Skip to content
Ringfully

Blog

A breach involving call records: what Law 25 asks you to do

Quebec's Law 25 requires you to keep a register of every confidentiality incident, and to notify the CAI and affected people when one presents a risk of serious injury.

August 19, 2026

Under Law 25 you must record every confidentiality incident in a register, and notify the Commission d'accès à l'information and the people affected whenever the incident presents a risk of serious injury. Both duties apply to call recordings, voicemail and call logs exactly as they do to a database.

The register is the part people miss. It covers every incident — not only the ones serious enough to report.

What counts as an incident

An incident is unauthorised access, use or communication of personal information, or its loss — including any other breach of protection. For a phone system, the realistic list is shorter and more ordinary than a headline breach:

  • a voicemail box reachable by someone who left the company
  • a recording emailed to the wrong address
  • a call log exported and left in shared storage
  • a softphone still signed in on a returned laptop
  • an agent listening to recordings they had no reason to hear

That last one is worth sitting with. Unauthorised use is an incident even when nothing left the building and no attacker was involved.

Two duties, not one

The register applies always. Every incident goes in, regardless of severity. It records what happened, when, what information was involved, and what you did. It is the artefact a regulator asks for first, and it cannot be reconstructed after the fact.

Notification applies conditionally — when the incident presents a risk of serious injury. That judgement weighs the sensitivity of the information, how it might be used, and the likelihood of harm. Where the risk exists, you notify both the CAI and the individuals concerned, promptly. The Commission publishes its own guidance for private businesses on confidentiality incidents and security measures, which is the authority to read before your own policy.

A recording is unusually sensitive here. It carries a voice, and often information the caller volunteered without thinking — a health detail, a financial figure, a home address said aloud to be helpful.

What to have ready before you need it

  • Know where recordings can be retrieved from, including exports someone made months ago
  • Know who has replay permission and be able to reduce it quickly
  • Know your retention, because information you no longer hold cannot be part of an incident
  • Have the register already exist. Creating one during an incident is how details get lost

Retention deserves the emphasis. The cheapest incident response is not holding the recording at all — deleting on a schedule shrinks the surface permanently, and it is a configuration decision rather than a project.

Where Ringfully is

Ringfully has no automated retention lifecycle for call recordings yet. Nothing expires them on a schedule; a recording persists until it is removed. That is a genuine gap, and it is the kind that grows quietly, because storage costs nothing to ignore.

Recording is off by default, replay is permission-gated, and our recording policy states what the product does and does not do. What we cannot give you is a register — that one is yours, because the incidents it records are yours.

A description of what the statute asks, not legal advice. Whether an incident presents a risk of serious injury is a judgement to make with a Quebec-qualified adviser, and quickly. Related: what Law 25 asks of a phone system.