Executive Summaries Nov 1, 2024

Obligation to Report Information Security Incidents: The Autorité des Marchés Financiers Catches the Wave and Publishes a New Regulation

On October 24, the Autorité des marchés financiers (“AMF”) published the Regulation respecting the management and reporting of information security incidents by certain financial institutions and by credit assessment agents (the “Regulation”), with provisions coming into force on April 23, 2025. 

This Regulation introduces a special notification regime in the event of an “information security incident”. This bulletin explains to whom this Regulation applies, the obligations it entails, and its scope, particularly in light of the existing obligations under the Act Respecting the Protection of Personal Information in the Private Sector (“Private Sector Act”) regarding notification in the event of a “confidentiality incident”. 

Organizations Covered by the Regulation 

The Regulation applies to the following organizations, which are already subject to the Private Sector Act: 

Information Security Incident Obligations 

As for the scope of the Regulation, it is important to understand the types of information it covers. An “information security incident” is defined in the Regulation as “an attack on the availability, integrity or confidentiality of information systems or the information they contain.” This definition is broad. Thus, a technical failure of information systems preventing access to these systems could constitute an “information security incident” subject to the Regulation. 

The definition of “information” in this Regulation has a broader scope than that of the Private Sector Act. In other words, an “information security incident” under the Regulation could encompass documents containing information such as a company’s financial information, product and service information, or reports and statistics, for instance; whereas a “confidentiality incident” under the Private Sector Act only involves documents containing personal information.  

Essentially, the obligations imposed on financial institutions and credit assessment agents under the Regulation are as follows: 

  • Establish and implement an information security incident management policy, including mechanisms to detect, assess, and respond to information security incidents.  
  • Appoint an officer or manager responsible for monitoring and supervising the management and reporting of information security incidents. 
  • Notify the AMF, via an online form, of information security incidents that are likely to have adverse impacts and those that have been the subject of a notice to a regulatory authority, such as the Commission d’accès à l’information, no later than 24 hours after the time an officer or manager is informed of the incident. In addition to the notice, necessary follow-ups must be made to the AMF every three days, and a final report must be submitted to the AMF no later than 30 days after the incident is contained.  
  • Maintain an information security incident register and retain entries for at least five years. 

Planned Penalties

The Regulation provides for monetary administrative penalties for any failure to comply with its obligations contained therein. 

 

Takeaways 

  • The Regulation adds a framework that supplements existing laws governing the protection of personal information. In other words, even if your organization already complies with the obligations under the Private Sector Act, it must still take action today to comply with the specific requirements of the Regulation. 
  • An information security incident as defined in the Regulation could also involve personal information. Thus, faced with the same incident, an organization may need to fulfill the obligations under both the Regulation and the Private Sector Act. 
  • Covered organizations must implement an information security incident management policy, including procedures and mechanisms to detect, assess, and address incidents. 
  • Organizations subject to the Regulation must also keep an information security incident register, which must include the date and time of the incident, its location, its nature, a detailed description, any injury caused, any third parties involved, actions taken by the organization, reasons for accepting or rejecting the risk, planned actions, and the incident close date. 
  • It should be noted that for an information security incident as defined in the Regulation, the notices to be sent to the AMF are more numerous than those to be sent to the Commission d’accès à l’information under the Private Sector Act in the event of a confidentiality incident. Indeed, in addition to the information security incident notice, the Regulation also provides for updates to be sent to the AMF, followed by the submission of a final report. 
  • Covered organizations must ensure that their contracts with service providers, particularly those who host their information systems on their behalf, contain a contractual clause requiring the service provider to notify the organization of any “information security incidents” affecting its information. In other words, the notification obligation imposed on service providers must cover both confidentiality incidents within the meaning of the Private Sector Act, and “information security incidents” within the meaning of the Regulation. 

For any questions or advice on implementing these practices, do not hesitate to contact BCF’s Data Protection, Privacy and Cybersecurity team. 

You would also like

Data-Privacy

Bill 82: One Step Closer to a National Digital Identity (and Modifications to Other Provisions!)

Entrepreneurship forum

Entrepreneurship Forum: Vision 2025

Athlete

Protecting Privacy in Sports – Don’t Wait to be Caught Flat-Footed!

Right to Data Portability: Is your Organization Ready?

