Step 5 of 956%
5

Law 25 Confidentiality Incident Log: Your Obligations

Document every confidentiality incident involving personal information.

Estimated time: 30 minutes (setup)
Updated July 30, 2026

The essentials

A confidentiality incident is any unauthorized access, use or communication of personal information, or its loss: an email sent to the wrong recipient, a stolen computer, ransomware, an employee looking at a file without a valid reason.

Since September 22, 2022, every incident must be recorded in a log, no exceptions. If the incident presents a serious risk of injury, you must also promptly notify the CAI and the individuals concerned (ss. 3.5 to 3.8, Act P-39.1).

The log must be kept for at least five years after the date you became aware of the incident, and provided to the CAI on request.

The decision path when an incident happens

Incident détecté ou soupçonné

Accès, utilisation ou communication non autorisés, ou perte d'un renseignement personnel

1. Contenir

Couper l'accès, isoler le poste, tenter le rappel du courriel

2. Évaluer : risque de préjudice sérieux ?

Sensibilité du renseignement, conséquences possibles, probabilité d'utilisation préjudiciable

Pas de risque sérieux

Consigner au registre

Tout incident va au registre, avec l'évaluation du risque documentée. Conservation : au moins 5 ans.

Risque sérieux

Registre + notifications

En plus du registre : aviser la CAI et les personnes concernées avec diligence, et prendre des mesures pour réduire le préjudice.

What the law says

Law 25 requires businesses to record every confidentiality incident involving personal information in a log.

A confidentiality incident includes:

  • Unauthorized access to personal information
  • Its unauthorized use or communication
  • Its loss
  • Any other event that compromises its confidentiality or security

The log must contain:

  • A description of the incident
  • The date or period of the incident
  • The individuals affected
  • The measures taken to reduce the risks and prevent it from happening again
  • The communications sent to the individuals concerned and to the CAI

⏱️ This log must be kept for at least 5 years after the date of the incident.

For a small business

Even in a small organization, an incident can happen: an email sent to the wrong recipient, a lost paper document, a compromised online account.

A simple, up-to-date, centralized log allows you to:

  • Respond quickly to your legal obligations
  • Demonstrate due diligence in the event of an investigation
  • Improve internal security

Good to know

Some incidents must be reported to the CAI and to the individuals concerned, in particular when the incident presents a serious risk of injury. Failing to do so can lead to significant penalties.

Concrete examples

Example 1: An online store notes in its log that an employee sent a client statement to the wrong email address on February 14, 2025.

The incident was corrected by contacting the client, deleting the erroneous email and reminding the team of the verification procedures before sending.

Example 2: A physiotherapy clinic discovers that a former employee still had access to the patient management software 3 months after leaving.

The incident is documented, access is revoked immediately, and a new procedure for deactivating accounts when employees leave is put in place.

The log and notification: two separate obligations

Many businesses believe a minor incident does not need to be documented. That is wrong: every incident goes in the log, even one with no apparent consequences. Notifying the CAI and the affected individuals, on the other hand, only applies when the incident presents a serious risk of injury.

To assess that risk, the law looks in particular at the sensitivity of the information, the anticipated consequences of its use, and the likelihood that it will be used for injurious purposes. An exposed social insurance number weighs far more than a first name and an email address. When in doubt, document your assessment in the log: it is your proof of diligence.

The law does not set a deadline in hours for notifying the CAI: it requires you to act promptly. Prepare your incident response procedure in advance so you are not improvising the day it happens.

Log it or report it: what to do depending on the incident

Four situations that small businesses face often, and how the law says to handle each one. In every case, the risk assessment is documented in the log.

SituationRecord in the logNotify the CAI and individuals
Email sent to the wrong recipient, recalled right away, low-sensitivity contentYesNo, if the assessment concludes there is no serious risk of injury
Theft of a laptop containing unencrypted client filesYesYes, a serious risk of injury is likely
Ransomware with possible data exfiltrationYesYes, promptly
Employee browsing files without a business needYesDepends on the sensitivity of the information and the assessed risk

Mistakes to avoid

  • Not documenting a "minor" incident because it seems unimportant
  • Using a log scattered across several documents
  • Forgetting to record the corrective measures taken
  • Not protecting access to the log

Step-by-step instructions

1
Create a single document to serve as the official log
2
Record each incident as soon as it occurs
3
Describe the facts, the impacts and the measures taken
4
Determine whether the incident must be reported to the CAI and the individuals concerned
5
Protect the log with a password or restricted access
6
Keep each entry for at least 5 years

Checklist: Step 5 complete?

  • I have created a centralized log for incidents
  • I know what constitutes a confidentiality incident
  • I know what information to document for each incident
  • I know when to report an incident to the CAI
  • The log is protected and accessible only to authorized people
  • I will keep entries for at least 5 years

Templates included in the Law 25 Kit

  • Confidentiality Incident Log template
  • Confidentiality Incident Notification Letter template
Get these templates

Frequently asked questions

Do all incidents have to be reported to the CAI?

No. Every incident goes in the log, but only incidents that present a serious risk of injury must be reported to the CAI and to the individuals concerned.

What is a serious risk of injury?

A risk assessed based on the sensitivity of the information, the possible consequences of its use (fraud, identity theft, reputational harm) and the likelihood it will be used for injurious purposes. That assessment is your privacy officer's responsibility.

Does an incident caused by an employee count?

Yes. Unauthorized access includes internal access: an employee who looks at files without a business need is a confidentiality incident that must be logged.

What must the log contain?

A description of the incident, its date or period, the information involved, the number of people affected, the assessment of the risk of injury, the measures taken and, where applicable, the notices sent. Keep everything for at least five years.