Acceptance of Common Portions in a New Condo (GCR Quebec)
09/06/2026Volunteer Condo Work: CNESST and Insurance
10/06/2026Privacy Impact Assessment in Divided Co-Ownership (Bill 25): When and How
A privacy impact assessment (PIA) has become an essential reflex for every divided co-ownership syndicate. With Bill 25, personal information protection obligations also apply to syndicates, boards of directors and condominium managers. A PIA helps you anticipate the privacy impacts of a project and demonstrate that you exercised due diligence in the event of an inspection.
In practical terms, a PIA is a structured process that identifies the personal information affected, assesses the risks and proposes mitigation measures. The goal is to protect co-owners, occupants and employees (e.g., the caretaker) while complying with the law. As of 2026-06-10, Bill 25 requires a PIA when the use of personal information presents a high risk to privacy, particularly when new technologies are being adopted.
If you are preparing your first file, remember that the key word is “traceability.” Document what you do, why you do it and how you control it. Also record your decisions in the board of directors’ minutes and, where appropriate, inform the co-owners at the annual general meeting.
Good to know: for search engine optimization, the expression “privacy impact assessment for divided co-ownership under Bill 25” is equivalent to “PIA in divided co-ownership.”
When is a PIA mandatory in divided co-ownership?
In Quebec, Bill 25 amends the Act respecting the protection of personal information in the private sector and requires a PIA when the use or communication of personal information presents a high risk to privacy. This applies particularly to technological or organizational projects that change how data is collected, retained or accessed.
Typical triggers in a divided co-ownership context:
- Installing or upgrading cameras in the common portions (lobby, garage, elevators), an intercom or audio/video recording.
- Deploying or replacing an access control system (electronic keys, fobs, app-based recognition or biometric readers).
- Adopting an online portal or management software that stores data in the cloud, possibly outside Quebec.
- Implementing connected meters/sensors (EUC, water-leak sensors and electric vehicle charging stations) that generate logs linked to a condo.
- Starting a new collection of sensitive information (banking details for pre-authorized payments, identity documents, social insurance numbers or medical information for accommodation measures).
- Sharing data with a new service provider (security, concierge services, telecommunications or charging-station readings) or transferring it to another condominium manager.
- After a confidentiality incident (e.g., a document safe is stolen or unauthorized access to the registers occurs), in order to correct deficiencies.
Useful references:
- Act respecting the protection of personal information in the private sector (LégisQuébec, c. P-39.1) — principles and obligations: official text.
- Civil Code of Quebec — rules governing the syndicate and its registers (e.g., document retention and access): CCQ-1991.
- RGCQ — resources and training on co-ownership governance: rgcq.org/ressources.
How to conduct a PIA step by step
Conducting a PIA does not necessarily require a long, costly audit. For most syndicates, a rigorous framework and well-documented decisions are sufficient.
-
Define the project and its objectives
- Describe the context: the problem to be solved (e.g., intrusions), scope (buildings and common portions), timeline and budget.
- Identify the person responsible (the board of directors) and the person responsible for the protection of personal information (RPRP), who, under Bill 25, is by default the syndicate’s highest-ranking officer.
-
Map the personal information
- List the data categories: images, sounds, names, contact details, email addresses, fob logs, charging-station billing and banking information.
- Indicate the source (co-owners, tenants, visitors and employees), the private portions or common portions affected, and the sensitivity of the information.
-
Assess the privacy risks
- Risks of harm: unauthorized access, profiling, disclosure, loss and excessive retention.
- Probability x impact: consider the volume, sensitivity and ease of identification.
-
Determine mitigation measures
- Organizational measures: internal policies, access request procedures, incident management and board of directors training.
- Technical measures: encryption, logging, role-based access, masking, automatic deletion and storage in Quebec.
- Contractual measures: confidentiality clauses, subcontractors, server location, audit rights and incident notices.
-
Consult the stakeholders
- Involve the condominium manager, the service provider and, where necessary, legal counsel.
- Inform the co-owners when the use is visible or perceived as intrusive (e.g., new cameras). Include an information item at the annual general meeting.
-
Decide and approve
- The board of directors makes the decision, records the reasons in the minutes, assigns responsibilities and approves the timeline.
