Quick answer: in Quebec, Law 25 applies to your condo syndicate. The syndicate is an enterprise within the meaning of the Act, even though it is non-profit. Since 22 September 2022, it must designate a person responsible for the protection of personal information and publish that person's title and contact details. Since 22 September 2023, it must also adopt and publish a governance policy.
This article answers the eight questions Quebec condo boards ask most often, citing the article that settles each one. Where no article settles it, it says so: that happens more often than people expect, and it is useful information.
Does Law 25 really apply to a condo syndicate?
Yes, and the usual objection does not hold. "We are not a business, we make no profit" changes nothing, because the definition itself answers the question.
Three articles carry the reasoning:
- The Act respecting the protection of personal information in the private sector applies, under section 1, to personal information collected "in the course of carrying on an enterprise within the meaning of article 1525 of the Civil Code".
- Article 1525 of the Civil Code defines carrying on an enterprise as "the carrying on by one or more persons of an organized economic activity, whether or not it is commercial in nature, consisting of producing, administering or alienating property, or providing a service".
- Article 1039 of the Civil Code makes the syndicate a legal person whose object includes "the maintenance and administration of the common portions".
Organized administration of property, non-commercial in nature: that is exactly the article 1525 test. The syndicate is therefore subject to the Act.
One clarification for phased co-ownerships. Where a complex has an initial syndicate and one or more concomitant syndicates, each is a separate legal person and therefore a separate enterprise under the Act. Each must designate its own person responsible and adopt its own governance policy: the obligations are not shared across the layers. See phased co-ownership.
Two obligations follow, with two different dates.
| Obligation | Section | In force since |
|---|---|---|
| Designate the person responsible, publish their title and contact details | s. 3.1 | 22 September 2022 |
| Establish, implement and publish a governance policy | s. 3.2 | 22 September 2023 |
Who is the person responsible in a syndicate?
Section 3.1 says "the person exercising the highest authority" holds the function, and may delegate it in writing. The Act does not say who that is in a syndicate, and neither does the Civil Code. In practice the board designates someone by resolution, which has the advantage of leaving a record.
What the Act requires you to publish is the "title and contact information" of the person responsible. Not necessarily their name.
What if the condo has no website?
That describes most small co-ownerships, and the Act anticipated it. Section 3.2 requires the information to be published "on the enterprise's website or, if it does not have a website, by any appropriate means". Section 3.1 uses the same formula for the contact details.
Having no website therefore exempts you from nothing: it changes the means. Posting in a common area, sending it with the meeting notice, filing it in the register, publishing it in the management portal: any of these can work. Keep proof of the means chosen and the date.
Can minutes use initials or unit numbers instead of names?
Yes, the syndicate may do that. No article requires it and none forbids it. That is the honest answer, and it often surprises.
The Civil Code requires the syndicate to keep minutes and to send them, but nowhere does it prescribe that they name people. The necessity principle in section 5 of Law 25, which limits collection to what is necessary for the purposes determined, argues for restraint.
Three points, because this is where mistakes happen:
- Minutes and the register are different things. Trimming the minutes changes nothing about the register: article 1070 of the Civil Code still requires "the name and postal address of each co-owner", and other personal information belongs there only with the person's express consent.
- A unit number is still personal information. In a co-ownership it identifies a person indirectly, which is enough under section 2 of the Act.
- This is not anonymization. Anonymization, under section 23, is irreversible and follows criteria set by regulation. Replacing a name with initials is de-identification, which is not the same thing and does not carry the same effects.
One last caution: minutes also serve to exercise remedies, including an application to annul a decision of the meeting. Minutes that become unintelligible would work against the syndicate.
Should co-owners be blind-copied on group emails?
Yes, in practice. But there is no "Bcc section" in the Act.
The obligation arises from two sections combined. Section 13 prohibits communicating personal information to a third person without the consent of the person concerned. An email address is personal information, and sending to "To" or "Cc" discloses it to every other recipient. Section 10 requires security measures that are reasonable given the sensitivity, quantity and purpose.
For a group message to co-owners, blind copy, or individual sends, is the reasonable measure expected.
One escape hatch not to reach for: the Act excludes from certain rules the professional contact details of a person carrying out duties within an enterprise. That exclusion covers a workplace email address. It does not cover a co-owner's personal email, which remains protected.
What insurance details may the syndicate require?
Start with what surprises people: the Civil Code requires a co-owner to carry liability insurance, but it does not require them to hand proof of it to the syndicate. That requirement normally comes from the declaration of co-ownership or the building by-laws. Check yours before demanding anything.
Once the purpose is established (confirming the coverage exists and is in force), section 5 limits collection to what is necessary:
| Information | Necessary to verify coverage? |
|---|---|
| Insurer name | Yes |
| Policy number | Yes |
| Coverage start and end dates | Yes |
| The full policy | No |
| Claims history | No |
| Past claim amounts | No |
And if the syndicate wants to file this in the register, article 1070 requires the co-owner's express consent: it is not part of the mandatory content.
Consent: a signed form every year, or an email?
The Act prescribes no form. No paper, no signature, no annual cycle. Section 14 imposes a quality: consent must be "clear, free and informed", given "for specific purposes", and requested "in clear and simple language". Where the request is in writing, it must be presented separately from any other information.
An exchange of emails can therefore constitute consent, provided each purpose is requested separately and the manifestation is active and traceable. A signed form has no greater legal value: it has better evidentiary value, which is a different matter.
Two misconceptions to drop:
- Consent does not expire after a year. Section 14 says it "is valid only for the time necessary to achieve the purposes for which it was requested". A change of purpose is what triggers a fresh request, not the calendar.
