consequences. Notifying the CAI and the affected individuals, on the other hand, only applies when the incident presents a serious risk of injury.
To assess that risk, the law looks in particular at the sensitivity of the information, the anticipated consequences of its use, and the likelihood that it will be used for injurious purposes. An exposed social insurance number weighs far more than a first name and an email address. When in doubt, document your assessment in the log: it is your proof of diligence.
The law does not set a deadline in hours for notifying the CAI: it requires you to act promptly. Prepare your incident response procedure in advance so you are not improvising the day it happens.
Log it or report it: what to do depending on the incident
Four situations that small businesses face often, and how the law says to handle each one. In every case, the risk assessment is documented in the log.
| Situation | Record in the log | Notify the CAI and individuals |
|---|---|---|
| Email sent to the wrong recipient, recalled right away, low-sensitivity content | Yes | No, if the assessment concludes there is no serious risk of injury |
| Theft of a laptop containing unencrypted client files | Yes | Yes, a serious risk of injury is likely |
| Ransomware with possible data exfiltration | Yes | Yes, promptly |
| Employee browsing files without a business need | Yes | Depends on the sensitivity of the information and the assessed risk |
Mistakes to avoid
- Not documenting a "minor" incident because it seems unimportant
- Using a log scattered across several documents
- Forgetting to record the corrective measures taken
- Not protecting access to the log
Step-by-step instructions
Checklist: Step 5 complete?
- I have created a centralized log for incidents
- I know what constitutes a confidentiality incident
- I know what information to document for each incident
- I know when to report an incident to the CAI
- The log is protected and accessible only to authorized people
- I will keep entries for at least 5 years
Templates included in the Law 25 Kit
- Confidentiality Incident Log template
- Confidentiality Incident Notification Letter template
Frequently asked questions
Do all incidents have to be reported to the CAI?
No. Every incident goes in the log, but only incidents that present a serious risk of injury must be reported to the CAI and to the individuals concerned.
What is a serious risk of injury?
A risk assessed based on the sensitivity of the information, the possible consequences of its use (fraud, identity theft, reputational harm) and the likelihood it will be used for injurious purposes. That assessment is your privacy officer's responsibility.
Does an incident caused by an employee count?
Yes. Unauthorized access includes internal access: an employee who looks at files without a business need is a confidentiality incident that must be logged.
What must the log contain?
A description of the incident, its date or period, the information involved, the number of people affected, the assessment of the risk of injury, the measures taken and, where applicable, the notices sent. Keep everything for at least five years.