Tech Forum 360

Tech 360 Forum: Growth and Inflection Points

Prospera: Québec’s Economic Barometer

Canada's Best Managed Companies: BCF Recognized for 17th Consecutive Year

paul et misha

BCF Strengthens its Expertise in Artificial Intelligence

new-partners-2024

BCF Has Appointed Three New Partners

Who’s Who Legal : 5 BCF Professionals Stand Out

BCF extends its Partnership with the Canadian Association of Black Lawyers to a Third Year

Demystifying Privacy Impact Assessments (PIAs)

The Data Processing Agreement: An Essential Resource to Implement

camera-on-a-wall

The Incident Response Plan: the Cornerstone of Effective Crisis Management

forum-privacy-en

Strategic Forum on Enterprise Data Protection

Chambers Canada Ranking: Five of our Lawyers Recognized

Photo of Julie Doré

Julie Doré Takes Over Management of The BCF Business Law Firm

Prospera – Quebec Economic Barometer

Julien Tricart, Member of the Meritas Sports Law Group

Pride Month: Let’s Create an Inclusive Future

Canada’s Best Managed Companies: BCF Recognized for 16th Consecutive Year

New Privacy Requirements: Is Your Business Compliant?

Every Woman Counts

Strategic Forum on the Role Played by Businesses in the Fight Against Climate Change

BCF Partners with the Canadian Association of Black Lawyers to Promote Diversity in Québec Law Faculties

BCF's More Inclusive Approach: Improved Parental Leave

Shaun E. Finn Appointed to the Superior Court of Québec

How to Ensure a Business Succession?

Business black folders on table

Adoption of Bill 78 on Transparency Business: Are You Ready?

Strategic Forum on Market Consolidation and Business Succession

BCF Partners with the Clinique Juridique de Saint-Michel to Promote Access to Legal Studies for Young People from Diverse Communities

What Are the Best Practices for Managing Privacy Incidents?

Shaun E. Finn, Co-Author of In the Public Eye: Privacy, Personal Information, and High Stakes Litigation in the Canadian Public Sector

Should Using Personal Information Obtained Without Consent Be Grounds for Class Action Authorization?

Five of our Lawyers Stand out in the 2023 Edition of the Chambers Canada Ranking

Cybersecurity and Privacy in Canada: What You Need to Know About Bill C-27

Is the Loss of Personal Information Sufficient to Justify the Success of a Class Action on the Merits?

Bill C-26: The Federal Government Takes a Closer Look at Cybersecurity and Privacy

Jocelyn Poirier, BCF’s Chief Privacy Officer

43 BCF Professionals Stand Out with 78 Nominations in the 2023 Editions of Best Lawyers in Canada and Ones to Watch

Seven New Lawyers Join BCF

Adoption of Bill 96: Be Ready

Pride Month: The Value of Diversity

BCF, the 3rd Largest Law Firm in Québec

Canada’s Best Managed Companies: BCF Recognized for 15th Consecutive Year

BCF Recognized by the Globe and Mail as one of Canada’s top Law Firms

Chambers Canada 2022: BCF Earned Band 1 Ranking in Québec for Corporate and Commercial Law

Seven New Lawyers Join BCF

Privacy and Data Protection Class Actions: Trends, Challenges and Best Practices

A First in Canada: Privacy Class Action Dismissed on the Merits

escalier

BCF Welcomes Seven New Lawyers

Collaboration in the Time of COVID-19: Legal Considerations for Successful AI and Healthcare Partnerships

Shaun E. Finn and Danielle Miller Olofsson Publish a Unique Practical Handbook on Privacy and Data-Protection Class Actions

What Are the Implications of the End of EU-U.S. Privacy Shield Framework for Your Business?

Investigation on Tim Hortons’ Application

Québec’s Bill 64 to Amend Data Protection Legislation: A Bill with Teeth?

Does the Use of Thermal Imaging Cameras in Stores Comply with Privacy Laws?

COVID-19: Solutions to Address this Situation

COVID-19: Finally a Toolbox for Developers of Geolocalisation Applications

Tracking the COVID-19 Pandemic with Cellphones

COVID-19: Don’t Forget Data Protection When Designing a Response Strategy

BCF once again ranks as one of Montreal's Top Employers

BCF Names 16 New Partners for Its 25th Anniversary

Joint Controllership or the Risks of using Website Plugins

Are You a Leader or a Follower?Results of the Innovation Survey

Chambers Canada 2020: BCF Recognised in Corporate and Commercial Law

Strategic Forum on Innovation

Different Legislative Approaches to 5G

Innovating to Survive: Are You a Leader or a Follower?

Is Your Company Implementing a New Technology System? Remember to Protect Your Data

5G Technology Is Coming: Legal Questions Abound

Legal Issues Surrounding the Industrial Revolution 4.0

Where Does Québec Stand in Terms of Privacy Class Actions?

De-fogging the Cloud Act

fenetres

Google and CNIL: a Case of Inappropriately Obtained Consent

Best Practices for Québec Companies Receiving European Data

Anonymization? Think Again

The Deep Web and Dark Web Demystified for Businesses

The GDPR is Coming: How to Get Ready

Protection of Personal Data: New Measures Put in Place by the European Union

Is Your Organisation Collecting Too Much Data and Is It Well Protected?

Get the latest thought leadership