Montreal Condo Energy Disclosure 21‑042
25/07/2026Condo Water Stack Replacement: Costs and Steps
25/07/2026Bill 25 and Co-Ownership Supplier Contracts: Key Clauses
Bill 25 modernized the protection of personal information in Quebec. For a divided co-ownership syndicate, the issue is very concrete: your supplier contracts must clearly govern the use of co-owners’, tenants’ and visitors’ data. Without these clauses, the board of directors (board) faces legal, operational and reputational risks.
In this article, we summarize what Bill 25 means for your agreements with suppliers (management, accounting, security, IT, resident platforms, etc.). You will find the clauses to include, best practices for calls for tenders, and governance advice to record in the minutes of your board meetings and present at the annual general meeting.
Understanding Bill 25 for a divided co-ownership syndicate
Bill 25 amended the Act respecting the protection of personal information in the private sector (chapter P-39.1). It imposes governance, security and incident notification obligations on organizations that process personal information. Your suppliers, which “process information on behalf” of the syndicate, are directly covered by these obligations and must be governed in writing.
Even if a syndicate is not always considered an “enterprise” in the strict sense, it must act prudently and honestly in performing its obligations (see the Civil Code of Quebec). The board remains responsible for protecting information entrusted to third parties. This is why supplier contracts must incorporate the requirements of Bill 25 and reflect the best practices recommended in the co-ownership sector.
In practice, this means:
- Designating a person responsible for the protection of personal information for the syndicate (often a director or the condominium manager, depending on the mandate);
- Policies and practices governing data management and confidentiality incidents;
- Written contracts imposing confidentiality, security, incident notification and data deletion obligations on the supplier at the end of the mandate (see P-39.1, particularly sections 3.1, 17 and 18.3).
For reference, consult the consolidated Private Sector Act and the modernization legislation:
- LégisQuébec – Act respecting the protection of personal information in the private sector (P-39.1)
- LégisQuébec – Act to modernize legislative provisions as regards the protection of personal information (2021, c. 25)
Mapping personal information in a condo: a useful prerequisite
Before negotiating your clauses, make an inventory of the data your suppliers access, host or handle. This simple exercise helps determine the required level of protection.
Personal information frequently involved in divided co-ownership:
- Identity and contact information: name, email address, telephone number, address of private portions and billing address;
- Financial information: statements of account, condo fee withdrawals, proof of payment, arrears of common expenses and special assessments;
- Administrative records: syndicate register, attendance lists for the annual general meeting, proxies, minutes, insurance claims;
- Security and access: camera recordings of common portions, access logs, licence plate numbers, intercom logs;
- Technical information: maintenance requests, work orders, information related to the maintenance logbook (EUC) and the contingency fund;
- Sales and rentals: syndicate certificates, communications with notaries and brokers, and proof of co-owners’ insurance.
This mapping helps you specify, in each contract, the categories of information concerned, the authorized purposes and the expected protection measures.
Mandatory clauses to include in your contracts
Include these key clauses in all your supplier contracts. Adapt the wording according to the type of service (management, IT, security, accounting, platform).