- Not everything rests on consent. Much of what a syndicate does flows from its Civil Code obligations, and the Act itself provides for communications without consent. Asking for consent where none is required creates a false impression of choice.
How long to keep information, and how to destroy it?
Law 25 sets no fixed duration. It sets a trigger and a reservation: under section 23, once the purposes of collection are achieved, the information must be destroyed or anonymized, "subject to a retention period provided for by an Act".
For a syndicate, that reference points mainly to documents the Civil Code requires be kept in the register. So it falls to the syndicate to set its own retention grid by category, and section 3.2 requires its governance policy to expressly address retention and destruction.
Mind the word "anonymize". Section 23 defines it strictly: information is anonymized when it is reasonably foreseeable that it irreversibly no longer allows the person to be identified, and anonymization must follow criteria set by regulation. Redacting a name in a document is not anonymizing it.
Does the management firm have the same obligations?
It has two sets of them, and the syndicate does not offload its own.
The firm carries on its own enterprise: it is therefore itself responsible for the information it holds, with its own person responsible and its own governance policy.
But it is also the syndicate's mandatary, and that is where section 18.3 applies. The syndicate must confer the mandate in writing, and the contract must state:
- the measures the firm must take to protect confidentiality;
- that the information is used only to carry out the mandate;
- that it is not kept after the mandate expires;
- that the firm must notify the syndicate's person responsible without delay of any violation or attempted violation;
- that the syndicate's person responsible may conduct any verification in that regard.
The same rule applies to any supplier processing information on the syndicate's behalf, including a software or hosting provider. It is the most frequently overlooked of the five.
A citation note, because the error circulates: the written-contract rule is section 18.3. Section 18.4 governs something else, the communication of information in the context of a commercial transaction.
Which policy must the syndicate have, and publish?
There are two distinct documents, and confusing them is the most common error.
| Governance policy | Confidentiality policy | |
|---|---|---|
| Section | 3.2 | 8.2 |
| Trigger | Every enterprise | Collection by technological means |
| Nature | Internal, with detailed information published | Distributed to the persons concerned |
The governance policy must address retention and destruction, define roles and responsibilities across the information lifecycle, and provide a complaint-handling process. It must be proportionate to the nature and scope of the syndicate's activities, and approved by the person responsible. A twelve-unit co-ownership therefore does not have to produce what a two-hundred-employee company would.
Is a co-owners' Facebook or WhatsApp group allowed?
The question is not the platform. It is who uses it, and for what.
A strictly private group among co-owners, unconnected to the administration of the syndicate, falls outside Law 25. It remains subject to the Civil Code right to privacy, which is not nothing: you do not post your neighbour's arrears there.
The moment the board or the manager uses it as an official channel, the whole regime applies: reasonable security measures, no communication of personal information to third persons without consent, and the prior assessment under section 17 if information is processed outside Quebec, which is the case for most consumer messaging services.
Two cautions. Section 17 does not prohibit processing outside Quebec: it requires you to assess it beforehand. And a chat group never replaces the register or the official transmission of minutes.
Frequently asked questions about Law 25 in co-ownership
Our syndicate is too small to be covered, surely?
No. The Act provides no size threshold and no exemption for non-profit organizations. What varies with size is the expected scope: section 3.2 requires policies "proportionate to the nature and scope of the activities". A twelve-unit co-ownership must therefore have a governance policy, but a short one.
Since when have these obligations existed?
Two dates. Designating and publishing the person responsible has been in force since 22 September 2022. The governance policy and its publication have been in force since 22 September 2023. A syndicate that has done nothing yet is late, not early.
Does the board have to pass a resolution?
The Act does not expressly require one: it provides that the function belongs to the person exercising the highest authority, and that any delegation must be in writing. A resolution remains the simplest way to prove who was designated, from what date, and with what mandate.
Can we refuse a co-owner access to other people's information?
Yes. The right of access covers information concerning the person making the request. It does not open other co-owners' files, whose communication remains governed by article 1070 of the Civil Code and by the confidentiality rule.
What should we do after a confidentiality incident?
Record it in the incident register, assess whether it presents a risk of serious injury, and if so notify the Commission d'accès à l'information and the persons concerned promptly. The incident register is kept for at least five years. If the incident occurs at a supplier, that supplier must notify the syndicate's person responsible without delay.
What a tool can do, and what it cannot
No software makes a syndicate compliant, and you should be wary of anyone who claims otherwise. Designating the person responsible, adopting the policy and making retention decisions belong to the board.
What a tool can take off your hands is the mechanics: keeping the register current, controlling who sees what, logging access to sensitive documents, sending notices without exposing everyone's address, and keeping proof of what was sent and when.
One question few syndicates ask themselves: where is your data hosted, and across how many different suppliers? Every supplier processing information on your behalf calls for a written agreement under section 18.3, and every processing outside Quebec calls for the section 17 assessment. The fewer the suppliers, and the closer they are, the lighter the assessment. No tool escapes the question entirely, CondoAide included: we use sub-processors, and some are outside Quebec. That is exactly why the list, with each one's jurisdiction, is published on our security page. An assessment is only possible if the supplier says where the data goes.
Further reading
- Complete guide to Law 16 in co-ownership: the other major block of syndicate obligations.
- The condo register versus Google Drive: the mechanics of access and permissions.
- Giving access to your accountant and other professionals: the concrete case of a supplier who sees personal information.
- Virtual meetings and videoconferencing: what a remote meeting produces.
This article provides general legal information current as of 25 August 2026. It is not legal advice and does not account for your syndicate's declaration of co-ownership. For a question that binds your co-ownership, consult a lawyer or notary.
