Skip to content
Ringfully

Blog

Law 25 and a breach involving call records

Law 25 asks you to register every confidentiality incident, and to notify the CAI and the people affected when one presents a risk of serious injury.

John · Owner and CEO · 3 min read · · updated

Under Law 25 you must record every confidentiality incident in a register, and notify the Commission d'accès à l'information and the people affected whenever the incident presents a risk of serious injury. Both duties apply to call recordings, voicemail and call logs exactly as they do to a database.

The register is the part people miss. It covers every incident, not only the ones serious enough to report, and it is one of the obligations Law 25 places on a Quebec business.

What counts as an incident

An incident is unauthorized access, use or communication of personal information, or its loss, including any other breach of protection. For a phone system, the realistic list is shorter and more ordinary than a headline breach:

  • a voicemail box reachable by someone who left the company
  • a recording emailed to the wrong address
  • a call log exported and left in shared storage
  • a softphone still signed in on a returned laptop
  • an agent listening to recordings they had no reason to hear

That last one is worth sitting with. Unauthorized use is an incident even when nothing left the building and no attacker was involved.

Two duties, not one

The register applies to every incident; notification applies only to the ones that present a risk of serious injury.

Flow diagram: every incident goes in the register, and only a risk of serious injury adds notice to the CAI

The register applies to every incident. Notice to the Commission and to the people affected is owed only where the incident presents a risk of serious injury.

Reuse this figure anywhere, including commercially, with credit to Ringfully and a link back to this page. CC BY 4.0.

The register applies always

Every incident goes in, regardless of severity. It records what happened, when, what information was involved, and what you did. It is the artifact a regulator asks for first, and it cannot be reconstructed after the fact.

Notification applies conditionally

Notification is owed when the incident presents a risk of serious injury. That judgement weighs the sensitivity of the information, how it might be used, and the likelihood of harm. Where the risk exists, you notify both the CAI and the individuals concerned, promptly, on the Commission's incident declaration form (PDF). The Commission publishes its own guidance for private businesses on confidentiality incidents and security measures, which is the authority to read before your own policy.

A recording is unusually sensitive here. It carries a voice, and often information the caller volunteered without thinking: a health detail, a financial figure, a home address said aloud to be helpful.

What to have ready before you need it

  • Know where recordings can be retrieved from, including exports someone made months ago
  • Know who has replay permission and be able to reduce it quickly
  • Know your retention, because information you no longer hold cannot be part of an incident
  • Have the register already exist. Creating one during an incident is how details get lost

Retention deserves the emphasis. The cheapest incident response is not holding the recording at all. Deleting on a schedule shrinks the surface permanently, and it is a configuration decision rather than a project.

Where Ringfully is

Ringfully deletes recordings on a schedule. An administrator sets a retention window per class of data, and an organization that has set nothing runs on the platform defaults: 30 days for recordings, 90 for voicemail. A job runs nightly and removes whatever has passed its window, so shortening a window deletes audio on the next run and there is no archive behind it. A single recording can also be deleted before its window ends, under a permission of its own rather than one every agent holds.

Recording is off by default, replay is permission-gated, and our recording policy states what the product does and does not do. What we cannot give you is a register: that one is yours, because the incidents it records are yours. What we hold and what we do not is listed on security.

A description of what the statute asks, not legal advice. Whether an incident presents a risk of serious injury is a judgement to make with a Quebec-qualified adviser, and quickly. Related: what Law 25 asks of a phone system.

Questions people ask

What counts as a confidentiality incident under Law 25?
Unauthorized access to, use of or communication of personal information, its loss, or any other breach of its protection. On a phone line that includes a voicemail box still reachable by someone who left, a recording emailed to the wrong address, or a call log exported and left in shared storage. Unauthorized use counts even when nothing left the building and no attacker was involved.
Do I have to report every confidentiality incident to the Commission d'accès à l'information?
No. You notify the Commission and the people affected only when the incident presents a risk of serious injury, weighing the sensitivity of the information, how it could be used and the likelihood of harm. Every incident goes in your register regardless, including the ones that present no such risk.
How long do I have to keep the register of confidentiality incidents?
At least five years from the date, or the period, on which your business became aware of the incident. The Commission can ask you for a copy of the register, so it has to already exist rather than be assembled once something has gone wrong.
Is a call recording sent to the wrong person a confidentiality incident?
Yes. It is an unauthorized communication of personal information, and it goes in the register. Whether you also have to notify depends on whether it presents a risk of serious injury, and a recording weighs heavily there: it carries a voice, and often something the caller volunteered without thinking.
Is my phone provider responsible if my call records are breached?
Not in your place. A business stays responsible for its own Law 25 obligations even when a third party holds the information for it: the measures to take, the register to keep, the notices to send. A provider can make all three cheaper to discharge, and cannot discharge them for you.

About the author

John

Owner and CEO

Owner and CEO with over 10 years of experience in the IT industry, including more than 5 years specializing in VoIP and cloud communications. Experienced in designing, deploying, and supporting reliable communication solutions for businesses.

More from John

If you are working out what Law 25 or Law 96 asks of your phone line, tell us what you record and who you serve, and we will say what we handle and what stays your job.

More in Law 25 and Law 96 · All posts