Confidentiality incident notification and register
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 22 September 2022.
A breach notification rule binding private bodies.
As of 24 September 2026.
What it requires
- If you have cause to believe a confidentiality incident involving personal information you hold has occurred, take reasonable measures to reduce the risk of injury and prevent further incidents of the same nature.
- Where the incident presents a risk of serious injury, judged by the sensitivity of the information, the anticipated consequences and the likelihood of injurious use, promptly notify the Commission d’accès à l’information and each person whose personal information is concerned.
- Keep a register of every confidentiality incident, and send a copy to the Commission d’accès à l’information on request.
What it makes you log
Who may demand the log
Regulator
Logging duty
The register's content is left to a government regulation and is not itself specified in the Act.
- Kind
- Explicit
- As of
- 24 September 2026
- Provision
- CQLR c P-39.1, s. 3.8
- Trigger
- security_incident
Who checks it
Audit expectation
on_request
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A person carrying on an enterprise who has cause to believe that a confidentiality incident involving personal information the person holds has occurred must take reasonable measures to reduce the risk of injury and to prevent further incidents of the same nature. A confidentiality incident is access, use or communication of personal information not authorized by law, or the loss of personal information, or any other breach of its protection.
Where the incident presents a risk of serious injury, judged by the sensitivity of the information, the anticipated consequences and the likelihood of injurious use, the enterprise must promptly notify the Commission d’accès à l’information and each affected person, and must keep a register of confidentiality incidents, a copy of which must be sent to the Commission on request.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachprocesses_voiceprocesses_biometricsoperates_social_platformserves_minorsoperates_app_storeships_mobile_app
Read the law
official consolidated statute text, LégisQuébec (Éditeur officiel du Québec)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.