Property Management Tips
PIPEDA and smart building technology: what property managers need to know
Smart lockers, cameras and access systems all collect personal information. A practical overview of the privacy questions Canadian property managers should be asking vendors.
By Accessa Parcel Team, Multifamily operations · · 9 min read

Every smart building system collects personal information. A parcel locker knows who lives in which unit, what their phone number is, when they came down to the lobby and how often. An access control system knows who entered and when. A camera at the locker bank records whoever stands in front of it. None of that is sinister, and all of it is regulated.
For Canadian property managers, the relevant framework is usually the Personal Information Protection and Electronic Documents Act (PIPEDA) federally, with substantially similar provincial legislation in Quebec, British Columbia and Alberta. Which regime applies to your building depends on where you operate and the nature of the activity — that determination is one to make with counsel, not from a blog post.
What this article can do is tell you which questions to ask, and which vendor answers should worry you.
Start with what is actually collected
Before any policy discussion, write down the data. For a parcel locker system the list typically looks like this:
- Resident name, unit number, email address and mobile number.
- Parcel events: deposit time, compartment, carrier, pickup time, pickup method.
- Access credentials: PIN codes, QR codes, app accounts, optionally RFID fobs.
- Camera images or video captured at the kiosk, where cameras are enabled.
- Sensor data indicating a door opened or an item was placed or removed.
- Staff account activity in the management dashboard.
That list is the foundation for everything else: what you tell residents, how long you keep it, who can see it, and what you have to do if it leaks.
The principles that drive vendor questions
Purpose and limits
Personal information should be collected for identified purposes and used for those purposes only. In practice this means asking a vendor directly: is resident data used for anything beyond operating the lockers? Is it used to train models, generate benchmarks, or sold or shared with third parties? A vendor that cannot answer plainly, in writing, is telling you something.
Consent and notice
Residents should know what is collected and why, in language they can understand, at the point they are enrolled. That usually means a short privacy notice at onboarding rather than a clause buried in a lease. Where cameras are in use, visible signage at the bank is standard practice.
Retention and deletion
Data should not be kept indefinitely because storage is cheap. Ask what the default retention period is for parcel events, access logs and camera footage; whether it is configurable; and what happens when a resident moves out. Move-out is the moment most systems quietly fail — accounts stay active, codes keep working, and personal information sits in the system for years.
Access and correction requests
A resident can ask what personal information you hold about them. You need to be able to answer without a support ticket to a vendor in another country. Ask whether the dashboard lets staff export a single resident's record and delete it, and how long a vendor-assisted request takes.
Safeguards
Encryption in transit and at rest, role-based staff access, multi-factor authentication for dashboard accounts, and audit logging of who looked at what. Ask specifically whether every staff member sees every resident, or whether access can be scoped per building — a portfolio-wide login for a site-level employee is a common and avoidable weakness.
Data residency and cross-border transfer
Where the data physically lives is one of the first questions Canadian boards and owners ask. Cross-border storage is not automatically prohibited under federal law, but residents generally must be told, and some public-sector and Quebec contexts carry additional requirements. Ask a vendor where data is stored, where support staff access it from, and whether Canadian residency is available.
[VERIFY] Accessa Parcel's own data residency position, sub-processor list and retention defaults must be confirmed with our compliance team and reproduced accurately here before publishing.
Breach response is a plan, not a reaction
Federal law requires organisations to report breaches of security safeguards that create a real risk of significant harm, notify affected individuals, and keep records of breaches. For a building, the practical questions are: who at the vendor tells you, how quickly, and what do they give you to work with?
- Confirm the vendor's notification commitment and timeline in the contract, not the sales deck.
- Know who inside your organisation owns the decision to notify residents.
- Keep a current inventory of which systems hold which resident data, so scope can be assessed in hours rather than weeks.
- Retain the vendor's incident report — record-keeping obligations apply to breaches you decide not to report as well.
Cameras deserve their own conversation
Video is the most sensitive stream in a locker deployment and the one most likely to be over-collected. Reasonable practice is to record only what is needed to resolve parcel disputes, keep it for a defined short period, restrict who can view it, log every access, and post clear signage. Continuous recording of a lobby for general surveillance is a different purpose and should be assessed separately.
“The safest posture is to collect the least data that still lets you answer the question a resident will ask, and to delete it on a schedule you set deliberately.”
A short vendor checklist
- What personal information does the system collect, field by field?
- Where is it stored, and who can access it from where?
- What are the default retention periods, and are they configurable?
- How is a resident deleted at move-out, and is that automatic?
- Can we export or delete one resident's record on request?
- Is data ever used for anything other than operating our lockers?
- What is the breach notification commitment, in writing?
- Is staff dashboard access role-based, scoped per building and audited?
If you are evaluating locker systems now, the software capabilities behind these answers are described on our smart parcel lockers page, and portfolio-level access controls are covered on the property managers page.
Stay in the loop
Get new Accessa Parcel articles and resources by email.