Updating the EEI and EFP After Work (Bill 16)
17/07/2026Discharging a Syndicate’s Legal Hypothec in Quebec
18/07/2026Key Management Policy: Divided Co-ownership and Bill 25
Managing keys, access cards and remote controls directly affects the security of the common portions and occupants’ privacy. In a divided co-ownership, a clear policy applied consistently has become essential since Bill 25 came into force, modernizing the protection of personal information in Quebec.
This article guides you through building a compliant access management policy that is simple for the board of directors (board) and the condominium manager to apply. We cover the elements to include, practical processes and records to maintain, in line with your declaration of co-ownership, the by-laws of the immovable and sound operational practices.
Key takeaway: your “key management policy for divided co-ownership and Bill 25” must limit the personal information collected, secure records, govern emergency access and document every issuance and return.
Why a policy is essential under Bill 25
Bill 25 has strengthened several obligations for anyone holding personal information, including syndicates. A key associated with a dwelling, an identified RFID card, a key-holder register or an access log may constitute information that can identify a person. This data must be handled carefully.
- Designation of a person responsible for the protection of personal information (often a director), with published contact information.
- An inventory of the information held (e.g., key-holder register) and a legitimate reason for collecting it.
- Appropriate security measures (access controls, passwords, encryption and locked premises).
- Procedures in the event of a confidentiality incident (e.g., loss of a master key or leak of a register).
For the legal framework, consult the Act respecting the protection of personal information in the private sector (P-39.1), as amended by Bill 25, and its original legislation. The syndicate’s governance rules also align with the Civil Code of Quebec (records management, access to documents and the syndicate’s obligations).
- LégisQuébec – Act respecting the protection of personal information in the private sector (P-39.1)
- LégisQuébec – Bill 25 (2021, c. 25)
- LégisQuébec – Civil Code of Quebec (CCQ-1991)
Essential content for a “keys, cards and access” policy
Your policy should be short, clear and aligned with the by-laws of the immovable. Adopt it by board resolution and announce it at the annual general meeting. Here are the recommended elements.
- Scope and definitions: mechanical keys, RFID cards, chips, PINs, mobile applications, master keys and key safes.
- Roles: board of directors (adoption and oversight), condominium manager (operations and records), concierge (implementation) and person responsible for privacy (Bill 25 compliance).
- Legitimate basis: security of the common portions, access control, compliance with the declaration of co-ownership and rules of use.
- Records: holders, card numbers, issuance and return dates, reasons for deactivation and incidents.
- Minimization: collect only the information required (e.g., name, unit, contact information and proof of identity when necessary). Do not copy identification documents except for a documented exception.
- Retention: limited periods and secure destruction (e.g., 24 months after return, unless there is an ongoing dispute).
- Issuance and return: standardized forms, acknowledgements of receipt, a deposit or fee according to by-laws approved at the annual general meeting, and prompt deactivation.
- Incidents: loss, theft or failure to return; who must be notified, timelines, measures (deactivation and reprogramming), traceability and notice to individuals if there is a serious risk of harm.
- Emergency access: a clear protocol (firefighters, police and damage-related emergencies), an opening log and a secure key safe.
- Contractors and brokers: temporary access with an expiry date and confidentiality obligations. Also see real estate brokerage practices.
Useful links:
- OACIQ – Protection of personal information in brokerage
- RGCQ – Resources for divided co-ownership syndicates
Records and retention: what to record and for how long
For each access credential, record the identifier (or masked number), issuance date, holder, authorizations (doors, floors and garage) and deactivation date. Avoid recording excessive information (e.g., date of birth). Keep records in secure software or a locked filing cabinet, with restricted and logged access.
- Access to records: limited to the condominium manager and authorized directors.
- Backups: encrypted, with storage in Canada whenever possible.
- Retention period: set a reasonable period based on operational needs and Bill 25, and define the deletion process.
Minimization and duty to inform
Inform co-owners and occupants, ideally through a standard notice, of the purposes, categories of information, technological tools used, access and rectification rights, and the contact information of the person responsible. Provide a consent template for optional access methods (e.g., mobile applications).
Step-by-step operational processes
Well-written procedures make day-to-day application easier and reduce errors. Adapt these steps to your building.
1) Issuing access credentials to a new occupant
- Verify the person’s status (co-owner or authorized tenant). Require written confirmation from the co-owner for a tenant.
- Issue the access credentials required, and no more. Avoid unjustified duplicates.
- Have the person sign the issuance form and the Bill 25 information notice.
