Emotional Support Animals in Quebec Condominiums
19/08/2026Bill 25: Access Logs and Access Control in Co-ownership
Building entry systems in a divided co-ownership (RFID keys, smart locks, intercoms, mobile applications) generate access logs. Under Bill 25, this data is considered personal information and must be managed rigorously. For a board of directors or a syndicate, properly regulating the collection, retention and access to these logs limits risks and strengthens co-owners’ trust.
Updated as of 2026-08-19, here is what you need to know to remain compliant and operational.
What Bill 25 requires for access logs
Bill 25 modernizes the rules governing the protection of personal information in Quebec. In particular, it amends the Act respecting the protection of personal information in the private sector (P-39.1). An access log that associates a chip, key fob or identifier with a person constitutes personal information. You must therefore:
- Define a clear and legitimate purpose (access control, security, limited internal investigations).
- Minimize collection (record what is necessary and nothing superfluous).
- Secure the data and restrict access to authorized persons.
- Set a proportionate retention period, then destroy or anonymize the data.
- Inform the individuals concerned and regulate suppliers that process this data.
Bill 25 also requires:
- Appointing a person responsible for the protection of personal information (often the board president by default, unless delegated) – see P-39.1.
- Applicable governance policies and practices that are published accessibly.
- A register of confidentiality incidents and, where necessary, notifications.
- A privacy impact assessment (PIA) for high-risk technology projects (e.g. biometrics), or when transferring data outside Quebec – see P-39.1.
Useful references:
- LégisQuébec – P-39.1 (Private sector): LégisQuébec
- LégisQuébec – Bill 25 (2021, c. 25): LégisQuébec
- LégisQuébec – C.C.Q. (syndicate register and documents, s. 1070): LégisQuébec
What to log… and how long to retain it
To achieve the purpose of “security and access control,” an appropriate log generally contains:
- Date and time (timestamp).
- Access point (door/elevator/garage).
- Technical identifier (chip/key/card number, not necessarily the person’s name in plain text).
- Result (access authorized/denied) and, where necessary, technical reason (e.g. deactivated key).
- Management events (issuing/revoking an identifier, repeated attempts).
Key minimization principles:
- Avoid recording the phone’s IP address or unnecessary metadata.
- Limit direct association with the person; favour a pseudonymized identifier in the system, with a separate, encrypted correspondence table.
- Do not continuously record audio/video through the intercom without clear justification and a properly regulated policy.
Recommended retention period (indicative and to be adapted according to the risk and life of the building):
- 12 months for routine access-control logs.
- Up to 24 months if the building is experiencing recurring issues (e.g. thefts, nuisance behaviour) and this is documented in an approved policy.
- Legal hold in the event of an investigation, loss or dispute: retain the data until the file is closed, then destroy it securely.
Do not set an “indefinite” retention period. Bill 25 requires destruction or anonymization once the purpose has been achieved. Document the method (automated purge, secure overwriting) in your governance practices.
Special cases: biometrics and cameras
- Biometrics (fingerprints, facial recognition): high risk. A PIA is required and use must be strictly necessary. Assess less intrusive solutions (chip) before using them.
- Access video surveillance: regulate the viewing angle, posting of notices, retention period (often shorter than for text logs) and restricted access to recordings.
Who may consult the logs and under what procedure
Access logs are not “public” documents for co-owners. Access and consultation must follow a procedure:
- Authorized persons: an appointed condominium manager, designated board member(s), concierge/security officer as needed. Access must be recorded in writing and limited to what is necessary.
- Suppliers: access regulated by contract (system maintenance). No reuse or unauthorized subcontracting.
- Police/authorities: upon a legitimate request. Keep a record of the disclosure.
Individual rights:
- A co-owner may request access to the personal information concerning them (P-39.1). Provide only their own data after verifying their identity. Avoid disclosing information about other people.
- The syndicate retains control of the logs. General requests by other co-owners to “see everything” must be refused, except for anonymized aggregates (e.g. number of entries per day) where relevant.
Governance:
- Put in place an access and request-response policy, adopted by the board of directors and communicated to co-owners. Mention it in the minutes and update it as needed.
- Harmonize the by-laws of the immovable and, where relevant, the declaration of co-ownership to reflect the existence of the access system and the rules governing its use.
For implementing these processes and maintaining documentation (policies, registers, response templates), see our administrative management service.
Technical security, hosting and suppliers
The security of access logs depends on technical and contractual controls:
- Role-based access controls (RBAC) and strong authentication for system users.
- Encryption of data at rest and in transit; immutable logging of access to the logs.
- Segmentation: separate the technical identifier ↔ person equivalence table; limit who can perform the “reconnection.”
- Consultation and export logs, with alerts in the event of unusual access.
- Hosting: favour Quebec or Canada. For any communication outside Quebec, conduct a privacy impact assessment and regulate it by contract (see P-39.1, transfer outside QC).
- Contractual clauses with the supplier: purposes, security measures, regulated subcontracting, assistance in the event of an incident, deletion and reversibility at the end of the contract.
Make sure the access-system installer holds a valid and appropriate contractor’s licence. Verify compliance on the RBQ website.
External resources:
- P-39.1 – private sector: LégisQuébec
- Bill 25 – 2021, c. 25: LégisQuébec
- C.C.Q., s. 1070 – syndicate register: LégisQuébec
- Good co-ownership practices: RGCQ
- Check a contractor: RBQ
Implementation in 7 steps for your board
-
Map data flows
Which access points? What data is collected? Who has access? Where is it hosted? What integrations are there (intercom, cameras, management software)? -
Define the purpose and minimize collection
Document what is necessary and remove anything superfluous. Pseudonymize identifiers as much as possible. -
Draft policies and procedures
Personal information protection policy (including access logs), procedure for responding to access requests, retention schedule and erasure method. -
Regulate suppliers
Contracts and security schedules (DPA), incident-notification obligations, reversibility. Verify server locations and subcontractors. -
Implement technical controls
RBAC, MFA, consultation logs, encryption, encrypted backups and automatic purges. -
Train and inform
Train the condominium manager, concierge and directors who consult the logs. Post a clear notice at access points and inform co-owners by communiqué. -
Approve and document
Adoption by the board of directors, information provided at the annual general meeting and mention in the minutes. Publish a summary of the practices on the building’s website or bulletin board. Review annually.
For template examples and frictionless implementation, see our management packages and our blog for other practical guides.
FAQ – Access Logs and Bill 25
Q1. Can a co-owner demand the complete list of entries into the building?
- No. They may request their own personal information (e.g. their passages associated with their chip) after their identity has been verified. Other people’s data must not be disclosed. Offer anonymized statistics where appropriate.
Q2. What retention period should be chosen for a building with no incidents?
- In practice, 12 months is often sufficient. Adapt it according to the risks and specify the rule in your policy. Then destroy or anonymize the data in a traceable manner.
Q3. Are cameras, video intercoms and mobile keys covered?
- Yes, if they make it possible to identify a person directly or indirectly. Regulate video streams and text logs separately; video retention is generally shorter.
This article provides general information and does not constitute legal advice. Consult a lawyer or notary for your situation.
Do you manage a co-ownership in Quebec? Discover our packages or contact us to assess your needs.
