Confidentiality incidents
A confidentiality incident is any unauthorized access to, use of or disclosure of personal information, its loss, or any other breach of its protection (s. 3.5 to 3.8).
Examples: a public S3 bucket holding customer files; a stolen unencrypted laptop; ransomware; an email sent to the wrong recipient; an API key exposed in a public repository.
Your responsibilities
- Detect: DLP alerts, anomaly detection (SIEM), monitoring of unusual access.
- Contain: revoke access, isolate, preserve evidence.
- Escalate immediately to the RPRP and security: the RPRP assesses the risk of serious injury.
- Document: timeline, systems, data and people affected.
If the risk of serious injury is confirmed, the organization must notify the CAI and the individuals promptly. In all cases the incident is entered in the register (kept 5 years).
Register template (excerpt)
| Field | Example |
|---|---|
| Date of discovery | 2026-03-04 |
| Circumstances | Backup bucket accidentally made public |
| Information concerned | Emails, names (200 people) |
| Measures taken | Access closed, keys rotated, configuration review |
| Risk of serious injury? | Assessed by the RPRP |
| Notice to CAI / individuals | Date and means |
Good practice: an internal SLA of at most 4 h between detection and alerting the RPRP. This is not a legal deadline.
Detailed legal framework: see the reference guide — Confidentiality incident management.