Death of a Co-owner in a Quebec Co-ownership
02/06/2026GCR New Condo Pre-Delivery Inspection: Deficiency Checklist
03/06/2026Privacy Officer for a Divided Co-ownership (Bill 25)
Bill 25 imposes clear rules on private organizations in Quebec for managing personal information. In divided co-ownership, the syndicate and board of directors manage extensive data: co-owners’ contact information, unit numbers, assessment notices, insurance claim files, cameras, intercom systems, and more. This is why it is important to officially appoint the person responsible for personal information and document your practices.
The search term “condo privacy officer Bill 25” refers, in practical terms, to the person appointed by your board of directors to apply Bill 25, coordinate policies and respond to privacy-related requests.
In this article, you will learn who is covered, how to appoint this person, what they must do on a daily basis and the minimum tools to put in place so your syndicate remains compliant and protects co-owners’ data.
Who is covered by Bill 25 in divided co-ownership?
- Bill 25 modernizes the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1). It applies to organizations that collect, hold or communicate personal information in the course of operating a business.
- In practice, syndicates administer a building, hire suppliers and process personal information. They must therefore comply with key obligations: appointing a person responsible, adopting policies, maintaining an incident register and ensuring transparency (see sections 3.1, 3.2 and 3.5 to 3.8 of Act P-39.1 on LégisQuébec).
- If no person is appointed, the law provides that the person with the highest authority within the organization—often the board president—automatically assumes this role, with the option of written delegation (section 3.1 of P-39.1).
For more context on how these rules apply in a condo setting, also see the RGCQ resources and the legal framework updated by Bill 25 (S.Q. 2021, c. 25).
How do you appoint the person responsible for personal information?
- Formal board decision: adopt a resolution appointing the person (a director, external condominium manager or other mandatary). Record the decision in the board of directors’ minutes, then inform the co-owners at the next annual general meeting.
- Written delegation: if the person with the highest authority does not directly assume the role, record a named and dated delegation specifying the scope of the functions (section 3.1 of P-39.1).
- Public contact information: if the co-ownership has a website, publish the person’s title and professional contact information (section 3.2 of P-39.1). Otherwise, make sure the information appears in an accessible communication, such as a posted notice or email sent to the co-owners.
- Ongoing updates: when the person responsible changes, redo the resolution, update the policy and notify your partners (management, concierge services, security and accounting).
Practical tip: attach the appointment to the by-laws of the immovable or the co-owner welcome manual to make reminders and transitions within the board of directors easier.
Key day-to-day responsibilities of the privacy officer
The person responsible for personal information is not alone in “doing everything,” but they lead and coordinate the work. Here are the essential areas to cover.
- Document governance
- Establish and keep up to date a privacy policy adapted to the co-ownership.
- Define guidelines for retaining and securely destroying records, both digital and paper.
- Determine who has access to what (common portions versus sensitive files, such as insurance claims, insurance claims files and complaints).
- Requests from individuals
- Respond to co-owners’ requests for access to or correction of their information within the reasonable time limits provided by law.
- Record requests and responses for traceability.
- Privacy incident register
- Document every incident involving personal information, assess the risk of serious harm and determine which notices are required (sections 3.5 to 3.8 of P-39.1 on LégisQuébec).
- Supplier management
- Verify that contracts for management, security, IT, cameras, intercom systems and accounting platforms contain compliant confidentiality clauses.
- Limit access to what is strictly necessary for the mandate and provide for the return or deletion of data at the end of the contract.
- Awareness for the board of directors and volunteers
- Review good practices: passwords, minimal sharing, secure delivery of minutes and financial statements, and caution with email lists.
Policies, registers and retention: what your syndicate must plan for
Effective compliance rests on a few simple documents adapted to the reality of your building.
- Privacy policy (external)
- Purpose: explain what data is collected, such as contact information, vehicles, licence plates, camera footage and intercom recordings; why it is collected, such as managing common expenses, security and communicating notices; and the rights of individuals.
- Publication: on the syndicate’s website, if one exists; otherwise, share it by email or through the co-owners’ digital folder.
