Water Sub-Meters in Co-Ownership: Legal in Quebec?
04/06/2026Room Rentals in a Quebec Condo: Rules for Co-owners
04/06/2026Smart Locks in Divided Co-ownership: Bill 25 in Quebec
Adopting smart locks in a divided co-ownership can improve security and simplify access management. However, these devices process personal information. Compliance with Bill 25 therefore becomes mandatory for the syndicate and the board of directors (board).
Updated as of 2026-06-04. This article guides you through the practical obligations related to digital access control, from privacy impact assessments (PIAs) to agreements with cloud providers, as well as internal policies and communications with co-owners.
What Bill 25 changes for access control
Bill 25 modernizes the Act respecting the protection of personal information in the private sector and imposes new responsibilities on organizations, including syndicates. Smart locks generate access logs, user identifiers and, sometimes, sensitive metadata. Here are the key requirements to plan for (see Act P-39.1, LegisQuebec):
- Designate a person responsible for the protection of personal information. In a syndicate, the board can assign this role to a director and document the mandate.
- Adopt policies and practices governing personal information management and publish clear information about them.
- Maintain a register of confidentiality incidents and, where there is a serious risk of harm, notify the affected individuals and the Commission d’accès à l’information.
- Conduct a PIA for any technology project presenting risks, including the implementation of a smart-lock system or the hosting of data outside Quebec.
- Establish contractual safeguards for providers that process information on behalf of the syndicate, including clauses on security, confidentiality and incident notification.
- Limit collection to necessary information, restrict access on a need-to-know basis, and establish retention periods and secure destruction practices.
Useful resources:
- Act (P-39.1): https://www.legisquebec.gouv.qc.ca/fr/document/lc/p-39.1
- Transfers outside Quebec and adequate protection measures (see s. 17 of P-39.1): https://www.legisquebec.gouv.qc.ca/fr/document/lc/p-39.1
Data collected by a smart lock: what is permitted
A smart lock or access controller typically collects:
- User identifiers (e.g., key fobs, PINs, cards or mobile applications) and their status.
- Entry and exit timestamps by door, sometimes with a device identifier.
- Administrative settings (creation/revocation of virtual keys), the panel’s IP address, and system logs.
These elements constitute personal information when they are linked to an identifiable person (co-owner, tenant, superintendent or contractor). In a condominium, their processing must comply with the principles of necessity, proportionality and security. In practical terms:
- Minimization: activate only useful functions. Avoid continuous geolocation or unnecessary data.
- Default settings: prioritize privacy by default (detailed logs visible only to individuals authorized by the board or management).
- Retention: define a reasonable period for access logs. The more sensitive the data, the shorter and more justified the retention period should be.
- Transparency: display a clear notice near entrances and inform occupants of the purposes, data categories and contact information for the person responsible.
If hosting or technical support is located outside Quebec, a PIA is required to assess the applicable legal framework and provide contractual safeguards (see s. 17 of P-39.1). The outcome and selected measures should be recorded and approved by the board.
Choosing a compliant provider and model
Before purchasing equipment or a cloud platform, the board should conduct due diligence. Here is a Bill 25-oriented checklist for selecting an access-control solution:
- Hosting: where are logs and settings stored? Prioritize Canada, or conduct a PIA and include appropriate clauses if hosting is outside Quebec.
- Security: encryption in transit and at rest, key management, tamper-proof logging, MFA for administrators.
- Governance: ability to define roles and granular access (condominium manager, board, superintendent), and export the audit register.
- Portability: ability to extract and delete data according to the syndicate’s retention policies.
- Contract: personal information protection addendum, incident notification, authorized subcontractors, data location, security testing.
- Operations: ease of revoking access (e.g., when a tenant leaves), reliable timestamps, compatibility with common-portion doors and panic-hardware regulations.
RGCQ publishes good-practice guidance for syndicates; use it to structure your project and internal policies: https://rgcq.org/ressources/
Syndicate governance: policies, declaration of co-ownership and annual general meeting
Introducing a smart lock is not limited to the technology. Your internal framework must keep pace.
- By-laws and declaration of co-ownership: check whether the declaration of co-ownership and by-laws of the immovable already govern access control. If not, an amendment or resolution may be required to clarify the use of common portions, virtual keys, and the management of visitors and contractors.
