OKTO Solutions

Privacy Incident: What to Do and When to Notify the Commission

A privacy incident isn’t just a ransomware attack. An email sent to the wrong person is one. A laptop left in a taxi is one. An employee browsing a colleague’s file for no reason is one. The law’s definition is intentionally broad, and that’s what catches small businesses off guard when it happens.

This page covers what qualifies as an incident, what to do in every case, when to notify the Commission d’accès à l’information, and the technical factor that determines everything: logging.

Quick answer: A privacy incident is any unauthorized access to, use of, or disclosure of personal information, or its loss. In all cases, you must take reasonable steps to reduce the risk and record the incident in your register. If the incident poses a risk of serious harm, you must promptly notify the Commission d’accès à l’information and the individuals affected.

1. What Counts as an Incident

Section 3.6 gives an intentionally broad definition. A privacy incident is:

  1. unauthorized access to personal information;
  2. unauthorized use of personal information;
  3. unauthorized disclosure of personal information;
  4. the loss of personal information or any other breach of its protection.

The fourth point significantly expands the scope. You don’t need a hacker. Ransomware that encrypts your files without exfiltrating them still constitutes a breach of protection, and therefore an incident.

Data breach alert on a company's systems

2. What You Must Do in Every Case

Section 3.5 sets out an obligation that applies as soon as you have reason to believe an incident has occurred, even before any risk assessment: take reasonable steps to reduce the risk of harm and prevent further incidents of the same kind.

That means containing the situation, then fixing the root cause: revoking access, resetting passwords, isolating a workstation, recalling an email, updating a procedure.

Section 3.8 also requires you to maintain a privacy incident register. The register covers all incidents, not just those that trigger a notification requirement. If the Commission requests it, a copy must be provided. The exact contents and retention period are set by the Règlement sur les incidents de confidentialité. Check the current version before finalizing your template.

3. When to Notify the Commission and Individuals

The threshold is in the second paragraph of Section 3.5: the incident must pose a risk of serious harm. In that case, the organization must promptly notify the Commission d’accès à l’information, as well as every individual whose personal information is involved. If it fails to do so, the Commission can order it to comply.

Note the wording: ‘promptly.’ The law does not specify a number of hours or days. Don’t go looking for a 72-hour rule (it comes from the European framework and does not appear in Quebec’s legislation). In practice, it means without undue delay once you have enough information to assess the risk.

The organization may also notify any person or body that could help reduce the risk, sharing only the information needed for that purpose and without the individual’s consent. In that case, the person in charge must record the communication. One exception applies: an affected individual does not need to be notified if doing so could interfere with an investigation by a law enforcement body.

4. How to Assess Serious Harm

Section 3.7 identifies the factors to consider: the sensitivity of the information involved, the anticipated consequences of its use, and the likelihood it will be used for harmful purposes. The same section adds a procedural requirement: you must consult your privacy officer when conducting this assessment.

A straightforward framework to document in your register:

  • High sensitivity: social insurance numbers, driver’s license numbers, banking data, health information, biometric data, login credentials.
  • Anticipated consequences: identity theft, financial fraud, reputational damage, job loss, discrimination, harassment, humiliation.
  • Likelihood of harmful use: it increases if the data went to an unknown recipient, if the incident resulted from a malicious act, if the data was unencrypted, or if you can’t confirm the copy was destroyed. It decreases if the recipient is known and trusted, if the data was encrypted with a key that wasn’t compromised, or if recovery is confirmed in writing.

When in doubt, lean toward notifying. The law penalizes failing to report; it does not penalize reporting out of caution.

5. The First 48 Hours, in Practice

Hours 0 to 2. Contain. Cut off access, isolate the workstation or account, change compromised passwords, and turn on detailed logging if it wasn’t already active.

Hours 2 to 8. Determine. Who accessed what, when, how many people are affected, what categories of information were involved, and whether the data was encrypted. This step requires logs. Without logging, you can neither evaluate the situation nor demonstrate what happened.

Hours 8 to 24. Evaluate with your privacy officer, using the three factors in Section 3.7. Record the decision and the reasoning behind it, even if the conclusion is that there is no risk of serious harm.

Hours 24 to 48. Notify if the threshold is met. File a notice with the Commission and notify the individuals affected. Preserve the evidence, and do not overwrite disk images or purge logs.

Afterward. Fix the root cause, update your register, revise your policy, and train staff if the incident resulted from human error.

Network monitoring and logging that enables incident reconstruction

6. Logging: The Technical Factor That Determines Everything

When a small business experiences an incident, it faces three questions. What data left the organization. Where it went. How long it had been going on.

Without audit logs retained long enough, none of those questions can be answered. The result: you have to assume the worst and notify broadly, which costs far more in reputation and effort than the logging itself would have.

This is infrastructure work: office suite audit logs enabled and retained, firewall logs, file server access logs, endpoint detection alerts, and immutable backups that let you compare a before-and-after state. That’s exactly what our cybersecurity and backup services cover.

Frequently Asked Questions

Does a misaddressed email need to be reported?

Yes, it qualifies as a privacy incident under Section 3.6 and must be recorded in the register. Notifying the Commission and the individuals involved is only required if the incident poses a risk of serious harm, assessed using the three factors in Section 3.7.

Does Quebec’s Law 25 require notification within 72 hours?

No. That rule comes from the European framework. Quebec’s legislation requires notification ‘promptly’ when the serious harm threshold is met, meaning without undue delay once an assessment is possible.

Is ransomware that encrypts files without stealing them still an incident?

Yes. The loss of personal information or any breach of its protection falls within the definition. The incident must be recorded in the register and assessed like any other.

Preparing Before an Incident, with a Team from the Mauricie

The register and the procedure can be written in a few hours. The ability to answer the three questions that matter has to be built before an incident happens: retained logs, endpoint detection, and immutable, tested backups. Our managed IT services put that foundation in place for small businesses in Trois-Rivières and across Quebec. To prepare your incident response, reach out through our contact form or call 450-231-3836.

This guide simplifies legal obligations for general understanding. It is not legal advice and does not replace reading the actual legislation or consulting a legal professional. Legal references point to the Act Respecting the Protection of Personal Information in the Private Sector (CQLR, chapter P-39.1), as amended by Law 25.