Confidentiality incidents

A confidentiality incident is any unauthorized access to, use of or disclosure of personal information, its loss, or any other breach of its protection (s. 3.5 to 3.8).

Examples: a public S3 bucket holding customer files; a stolen unencrypted laptop; ransomware; an email sent to the wrong recipient; an API key exposed in a public repository.

Your responsibilities

  1. Detect: DLP alerts, anomaly detection (SIEM), monitoring of unusual access.
  2. Contain: revoke access, isolate, preserve evidence.
  3. Escalate immediately to the RPRP and security: the RPRP assesses the risk of serious injury.
  4. Document: timeline, systems, data and people affected.

If the risk of serious injury is confirmed, the organization must notify the CAI and the individuals promptly. In all cases the incident is entered in the register (kept 5 years).

Register template (excerpt)

Field Example
Date of discovery 2026-03-04
Circumstances Backup bucket accidentally made public
Information concerned Emails, names (200 people)
Measures taken Access closed, keys rotated, configuration review
Risk of serious injury? Assessed by the RPRP
Notice to CAI / individuals Date and means

Good practice: an internal SLA of at most 4 h between detection and alerting the RPRP. This is not a legal deadline.

Detailed legal framework: see the reference guide — Confidentiality incident management.