- Decision-making process: depending on the scope of the work, a board resolution may be sufficient. For rules affecting all occupants, favour a vote at the annual general meeting and record the decisions in the minutes. Ensure quorum and precise wording of the administration powers.
- Information: provide co-owners and tenants with a notice specifying the purposes, data categories, retention periods, and recourse available to access or correct information.
- Internal access: clearly define who within the board and management may consult the logs, for what purposes, and under what authorization procedure.
To structure your approach, see our administrative management and compliance services, including support for the board and document updates: https://www.multirent.ca/services/#gestion-administrative
Notice, consent and transparency
In a common-portion security context, consent may be implied if the collection is necessary and proportionate to the purpose pursued. Transparency remains essential: display a notice at the entrance, incorporate an internal privacy policy, and provide the contact information for the person responsible. Avoid reusing logs for disciplinary purposes without a legitimate basis and without respecting the principles of necessity and proportionality.
Roles and data access
- The board assumes overall responsibility and approves the policies.
- Management, whether internal or external, implements the procedures, administers access, and maintains the incident register.
- Providers act only as mandataries; their access must be limited contractually and monitored through logging.
For more guidance on document governance (minutes, policies and registers), browse our blog: https://www.multirent.ca/blogue/
Biometrics and incidents: points to watch
Some solutions offer fingerprint or facial-recognition technology. Biometrics raise heightened concerns. In Quebec, the creation of a database of biometric characteristics must be reported to the competent authority before it is put into service, and must be governed by strict security and proportionality measures. Refer to the following legal framework:
- Act to establish a legal framework for information technology (C-1.1): https://www.legisquebec.gouv.qc.ca/fr/document/lc/C-1.1
- Regulation respecting biometric characteristics or measurements databases (C-1.1, r. 1): https://www.legisquebec.gouv.qc.ca/fr/document/rc/C-1.1,%20r.%201
Before choosing biometrics, ask yourself whether a card, key fob or application with MFA would not be sufficient. If you retain the biometric option, conduct an in-depth PIA, establish safeguards for consent, and provide a non-biometric alternative.
As for incidents, Bill 25 requires a register to be maintained and the affected individuals and the Commission d’accès à l’information to be notified when an incident presents a serious risk of harm. Prepare a response plan covering detection, containment, risk assessment, notifications, corrective measures and a review of controls.
For reference, the Civil Code of Quebec entrusts the syndicate with the preservation of the building and the safeguarding of rights pertaining to the common portions. Access control must therefore reconcile security, privacy and reasonable access to private portions (see C.C.Q. https://www.legisquebec.gouv.qc.ca/fr/document/lc/CCQ-1991).
Implementation in 6 steps
- Scoping: adopt a board mandate, designate the person responsible, and list the doors and users (co-owners, tenants and contractors).
- PIA: analyze data flows, risks, hosting and mitigation measures. Document the choices and obtain board approval.
- Provider selection: compare contractual safeguards, security and governance functions. Prepare a personal information protection addendum.
- By-laws: update the by-laws of the immovable as needed, prepare the notice to occupants, and plan the resolution for the annual general meeting. Record the decisions in the minutes.
- Deployment: schedule a pilot project, train the superintendent and management, review the default settings, and activate MFA.
- Operations: apply retention periods, test incident procedures, and periodically reassess the solution.
Need help structuring the project, drafting your policies or managing the provider? See our integrated management services and packages: https://www.multirent.ca/#forfaits and https://www.multirent.ca/services/#gestion-des-operations
FAQ
- Are access logs personal information? Yes, when they identify a person directly or indirectly. Their collection must be necessary, and access must be limited to authorized individuals.
- Can we require all occupants to use a mobile application? You can propose the application if it is necessary and proportionate. Offer a reasonable alternative (e.g., card or key fob) to avoid excessive collection.
- How long should logs be retained? Determine a period justified by security and any potential legal obligations. Document it in your policy, apply automatic deletion, and maintain a destruction register.
This article provides general information and does not constitute legal advice. Consult a lawyer or notary regarding your situation.
Do you manage a condominium in Quebec? Discover our packages or contact us to assess your needs.