- Update the register within 24 hours.
2) Recovering access credentials when someone moves out
- Remind the person of the return obligation set out in the by-laws.
- When the items are returned, check each one and immediately deactivate digital credentials.
- If items are not returned, apply the measures provided for (deactivation and fees according to by-laws approved at the annual general meeting) and document them.
3) Loss, theft or damage
- Report the incident as soon as it becomes known.
- Assess the risk and deactivate or reprogram without delay.
- If the master key is compromised, activate the special protocol (partial or complete replacement, communication to occupants and entry in the board’s minutes).
4) Emergency access
- Use an intrusion-resistant key safe or equivalent system, with an opening log.
- Limit access to emergency services and authorized persons designated by board resolution.
- Test the protocol twice a year and record it in the minutes.
5) Temporary access for contractors and brokers
- Require licences and insurance, and verify identities.
- Issue temporary cards with automatic expiry.
- Record visits in the log and recover or deactivate credentials at the end.
Require contractors to have the appropriate qualifications for access control and alarm systems. Consult the Regie du batiment du Quebec (RBQ) to understand work subcategories and the obligations of specialized contractors.
Summary table — roles, timelines and records
| Process | Primary person responsible | Recommended timeline | Evidence/record |
|---|---|---|---|
| Initial issuance | Condominium manager | 24 h | Signed form, register entry |
| Deactivation of lost card | Condominium manager/concierge | Immediate (same day) | System log, incident ticket |
| Master key replacement | Board of directors + supplier | 48–72 h depending on risk | Board resolution, invoice, notice to occupants |
| Emergency access | Designated persons | According to protocol | Opening log, annual general meeting/board minutes |
| Records purge | Person responsible for privacy | Quarterly/annually | Purge report, anonymized list |
Technology security and suppliers
RFID cards, chips and mobile applications create access logs. This data is useful for security, but sensitive under Bill 25.
Recommended best practices:
- Limit access-log retention to a defined period connected to incident prevention.
- Mask complete identifiers in exports (pseudonymization where necessary).
- Enable encryption and multifactor authentication for administration consoles.
- Manage passwords through complexity requirements, rotation and immediate removal of access when staff leave.
- Give preference to suppliers offering data hosting in Canada and accessible audit logs.
- Establish contractual clauses covering confidentiality and incident management with your suppliers.
For the installation, maintenance or upgrading of access controls, work with qualified and properly licensed contractors, and ensure that the technical documentation is added to your maintenance logbook/EUC.
Governance, training and communication with occupants
An effective policy lives through your decisions, minutes and communications. Here is how to anchor it for the long term.
- Adoption and updating: approve it by resolution; review it annually or after an incident. Add “current as of” followed by the date to the master document.
- Document integration: reference the policy in the declaration of co-ownership and the by-laws of the immovable; distribute it on the intranet or bulletin board.
- Training: provide a short module for new directors and the concierge, including a quick reference guide for welcoming and departing occupants.
- Transparency: explain in plain language why you collect certain data and how it is protected.
- Measurement and follow-up: report to the board of directors on the number of incidents, deactivation timelines and access or rectification requests.
For policy and form templates, see our administrative management and operations management service offerings. You can also explore our articles on local best practices.
- multiRent – Services (operations management)
- multiRent – Services (administrative management)
- multiRent – Blog
Frequently asked questions
Q1. Can we require a copy of identification to issue an access card?
A. Avoid keeping a copy unless there is a demonstrable need. Bill 25 favours minimization. Verify the person’s identity visually, record only what is required (name, unit and contact information) and state the legitimate basis for collecting it.
Q2. Who can consult the key-holder register?
A. Access should be strictly limited to the condominium manager and authorized directors. Provide anonymized excerpts upon request when a legitimate need is demonstrated. State this access and rectification right in your notice to occupants.
Q3. Can we charge a fee for a lost card?
A. Yes, if the by-laws of the immovable adopted in accordance with the declaration of co-ownership provide for it, and if the fee is reasonable and clearly announced. Document everything and issue a receipt. Enter the event in the register.
Q4. Is it permitted to use mobile applications as digital keys?
A. Yes, provided that you inform people, limit the data collected, secure the logs and establish contractual requirements for the supplier. Offer an equivalent alternative to people who decline this option.
This article provides general information and does not constitute legal advice. Consult a lawyer or notary for your specific situation.
Do you manage a divided co-ownership in Quebec? Explore our plans or contact us to assess your needs.
