Search Google in French for a Quebec confidentiality incident response plan and you land on the Tribunal administratif du Québec, two universities, the Ordre des ingénieurs and a few law firms. The published procedures are serious, but they come from organizations with legal departments, and not all under your law: public bodies follow the Access Act, not the private-sector statute. A fifteen-person SMB carries nearly the same obligations, set out in our summary of Law 25 obligations for SMBs, with nobody on staff to write the procedure.
This article is that procedure. We have covered the incident register and the ransomware scenario elsewhere. What follows is seven steps, from an employee's suspicion to the notice sent to the Commission d'accès à l'information, followed by the two-page plan that makes them workable even while the privacy officer is on vacation.
The short answer, for the busy
In Quebec, the procedure for a privacy breach, called a confidentiality incident in the law, comes from sections 3.5 to 3.8 of the Act respecting the protection of personal information in the private sector and from the Regulation respecting confidentiality incidents. It starts as soon as the business "has cause to believe" that personal information was accessed, used or communicated without authorization, or lost. In order: report to the person in charge of the protection of personal information, contain the incident with reasonable measures, establish the facts, then assess with that person the risk of serious injury, weighing the sensitivity of the information, the anticipated consequences of its use and the likelihood of injurious use. If the risk is serious, promptly notify the Commission d'accès à l'information in writing, then every person concerned. Every incident, reported or not, goes in the register for at least five years. The law requires no written plan, but the Commission recommends one.
What the law requires, and what it leaves you to write
Section 3.5 describes no steps. It requires "reasonable measures to reduce the risk of injury and to prevent new incidents of the same nature", then, if the risk is serious, a prompt notice to the Commission and to the people concerned. No section requires an incident response plan. The closest is section 3.2, which requires governance policies that "define the roles and responsibilities of the members of its personnel throughout the life cycle of the information".
The Commission is blunter. Its January 2026 guide on preventing confidentiality incidents calls it highly probable, even certain, that your business will be hit one day, and recommends a response plan so you can act faster.
The decisive argument is in its notification form. Section 8 asks which measures were taken from the moment of discovery and, for each one, how quickly. The same form states that the Commission does not guide organizations through incident management and does not validate their measures. It will read your response after the fact, as a timeline. The plan keeps that timeline short and defensible.
And the risk is concrete: the Commission received 514 incident notices in 2024-2025, up 16% from the previous year, 80% of them from the private sector. The most frequent causes were cyberattacks, human error and ransomware.
The procedure, in seven steps
1. Report on a suspicion. The law applies as soon as the business "has cause to believe" an incident occurred. Proof can wait. Anyone who suspects a misdirected email, unusual access or a lost device reports it to the person in charge of the protection of personal information, without trying to confirm it first. By default that is whoever holds the highest authority in the business (section 3.1), unless delegated in writing. The Commission's form asks for two dates, when the incident happened and when it was discovered: the gap between them is yours to explain.
Your vendors are part of the chain. Section 18.3 requires a service provider holding your personal information to notify your privacy officer "without delay" of any violation of its confidentiality, and you remain responsible even when a third party holds the data. The same section requires a written contract: write in it who the vendor must notify.
2. Contain within the hour. Have the email deleted, revoke access, change passwords, wipe the lost device. The Commission wants a quick reaction even without all the facts. Write down the time of each action and who took it: that is exactly what section 8 of the form will ask for. The law also lets you alert, without consent, anyone who could reduce the risk, your bank for instance, sharing only what is necessary; the privacy officer records that communication.
3. Establish the facts with six questions. The Commission's grid works as is: who is affected (employees, clients, partners) and who may have seen the information, how many people, what information and whether it is sensitive, when the incident happened and when it was discovered, where (including at a vendor), and why the existing safeguards failed.
4. Assess the risk of serious injury, with the privacy officer. Section 3.7 sets three criteria (the sensitivity of the information, the anticipated consequences of its use, the likelihood it will be used for injurious purposes) and a method: consult the person in charge of the protection of personal information. The form will ask, yes or no, whether you did. Two details often change the answer: the regulation adds possible malicious uses to what you must describe, and a footnote on the form states that the serious injury need not have materialized, only be likely.
5. Notify the Commission in writing, with what you know. The regulation lists eleven items, including the number of people concerned and how many live in Quebec, the measures taken or planned and, where applicable, the fact that an authority outside Quebec was also notified. If you serve clients in Ontario, that box sends you to the federal law that may apply alongside Law 25. The form goes by email, mail or fax, and carries three warnings: include nothing that identifies a person, expect your company's name and the incident itself may be made public, and do not treat the notice as proof of compliance. Anything you learn after sending it must "promptly be sent" (section 4 of the regulation): notify early, then complete.
6. Notify the people concerned. The individual notice has six elements: the information involved, the circumstances, the date or period, the measures taken, what the person can do to protect themselves, and contact details for more information. A public notice replaces it in only three cases: when an individual notice could increase the harm, when it would cause excessive hardship, or when you lack the person's contact details. You may hold the notice back as long as it could hamper an investigation by the authorities responsible for fighting crime. The form asks for a copy, and this text is best written calmly in advance: keep a template in the plan.
7. Record it, then fix the cause. Every incident goes in the register, reported or not, and stays there at least five years after you became aware of it. Then the part people forget once the crisis is over, though the law puts it in the same sentence as containment: preventing new incidents of the same nature. The form asks for those measures separately, with their planned dates.
The response plan, on two pages
The plan is the procedure above with names and phone numbers. The incident response plan template Ottawa published for the CyberSecure Canada certification sets a sound minimum: an executive, an incident handler, a communications lead, and a backup for each role. It ignores Law 25, so steps 4 to 6 need grafting on. In a fifteen-person SMB, that might mean the owner as person in charge of the protection of personal information, a designated backup, and the outside IT provider as the technical arm.
Page one: roles and backups, with personal cell numbers, since an incident can take down company email. Then the outside contacts: IT provider, insurer if you carry a cyber policy, bank, lawyer, and the Commission's phone numbers (418 528-7741, toll-free 1 888 528-7741). Finally, the list of systems holding personal information, with their vendors; to build that inventory, the Commission points to the method of a privacy impact assessment.
Page two: the seven steps as a checklist, a three-column timeline sheet (time, action, person) that mirrors section 8 of the form, and the template for the notice to individuals. Add one decision rule: if doubt remains about whether the risk is serious, you notify.
The federal template recommends reviewing the plan at least every three years and testing it through simulations. Half an hour a year is enough: take a salesperson's phone left in a cab, still logged into the client database, and walk through the seven steps around a table. The gaps show up fast, like the vendor nobody has an emergency number for.
Where to start
Before writing anything, confirm who your privacy officer is and who backs them up. Then check that vendors holding personal information know whom to notify. Then write the two pages on a quiet day.
When you list your systems, include the website: its forms and plugins collect personal information, and its security and Law 25 compliance are part of our web services.
→ Tell us about your situation
This article explains legal obligations to help an SMB ask the right questions; it is not legal advice. The Act respecting the protection of personal information in the private sector, the Regulation respecting confidentiality incidents and the positions of the Commission d'accès à l'information are authoritative: for a specific situation, consult a lawyer.
