Construction Legal Hypothec in Quebec Condominiums
19/07/2026Converting a Common Portion into a Private Portion in Quebec
20/07/2026Privacy Activity Register (Bill 25) for Divided Co-ownership
Bill 25 requires syndicates of divided co-ownership to document how personal information is collected, used, communicated and retained. The privacy activity register therefore becomes a central tool for your board of directors, condominium managers and suppliers. This article, current as of 2026-07-19, provides a practical template adapted to the realities of a divided co-ownership in Quebec (the Greater Montreal area), along with practical advice for implementing it effectively.
Beyond compliance, a clear register reassures co-owners, reduces risks in the event of a confidentiality incident and makes follow-ups easier during the annual general meeting and internal audits. You will gain greater transparency and administrative efficiency.
What is a privacy activity register?
The privacy activity register lists, for each process involving personal information, the purposes, categories of information, people with access, recipients, security measures and retention periods. Bill 25 modernizes Quebec’s legislation on the protection of personal information in the private sector and requires more formal governance, including maintaining such a register.
- The syndicate must designate a person responsible for the protection of personal information (PRPPI). Often, a board member takes on this role and may delegate operational duties to the condominium manager.
- The register covers co-owners as well as occupants, suppliers, syndicate employees (if applicable) and visitors when cameras or an intercom system are involved.
- The obligation to document is based on sector-specific personal information legislation; references to the Civil Code of Quebec (C.C.Q.) also apply to the diligent management of the syndicate’s documents and respect for civil rights.
For official references, consult LégisQuébec for the legislation on personal information in the private sector and the C.C.Q. (see the links at the bottom of the article).
What activities should be documented in a divided co-ownership?
Your register must reflect your syndicate’s actual operations, in accordance with the declaration of co-ownership and the by-laws of the immovable. In practice, it will generally include:
- Maintaining the co-owner register: contact information, co-ownership shares, the status of common expenses/condo fees, units and parking spaces.
- Collecting common expenses and contingency fund contributions: billing information, payments, arrears follow-ups and formal demands.
- Managing meetings (annual general meetings and special meetings): attendance lists, proxies, votes, recording quorum and distributing the minutes.
- Contracts and suppliers: contractors’ contact information, certificates and banking information, as well as Regie du batiment du Quebec (RBQ) compliance where relevant.
- Security and access: keys, access cards, intercom, cameras in common portions, and incident and claim records.
- Managing requests: work in private portions, renovations, pets, noise, complaints, and room or pool reservations.
- Sale of a condo: syndicate certificate, financial statements, statement of condition/maintenance logbook, and correspondence with notaries and brokers.
Each activity should be listed once, with its essential information. Avoid duplicates, but separate different activities (for example, “annual general meeting and proxies” versus “distribution of the minutes”) if their purposes and retention periods differ.
Register template: essential columns and examples
Use a simple table format (spreadsheet or document management tool). The following columns are recommended for a syndicate:
- Processing activity
- Purpose (objective)
- Categories of personal information
- Legal basis (for example, consent, performance of a legal or contractual obligation)
- Individuals concerned (co-owners, occupants, suppliers, visitors)
- Internal access (board of directors, condominium manager, caretaker)
- External recipients (for example, accountant, notary, bank)
- Transfer outside Quebec (yes/no, specify if applicable)
- Security measures (technical/organizational)
- Storage location (server, cloud, locked filing cabinet)
- Retention period and archiving/destruction criteria
- Privacy impact assessment (PIA) required? (yes/no)
- Person responsible and date last updated
Example format using three common activities:
| Activity | Purpose | Categories | Legal basis | Access | Recipients | Retention | Security |
|---|---|---|---|---|---|---|---|
| Co-owner register | Keeping contact information and co-ownership shares up to date, sending official notices | Name, address, email, telephone, unit | Legal obligation of the syndicate; performance of obligations under the declaration of co-ownership | Board of directors, condominium manager | In person/by mail; sometimes a notary during a sale | 7 years after the sale, then anonymization | File encryption; access rights; backups |
| Collection of assessments | Billing, arrears follow-up, financial statements | Contact information, partially masked payment information, balance | Performance of legal/contractual obligations | Condominium manager, treasurer | External accountant; financial institution | 7 years (accounting documents) | 2FA, access log, confidentiality agreements |
| Annual general meeting and proxies | Proof of quorum, voting rights, minutes | Name, unit, signature, email address | Legal obligation (holding an annual general meeting), consent for electronic distribution | Board of directors, condominium manager | Notary when needed; virtual meeting platform | Minutes: permanently; supporting documents: 3 years | Locked room; digital vault; restricted sharing |
Minimal template to copy and paste
- Activity:
- Purpose:
- Individuals concerned:
- Categories of personal information:
- Legal basis:
- Authorized internal access:
- External recipients:
- Transfer outside Quebec (yes/no; specify):
- Security measures:
- Storage location:
- Retention period and destruction criteria:
- PIA required (yes/no):
- Person responsible and update date:
Roles and responsibilities: board of directors, condominium manager and PRPPI
- The board of directors adopts a personal information governance policy and formally designates the PRPPI. This policy may be appended to the by-laws of the immovable to establish rules for accessing documents and distributing information (for example, masking sensitive data in the minutes sent to co-owners).
