Compliance

The confidentiality incident registry: keeping it without drowning

July 27, 2026
Xavier PeichBy Xavier Peich

A misdirected email is a confidentiality incident. What Law 25 requires: log everything for five years, and report only serious cases to the CAI.

The confidentiality incident registry: keeping it without drowning

An employee sends the payroll file to the wrong recipient. An assistant browses a client's file out of curiosity. A work laptop stays behind on the back seat of a taxi. In the eyes of Law 25, these three ordinary mishaps share one name, confidentiality incident, and trigger the same obligation, the most concrete and least respected of all the duties covered in our summary of Law 25 obligations for SMBs: recording the incident in a registry.

Since September 22, 2022, every Quebec business must keep this registry, whatever its size. Many SMBs don't have one. Rarely out of bad faith: mostly because they believe the obligation targets spectacular hacks, not last Tuesday's misdirected email, and because nobody has shown them a registry that takes fifteen minutes per incident.

This article settles both: what counts as an incident, what goes in the registry, what gets reported to the Commission d'accès à l'information (CAI), and the reflex to install in a fifteen-person company.

The short answer, for the busy

Since September 22, 2022, Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, imposes two distinct duties on every business. First: record every confidentiality incident in a registry, however minor. An incident is any access, use or communication of personal information not authorized by law, or its loss (section 3.6): an email sent to the wrong recipient qualifies. The Regulation respecting confidentiality incidents lists eight elements the registry must contain and requires keeping each entry at least five years after the business becomes aware of the incident. Second: if the incident presents a risk of serious injury, notify the Commission d'accès à l'information with diligence, through its official form, and notify each person affected. The assessment, made with the privacy officer, weighs the sensitivity of the information, the anticipated consequences of its use, and the likelihood it will be used to cause harm.

An incident is much broader than a hack

Section 3.6 of the Act defines a confidentiality incident in four branches: access to personal information not authorized by law, its unauthorized use, its unauthorized communication, and its loss or "any other breach of the protection of such information".

Reread that list with your average week in mind rather than the headlines. The email sent to the wrong recipient is an unauthorized communication. The employee who digs through a client file with no business reason commits unauthorized access, even if nothing leaves the company. The misplaced USB key is a loss, recovered or not. The ransomware that encrypts your server is a breach of protection, even without proof of exfiltration. And the definition contains no severity threshold: one piece of personal information, one person affected, and the incident exists.

That is the first mental unlock. A company that claims it has never had a confidentiality incident probably doesn't have exceptional security: it has too narrow a definition. Addressing errors and curiosity lookups happen anywhere humans handle files.

Two tiers: log everything, report rarely

The law splits the response into two tiers, and confusing them explains half the empty registries.

First tier, the registry (section 3.8): every incident goes in, no exceptions, including those that present no serious risk. Second tier, reporting (section 3.5): only if the incident presents "a risk of serious injury" must you notify the CAI with diligence, then each person affected.

The design has its logic. If everything had to be reported, the CAI would drown in misdirected emails and businesses would stop paying attention. If nothing had to be logged, every business would conclude, file by file, that its own case wasn't that serious. The registry forces organizational memory; the reporting threshold reserves the alarm for cases that deserve it. And the registry has an outside reader: on request, you must send the Commission a copy. That is exactly what makes an empty registry risky. A fifteen-person company that produces a blank page after three years is not demonstrating an absence of incidents: it is demonstrating an absence of tracking.

The penalties give the scale. Failing to report an incident that should have been reported is explicitly listed among the breaches subject to administrative monetary penalties, up to $10 million or 2% of worldwide turnover, and among the penal offences, $15,000 to $25 million or 4% (sections 90.1, 90.12 and 91). Nobody will hit an SMB with those ceilings over one email, but the registry is the first thing an investigator will ask for.

Assessing the "risk of serious injury"

Everything therefore hinges on an assessment, and the law tells you how to run it. Section 3.7 imposes three criteria: the sensitivity of the information concerned, the anticipated consequences of its use, and the likelihood it will be used for injurious purposes. The same section also imposes a method: consult your privacy officer. The assessment is not meant to happen alone in the owner's head at 5 p.m. on a Friday.

