Confidentiality Incident Procedure: Responding Under Law 25
Establish a clear procedure to respond quickly and effectively to a confidentiality incident.
The essentials
When a confidentiality incident occurs, every hour counts. A procedure written in advance keeps you from improvising: who to alert, how to contain the leak, how to assess the risk, who notifies the CAI and the individuals affected.
The procedure puts into practice the obligations in sections 3.5 to 3.8 of Act P-39.1: take reasonable measures to reduce the risk of injury, record the incident in the log, and notify if the risk is serious.
The linchpin of the procedure is your privacy officer, the person in charge of the protection of personal information: they assess the risk and decide on notifications.
What the law says
Law 25 requires every business to have a clear, documented procedure for managing confidentiality incidents.
This procedure must:
- Define what a confidentiality incident is
- Explain how to detect and report an incident
- Describe the steps to follow to limit the damage
- Determine who must be informed and within what time frame
- Specify the criteria for notifying the CAI and the individuals concerned
An effective procedure lets you act quickly, limit legal risks and preserve customer trust.
For a small business
In a small business, the procedure can fit on a single page that is clear and accessible to all employees. It must indicate:
- Who to report an incident to (usually the privacy officer)
- The immediate actions to take (e.g. disconnecting, deleting an email sent in error)
- How to document the incident in the official log
- The time frames for informing the authorities and the individuals concerned
Good to know
In the event of an incident presenting a serious risk of injury, you must notify the CAI and the individuals concerned. Not having a clear procedure can delay that notification and worsen the penalties.
Concrete examples
Example 1: A medical clinic adopts a procedure stating that every employee must immediately report an incident to the privacy officer.
The privacy officer assesses the severity, documents the event in the log, takes measures to limit the impact and, if necessary, sends a notification to the CAI and the affected patients within 72 hours.
Example 2: A real estate agency posts a one-page sheet near each workstation summarizing the 5 steps to follow in the event of an incident.
Every employee knows to first secure the data, then immediately contact the director (the privacy officer), who takes over the rest of the procedure.
The four reflexes of a good incident response
1. Contain: cut off access, recall the email, isolate the infected workstation. 2. Assess: what information, how many people, what serious risk of injury. 3. Record: everything in the log, including the assessment and the measures taken. 4. Notify if required: the CAI and the individuals concerned, promptly.
Test the procedure once a year with a mock scenario (a stolen laptop, a misdirected email). A procedure that is never rehearsed is a procedure that will fail on the day it matters.
Build your incident kit before the crisis
On the day of an incident, every minute spent looking for a phone number is a minute lost. Prepare in advance: a contact list (privacy officer, IT support, insurer if you have cyber coverage, legal counsel), a notice template for affected individuals ready to personalize, and your up-to-date personal information inventory so you can immediately identify what has been compromised.
Store this kit somewhere accessible even if your systems are down: a ransomware incident can cut you off from your own documents.
The four phases of an incident response
| Phase | Key actions | Who acts |
|---|---|---|
| 1. Contain | Cut off access, isolate the workstation, try to recall the email | The employee who discovers the incident, with the privacy officer |
| 2. Assess | Information involved, individuals affected, serious risk of injury | The privacy officer |
| 3. Record | Document everything in the incident log, including the risk assessment | The privacy officer |
| 4. Notify | CAI and individuals concerned if the risk is serious, promptly | The privacy officer, with management informed |
Mistakes to avoid
- Not training employees on the procedure
- Not specifying response time frames
- Forgetting to indicate who is responsible for each step
- Having a procedure that is too vague or exists only verbally
Step-by-step instructions
Checklist: Step 6 complete?
- My procedure clearly defines what an incident is
- The steps to follow are documented and clear
- Responsibilities are assigned (who does what)
- Notification time frames are specified
- My employees know the procedure
- The procedure is accessible to everyone
Templates included in the Law 25 Kit
- Internal Confidentiality Incident Procedure template
Frequently asked questions
Who decides whether to notify the CAI?
The privacy officer, based on the assessment of the serious risk of injury. The decision and its reasons must be documented in the incident log.
What should affected individuals be told?
What happened, what information is involved, what you did to limit the risks, and what they can do to protect themselves (change a password, monitor their accounts). Transparency limits the injury and preserves trust.
Do we have to notify even if we are not certain there was a leak?
The obligation applies as soon as you have reason to believe an incident has occurred. If you are uncertain, document the assessment in the log; that is exactly what the CAI will want to see.