- The condominium manager supports the maintenance of the register, implementation of security measures and training. The manager must also ensure that subcontractors sign confidentiality commitments and that the platforms used comply with applicable standards.
- The PRPPI oversees ongoing updates, risk analysis (for example, a PIA for video surveillance in common portions) and responses to access/correction requests from individuals concerned.
Local best practices:
- Align the register with your tools: common expenses accounting, document management (statement of condition/maintenance logbook), co-owner portal and intercom system.
- Review the register before the annual general meeting to inform co-owners about significant changes and resolved incidents.
- Specify in the declaration of co-ownership or the by-laws of the immovable the authorized distribution channels (email, portal), in accordance with Bill 25.
To learn how administrative support can structure these tasks, see multiRent’s administrative management services: https://www.multirent.ca/services/#gestion-administrative
Retention, security and incident management
Bill 25 requires rigorous management of the information life cycle:
- Retention periods: set reasonable periods based on the purpose and accounting requirements. For example, retain supporting documents related to assessments for at least 7 years; minutes of the annual general meeting are archived permanently.
- Security: apply the principle of least privilege, multifactor authentication and encryption at rest/in transit, and keep an access log. Paper files must remain locked up.
- Confidentiality incidents: in the event of unauthorized access, loss or disclosure, assess the risk of serious harm. Document the incident, notify affected individuals and, when required by Bill 25, send notice to the competent authority. Keep an incident register.
- Suppliers: verify where data is hosted, any potential subcontractors and the contractual guarantees. Avoid transfers outside Quebec without appropriate analysis and clauses.
Integrate these rules into your regular procedures (for example, providing a co-owner information package, changing condominium managers and ending a director’s mandate) to limit oversights.
Getting started in 30 days: a realistic action plan
Week 1
- Designate the PRPPI and approve a register template.
- Conduct a quick inventory of systems and documents: accounting, co-owner lists, cameras, intercom and platforms used for the annual general meeting.
Week 2
- Complete the register for 5 to 8 critical activities (co-owner register, collection of assessments, annual general meeting/proxies, supplier contracts, incidents/claims and cameras, if applicable).
- Identify gaps: missing retention periods, overly broad access, lack of encryption or 2FA.
Week 3
- Update procedures and templates (proxies, notices of meeting, work request forms and supplier confidentiality clauses).
- Prepare a short privacy notice to publish on the syndicate’s website/portal and attach to major electronic communications.
Week 4
- Train the board of directors and condominium manager on the new practices, and document the training.
- Adopt the governance policy, place the register in the syndicate’s file and schedule a quarterly review.
To track developments and centralize documentation, consult the multiRent blog: https://www.multirent.ca/blogue/
Quick FAQ
Q: Does the register have to be sent to every co-owner?
A: No. It must be kept available and presented when necessary (for example, for a review, incident or formal request). However, you may share a summary at the annual general meeting to provide information about the measures in place.
Q: Is a PIA mandatory for installing cameras in common portions?
A: A privacy impact assessment is recommended and may be required depending on the risk. It documents the necessity, proportionality, location, retention period and safeguards.
Q: Can the minutes of the annual general meeting be emailed to all co-owners?
A: Yes, if the declaration of co-ownership or a resolution authorizes it and adequate security measures are in place. Avoid including unnecessary personal information; favour access through a secure portal.
Useful sources
- LégisQuébec – Act respecting the protection of personal information in the private sector (P-39.1)
- LégisQuébec – Civil Code of Quebec (CCQ-1991)
- RGCQ – Resources for co-ownership syndicates
- OACIQ – Official website for real estate brokerage in Quebec
This article provides general information and does not constitute legal advice. Consult a lawyer or notary regarding your situation.
Do you manage a divided co-ownership in Quebec? Discover our packages or contact us to assess your needs.