- Information governance framework (internal)
- Roles, access processes, retention and destruction, logging, and controls for physical and cloud-based media.
- Include a risk assessment template for new projects, such as adding cameras or a smart key system. Certain activities may require a privacy impact assessment before deployment.
- Incident register
- Keep an ongoing register, even when no external notice is required. The register must describe the incident, the information involved, the risk assessment and the measures taken (section 3.8 of P-39.1).
- Retention schedule
- Set retention periods based on legal obligations and management needs: for example, minutes and corporate registers may be retained for a long time, insurance claim files for at least several years after closure, and accounting records according to tax requirements. Refer to Revenu Québec guidelines for tax documents.
Practical examples in a condo
- Intercom systems and cameras: announce the presence of cameras, limit the viewing angle to the necessary common portions, set a short retention period (e.g., 14–30 days according to actual needs) and control access.
- Digital tools: management, accounting and notice-sending platforms must be protected with strong passwords and, where possible, two-factor authentication. Separate board of directors’ access and revoke access for former directors.
- Sharing information among co-owners: avoid publicly sending third parties’ complete contact information. Use blind-copy mailing lists and redact documents when necessary.
For an additional sector overview, also consult the OACIQ guidelines on managing personal information in real estate.
Managing a privacy incident: quick steps
A privacy incident is any unauthorized access, use, communication or loss of personal information, or any other breach involving personal information. Examples include a lost board laptop, minutes sent to the wrong mailing list or unauthorized access to camera recordings.
Here is an intervention sequence adapted to a syndicate, consistent with Act P-39.1 (sections 3.5 to 3.8):
- Contain
- Cut off the compromised access by changing passwords, deactivating an account, or remotely retrieving or erasing a device.
- Assess the risk of serious harm
- Consider the nature of the information (contact information, financial information and sensitive data), the number of people affected and the likelihood of malicious use.
- Document the incident in the register
- Describe the incident, the people potentially affected, the risk analysis and the corrective measures.
- Notify where necessary
- If a risk of serious harm has been established, notify the individuals concerned without delay and the competent authority in accordance with the applicable law. The notice must enable individuals to reduce the risk, such as by monitoring accounts or changing passwords.
- Make lasting corrections
- Adjust controls by training the board of directors, strengthening access controls, changing document-sending procedures and reviewing retention periods.
Important: the Act requires the incident register to be retained and made available upon request. Even a “minor” incident must be recorded.
A five-step implementation plan for your board of directors
- Assess the current situation (2-3 board of directors meetings)
- Inventory the data: what information exists, where it is stored, who has access to it and for what purpose.
- Appointment and publication
- Board of directors’ resolution, written delegation where necessary, published contact information and notice to co-owners.
- Minimum documentation
- External policy, internal framework, incident register and retention schedule.
- Contractual clauses
- Add “confidentiality” schedules to current and future supplier contracts, covering limited access, subcontracting, the end of the mandate (return or destruction) and incident notices.
- Training and annual review
- Use 30 minutes at the annual general meeting to present the policy and review good practices; the privacy officer should conduct an annual review of access rights and the register.
Official resources to consult
- Consolidated text: Act respecting the protection of personal information in the private sector (P-39.1)
- Modernized legislative framework: S.Q. 2021, c. 25 (Bill 25)
- Practical divided co-ownership resources: RGCQ
Looking for templates, such as a resolution, policy or register? Take a look at our services pages to see how support can structure your documentation: administrative management services and financial management.
In summary, appointing a privacy officer, documenting a few simple procedures and maintaining an incident register already puts you on the right track. The rest comes down to board of directors discipline: minimize data, limit access and review everything annually. This protects co-owners, reduces risks and builds trust at annual general meetings.
To continue, browse our resources on the blog or speak with us about a realistic implementation plan for your syndicate.
This article provides general information and does not constitute legal advice. Consult a lawyer or notary for advice about your situation.
Do you manage a co-ownership in Quebec? Explore our packages or contact us to assess your needs.