The three criteria combine, which is what makes the exercise workable. The payroll file sent by mistake to your external accountant, who confirms deleting it: sensitive information, but a known and trusted recipient, and a near-zero likelihood of harmful use. You log it, you don't report it, and you note the reasoning in the registry. The same data exfiltrated by ransomware, social insurance numbers included: maximum sensitivity, heavy potential consequences (fraud, identity theft), real likelihood. You report.

If the conclusion is "serious risk", the mechanics are mapped out. The notice to the CAI goes through its official form (formulaire.cai.gouv.qc.ca) and its content is set by regulation: identification of the business, description of the information involved, circumstances and cause if known, dates, number of persons affected including Quebec residents, your risk analysis, the measures taken and those planned. You don't need to know everything before notifying: the regulation provides that information obtained later is passed along as it comes, with diligence. The notice to affected persons must give them the means to protect themselves: what leaked, in what circumstances, what you did, what they can do, and a contact point. In some cases a public notice can replace individual notices, notably when you don't have people's contact information or when individual notice would be excessively difficult.

The registry fits in a spreadsheet

No specialized software is required. The Regulation respecting confidentiality incidents requires eight pieces of information per incident, no more, no less: a description of the information involved (or the reason you don't know), a brief description of the circumstances, the date or period of the incident (or an approximation), the date you became aware of it, the number of persons affected (or an approximation), the elements that lead you to conclude there is or is not a risk of serious injury, the dates of the notices to the CAI and to affected persons if the incident was reported, and the measures taken to reduce the risk.

In other words: a spreadsheet with eight columns, one row per incident. The sixth column matters most, because it documents your judgment: two sentences on sensitivity, consequences and likelihood are often enough. The regulation adds two housekeeping rules: keep the information up to date, and keep each entry at least five years after you became aware of the incident. Five years outlasts the team's memory and many employees' tenure: the file has to survive departures, which argues for a shared, known location, not one person's laptop.

Fifteen minutes per incident, honestly. The real cost isn't the writing: it's installing the reporting reflex.

The 48-hour reflex at fifteen employees

In an SMB, nobody holds the title of "incident response lead". So you need a simple script, known to everyone, that fits on one page.

First move, within the hour: whoever spots the incident tells the privacy officer. For that move to happen, the team must have heard it clearly: flagging a misdirected email is the procedure, not a confession. A culture that punishes the messenger guarantees an empty registry and late surprises.

Second move, same day: contain. Recall or have the email deleted, revoke the access, change the passwords, isolate the affected machine. Containment is a legal duty in its own right: section 3.5 requires "reasonable measures" to reduce the risk of injury and prevent incidents of the same nature. The law even allows you to notify, without consent, a third party able to reduce the risk, your bank for instance, sharing only what's necessary; the privacy officer then records that communication.

Third move, within 48 hours: open the registry row while the facts are fresh, then settle the serious-injury question with the privacy officer, section 3.7 criteria in hand. If doubt persists, it leans toward reporting: a cautious notice to the CAI costs an hour of form-filling, an omission can cost a penalty. Only then, fix the root cause: the address field that autocompletes badly, the access never revoked from the ex-employee, the missing backup.

Where to start

Three moves this week. Create the eight-column spreadsheet and put it somewhere shared, with a first retroactive row if an incident comes back to mind. Appoint the privacy officer if it isn't done, and write the 48-hour script on one page. Then tell the team, in five minutes of a staff meeting, what an incident is and who to flag it to.

The registry then lives at the pace of your tools. Your website is one of the possible sources of incidents, a leaky form, a compromised plugin, which is one reason compliance is ongoing maintenance in our web subscriptions rather than a one-off project. What your visitors see of all this is your privacy policy; the registry is the document you only ever show the Commission, and the day it asks, you'll be glad it exists.

If you want the reflex in place without losing a month to it, let's talk: we set up this kind of machinery with our clients, registry, script and quick training included.

→ Tell us about your situation

This article explains legal obligations to help an SMB ask the right questions; it is not legal advice. The Act respecting the protection of personal information in the private sector, the Regulation respecting confidentiality incidents, and the positions of the Commission d'accès à l'information prevail: for a specific situation, consult a lawyer.

Xavier Peich

Written by

Xavier Peich