- If a rule of use needs to be established, prepare an update to the by-laws of the immovable and the DCV with legal advice.
-
Document and retain
- Keep the PIA, contracts, policies and proof of training in the syndicate’s registers.
- Prepare a brief information notice for occupants if cameras or sensors are added.
-
Review periodically
- Review the PIA when an upgrade or service provider change takes place, after an incident or at least every 2-3 years.
Recommended tools and templates
- Processing activity register (what, why, legal basis, retention period and recipients).
- Collection notice template for cameras in the common portions (including the RPRP and a means of contact).
- Simple risk matrix (low/medium/high) with objective criteria.
- Contract checklist for service providers (data location, subcontracting and deletion at the end of the mandate).
To structure your processes, see our administrative management services and our turnkey packages.
Who signs it and who keeps it?
The board of directors approves the PIA and mandates the RPRP to carry it out and follow up on it. The complete file (PIA, approval minutes, policies, incident log and proof of notices posted) is kept in the syndicate’s registers, with controlled access. Remember that the Civil Code governs access to the registers; provide excerpts as needed without disclosing more information than required.
What data is covered in a condo?
Here are common examples of data covered in a divided co-ownership setting:
- Register of co-owners and occupants, emergency contact details and intercom telephone numbers.
- Images/videos captured in the common portions, fob access logs and elevator histories.
- Payment information (e.g., condo fee withdrawals), insurance claims and loss reports.
- Human resources files for the maintenance employee or caretaker (contracts, availability and training).
- Data generated by the maintenance logbook/EUC, leak sensors, heating systems, electric vehicle charging stations and parking.
This information may seem harmless on its own, but it becomes sensitive when combined (e.g., images + access logs). The PIA helps limit collection, establish reasonable retention periods and restrict access to authorized persons only.
Governance and responsibilities under Bill 25
Bill 25 requires the syndicate to:
- Designate an RPRP (often the president of the board of directors by default) and publish that person’s contact information.
- Adopt policies governing personal information management and incident response.
- Inform people when information is collected, specify the purposes, limit retention and regulate communication outside Quebec.
- Maintain a register of confidentiality incidents and notify the CAI and the persons concerned when there is a risk of serious harm.
Consult the official text for detailed obligations and definitions: LégisQuébec — P-39.1. You can also follow sector news through the RGCQ and, for brokerage issues related to condo sales and forms, the OACIQ.
Integrating the PIA into the board of directors’ calendar
- Plan the PIA before issuing calls for tenders (cameras, access control and software). Include privacy criteria.
- Add a “privacy” item to the board of directors’ agenda and keep a summary of follow-up items in the minutes.
- Present a brief update at the annual general meeting: updated policies, incidents (if any) and preventive measures.
- Align your practices with the DCV, the by-laws of the immovable and maintenance procedures. For example, link video deletion to a maintenance cycle and record it in your calendar.
- Set aside a budget in the common expenses for compliance (signage, a secure storage safe for recordings and training). This differs from the contingency fund, which is intended for capital expenditures.
For more operational advice on divided co-ownership, consult our blog and our services page.
FAQ — PIA and divided co-ownership
Is a PIA required for cameras in the common portions?
Yes, in practice. Cameras involve the systematic collection of images. A PIA helps justify the installation and specify the angles, retention period, access and required signage. This due diligence is consistent with Bill 25 and reduces the risk of privacy breaches.
Must the annual general meeting approve the PIA?
No, approval falls to the board of directors, which manages day-to-day administration. However, if the project significantly affects the use of the common portions or requires revised by-laws of the immovable, inform the co-owners and, where necessary, submit the amendment to the meeting in accordance with the DCV and the Civil Code of Quebec. Document the decision in the minutes.
What should be done in the event of a confidentiality incident?
Isolate the cause, limit the spread, assess the risk of serious harm and record the incident in the register. If the risk is serious, notify the competent authority and the persons concerned. Conduct a corrective PIA to prevent a recurrence and update your policies.
This article provides general information and does not constitute legal advice. For your situation, consult a lawyer or notary.
Do you manage a divided co-ownership in Quebec? Discover our packages or contact us to assess your needs.