- Purpose, scope and definitions
Specify that the supplier processes personal information “on behalf” of the syndicate, solely for the purposes of the mandate. Define “personal information” and “confidentiality incident” in accordance with Bill 25. - Confidentiality and minimum access
Limit access to authorized individuals at the supplier only, on a need-to-know basis. Require confidentiality agreements and background checks where appropriate. - Security measures
Require technical and organizational measures proportionate to the risks: access controls, logging, encryption in transit, backups, security patches and password management. Specify how mobile devices and IT subcontracting will be managed. - Incident register and notification
Require the supplier to maintain a confidentiality incident register and notify the syndicate “without undue delay” of any incident presenting a serious risk of harm, with the details needed for assessment and mitigation. - Retention, return and deletion
Define retention periods. Require secure return or verifiable deletion (including copies and backups) at the end of the contract, supported by written confirmation. - Subcontracting and “flow-down”
Prohibit any subcontracting without prior written authorization. Impose on subcontractors obligations at least equivalent to those in the main contract. - Hosting and transfers outside Quebec
Require the supplier to disclose the hosting location. For any transfer outside Quebec, require a privacy impact assessment and adequate contractual safeguards, in accordance with P-39.1, section 17. - Audit rights and attestations
Provide for a reasonable right of audit by the syndicate or an independent auditor. Require periodic compliance attestations and disclosure of relevant major findings from third-party audits. - Assistance with requests from individuals
Require the supplier to cooperate with requests for access, rectification or withdrawal of consent concerning the data it holds on behalf of the syndicate. - Data ownership and portability
Specify that the data belongs to the syndicate. Require a complete, readable export at the end of the contract, without unreasonable fees.
Incident management and notification: what to provide for in practice
Your contract should govern the following sequence in the event of a confidentiality incident:
- Prompt notice to the syndicate, with a description of the facts, the categories of information affected and the immediate measures taken;
- Cooperation in assessing the “risk of serious harm” and, where necessary, preparing notices to affected individuals and taking the steps required by law;
- Delivery of an updated incident report, followed by a closing report outlining the corrective measures implemented and the lessons learned.
Also specify who, at the supplier and on your side, acts as the person responsible for the protection of personal information to speed up coordination.
Transfers outside Quebec and hosting: avoid blind spots
If a supplier hosts data in the cloud or employs staff outside Quebec, the contract should provide for:
- A privacy impact assessment before the transfer (see P-39.1, section 17);
- Contractual safeguards ensuring equivalent protection (confidentiality, security, audit rights and deletion);
- Disclosure of the jurisdictions involved and the remedies available.
Tip: require a technical data sheet describing the architecture (data centres, backups and logging) and update it annually.
Calls for tenders, verifications and supplier monitoring
Oversight starts with the call for tenders. Here is a simple process for a board:
- Tender documents: include specifications setting out your Bill 25 requirements and a model set of contractual clauses. Identify the categories of information involved (for example, co-owner register, statements of account and videos of common portions).
- Due diligence: request proof of liability insurance, the security policy, the incident response plan and hosting locations. For building work, verify the contractor’s licence with the RBQ.
- Evaluation criteria: give information security the same weight as price and service. Request references and require a demonstration of access controls and backups.
- Negotiation and signing: incorporate your Bill 25 clauses, establish a testing schedule (backup restoration and data export), and set relevant service-level indicators (SLAs).
- Annual monitoring: obtain a compliance attestation, review the hosting data sheet, and hold a meeting to review incidents and improvements.
Good to know: the RGCQ publishes useful content on best practices in divided co-ownership. Use it as a guide to structure your file and internal communications.
Board governance: policies, minutes and key documents
A good contract is not enough without internal governance. We recommend that the board:
- Officially designate, by resolution recorded in the minutes, the person responsible for the protection of personal information;
- Adopt a policy governing the management of personal information and an incident response process;
- Update the by-laws of the immovable or, if necessary, the declaration of co-ownership to clarify certain obligations regarding access, display and use of devices (cameras in common portions and intercom);
- Document in the maintenance logbook (EUC) the critical systems and suppliers that handle data (management platform, servers and cameras), along with the frequency of security reviews;
- Inform co-owners, no later than at the annual general meeting, of the improvements implemented, without disclosing sensitive information.
Also consider coordinating this with financial management: an accounting or payment-processing supplier handles banking data and information about condo fees. Review these contracts and the separation of duties periodically (for example, payment approval and access to logs).
To learn more, consult our administrative management services and browse other practical articles on the multiRent blog.
This article provides general information and does not constitute legal advice. For your situation, consult a lawyer or notary.
Do you manage a divided co-ownership in Quebec? Discover our packages or contact us to assess your needs.
