Insights · Jun 12, 2026 · 5 min read
Law 25: the registers most practices are missing
When the Commission d'accès à l'information asks a firm for its incident register, the honest answer in many offices is a pause. Everyone remembers the consent banners. Fewer remember that Law 25 made record-keeping itself an obligation.
The register you must be able to produce
Every enterprise, whatever its size, must keep a register of confidentiality incidents and provide a copy to the Commission on request. The Commission's guidance is specific about what an entry contains:
- a description of the personal information involved, or the reason it cannot be identified;
- the circumstances of the incident, and its date or period, even approximate;
- the date or period when the enterprise became aware of it;
- the number of persons concerned, even approximate;
- the assessment of the risk of serious injury: sensitivity of the information, possible malicious uses, foreseeable consequences, likelihood;
- where the risk was serious, the dates of notification to the Commission and to the persons concerned;
- the measures taken to reduce the risk.
Entries are kept for a minimum of five years after the enterprise becomes aware of the incident. When an incident presents a risk of serious injury, the enterprise notifies the Commission and the persons concerned without delay, using the Commission's official form.
The registers around the register
The incident register rarely travels alone. The same reform expects a designated person responsible for the protection of personal information, published governance policies and practices, and privacy impact assessments when acquiring or overhauling systems that touch personal information. A practice adopting AI tooling meets that last one immediately: the assessment is the natural place to write down what a tool may read, where its data physically sits, and who verifies its output.
One more provision matters for AI specifically. When a decision about a person is based exclusively on automated processing, the person must be informed. The cleanest way to never trip on that rule is the discipline worth adopting anyway: no decision leaves the office without a human who read it.
A checklist you can run this week
- Name the person responsible for the protection of personal information, in writing.
- Create the incident register today, even empty. An empty register is compliance. A missing one is exposure.
- List the systems that hold personal information, and where the data physically sits.
- Write the two-paragraph procedure: who assesses an incident, who calls the Commission.
- Put a human checkpoint on any automated output that touches a person's file.
Monetary penalties give the exercise its edge, since the reform armed the Commission with administrative sanctions that reach into the millions. But the quieter argument is the better one. These registers are what being in control of your files looks like, written down.
Book your Orée diagnostic
One call to confirm the scope. Three days given to your organization — on site or remotely, whichever suits you best. An honest picture of what slows the work down, whether or not you continue with us.