Step 6 of 967%
6

Confidentiality Incident Procedure: Responding Under Law 25

Establish a clear procedure to respond quickly and effectively to a confidentiality incident.

Estimated time: 1 hour
Updated July 30, 2026

The essentials

When a confidentiality incident occurs, every hour counts. A procedure written in advance keeps you from improvising: who to alert, how to contain the leak, how to assess the risk, who notifies the CAI and the individuals affected.

The procedure puts into practice the obligations in sections 3.5 to 3.8 of Act P-39.1: take reasonable measures to reduce the risk of injury, record the incident in the log, and notify if the risk is serious.

The linchpin of the procedure is your privacy officer, the person in charge of the protection of personal information: they assess the risk and decide on notifications.

What the law says

Law 25 requires every business to have a clear, documented procedure for managing confidentiality incidents.

This procedure must:

  • Define what a confidentiality incident is
  • Explain how to detect and report an incident
  • Describe the steps to follow to limit the damage
  • Determine who must be informed and within what time frame
  • Specify the criteria for notifying the CAI and the individuals concerned

An effective procedure lets you act quickly, limit legal risks and preserve customer trust.

For a small business

In a small business, the procedure can fit on a single page that is clear and accessible to all employees. It must indicate:

  • Who to report an incident to (usually the privacy officer)
  • The immediate actions to take (e.g. disconnecting, deleting an email sent in error)
  • How to document the incident in the official log
  • The time frames for informing the authorities and the individuals concerned

Good to know

In the event of an incident presenting a serious risk of injury, you must notify the CAI and the individuals concerned. Not having a clear procedure can delay that notification and worsen the penalties.

Concrete examples

Example 1: A medical clinic adopts a procedure stating that every employee must immediately report an incident to the privacy officer.

The privacy officer assesses the severity, documents the event in the log, takes measures to limit the impact and, if necessary, sends a notification to the CAI and the affected patients within 72 hours.

Example 2: A real estate agency posts a one-page sheet near each workstation summarizing the 5 steps to follow in the event of an incident.

Every employee knows to first secure the data, then immediately contact the director (the privacy officer), who takes over the rest of the procedure.

The four reflexes of a good incident response

1. Contain: cut off access, recall the email, isolate the infected workstation. 2. Assess: what information, how many people, what serious risk of injury. 3. Record: everything in the log, including the assessment and the measures taken. 4. Notify if required: the CAI and the individuals concerned, promptly.

Test the procedure once a year with a mock scenario (a stolen laptop, a misdirected email). A procedure that is never rehearsed is a procedure that will fail on the day it matters.

Build your incident kit before the crisis

On the day of an incident, every minute spent looking for a phone number is a minute lost. Prepare in advance: a contact list (privacy officer, IT support, insurer if you have cyber coverage, legal counsel), a notice template for affected individuals ready to personalize, and your up-to-date personal information inventory so you can immediately identify what has been compromised.

Store this kit somewhere accessible even if your systems are down: a ransomware incident can cut you off from your own documents.

The four phases of an incident response

PhaseKey actionsWho acts
1. ContainCut off access, isolate the workstation, try to recall the emailThe employee who discovers the incident, with the privacy officer
2. AssessInformation involved, individuals affected, serious risk of injuryThe privacy officer
3. RecordDocument everything in the incident log, including the risk assessmentThe privacy officer
4. NotifyCAI and individuals concerned if the risk is serious, promptlyThe privacy officer, with management informed

Mistakes to avoid

  • Not training employees on the procedure
  • Not specifying response time frames
  • Forgetting to indicate who is responsible for each step
  • Having a procedure that is too vague or exists only verbally

Step-by-step instructions

1
Clearly define what a confidentiality incident is
2
Write a list of immediate actions to take
3
Specify who must be informed and how
4
Determine the criteria for notifying the CAI and the individuals concerned
5
Document the incident in the official log
6
Train employees on the procedure and send periodic reminders

Checklist: Step 6 complete?

  • My procedure clearly defines what an incident is
  • The steps to follow are documented and clear
  • Responsibilities are assigned (who does what)
  • Notification time frames are specified
  • My employees know the procedure
  • The procedure is accessible to everyone

Templates included in the Law 25 Kit

  • Internal Confidentiality Incident Procedure template
Get these templates

Frequently asked questions

Who decides whether to notify the CAI?

The privacy officer, based on the assessment of the serious risk of injury. The decision and its reasons must be documented in the incident log.

What should affected individuals be told?

What happened, what information is involved, what you did to limit the risks, and what they can do to protect themselves (change a password, monitor their accounts). Transparency limits the injury and preserves trust.

Do we have to notify even if we are not certain there was a leak?

The obligation applies as soon as you have reason to believe an incident has occurred. If you are uncertain, document the assessment in the log; that is exactly what the CAI will want to see.