
Rules
Part of How to plan condo EV charging from start to finish
Where privacy concerns appear with condo EV charging
Session logs from condo chargers show when residents come and go. Boards must decide who sees that data and what happens to it at contract end.
What to take away
- A session log is a movement recordstart time, end time, port, energy delivered. It shows when a unit was empty.
- Name the board roles that may open individual session records, and write that list into the management agreement before anyone asks for it.
- Ask the vendor in writing what happens to resident data if the association leaves, and put the answer in the contract.
- A networked charger is an internet-connected device on building infrastructure. It belongs in the same security review as the access system and the Wi-Fi.
- Keep session detail only as long as the billing dispute window requires. Years of history serves nobody.
Nobody objects to a charger measuring kilowatt hours. The objection arrives when a resident realizes the log shows what time they got home on a Tuesday.
What the system actually holds
Write this inventory before you choose hardware. Each line carries a different retention and access question.
| Data | Why it exists | Who usually sees it |
|---|---|---|
| Name, unit, email, phone | Account setup | Property manager, vendor support |
| Card, fob or app credential | Port access | Vendor platform |
| Session record: port, start, end, kWh | Billing and load reports | Board admin logins |
| Payment and transaction history | Settlement | Payment processor |
| App permissions, including location | Driver features | Vendor, third parties per its policy |
| Support tickets | Troubleshooting | Vendor staff |
| Camera coverage of the charging area | Security | Separate system, separate rules |
For each row, settle four things: why it is collected, who may see it, how long it is kept, and what happens at contract end. Most vendors can answer. Few volunteer.
The session log is the sensitive part
Energy totals are dull. Timestamps are not. A month of records shows working hours, travel, and empty space.
Who sees session detail
Does the board see individual sessions?
stated reason required
aggregate totals and billing only
In a condominium the readers are neighbors and volunteer board members, not trained staff. The same exposure attaches to the application file as much as the session log.
So decide deliberately:
- Does the board see individual sessions, or only aggregate totals and billing?
- Who holds an administrator login, and what happens to it when they leave the board?
- Is there an audit trail showing who opened which record?
- Can a resident pull their own history without asking staff?
The reasonable default is aggregate data for billing and capacity planning. Individual detail needs a stated reason each time. The Department of Energy's discussion of data access and privacy in metered energy systems makes the same point.
Payments and the resident app
Prefer an arrangement where the payment processor holds card details and the association never does. Ask whether the vendor stores card data, who the merchant of record is, and where refunds come from.
Check the arithmetic in practice. Running sessions of known duration against the meter catches a price rule that does not match the receipt.
Then look at the app residents are told to install. Ask what permissions it requests, whether it wants location in the background, and what its policy says about sharing with third parties. The association is recommending that app, and the recommendation carries weight.
The chargers sit on your network
A networked charger is an internet-connected device on property infrastructure, often with its own cellular link, sometimes on the building connection.
The Department of Energy has written about why cybersecurity matters for charging infrastructure. For a condominium the stakes are modest but real.
Ask how firmware updates are delivered and authenticated. Ask whether the units sit on a separate network segment from anything else the building runs. Ask what remote access the vendor keeps, and whether you can see when it is used.
If a vendor cannot describe how updates are signed, that is worth noticing.
What the resident notice says
Hand this over at sign-up. Six lines, no legal padding:
- what is collected and why
- who can see it, naming the board roles
- how long records are kept
- who it is shared with, naming the processor and the operator
- how to request your own data or a correction
- what happens to the data if the association changes vendors
Give retention as a number of months, not "as long as necessary." Billing disputes have a window. Session detail kept past it is exposure with no purpose.
Worked example: the exit clause
A board signs a three-year platform agreement. In year two they switch vendors. The old platform holds 40,000 session records, the resident roster, and two years of payment history.
Three questions decide whether that handover is clean:
- Can the association export the full history in a usable format, and at what cost?
- Does the vendor delete its copy, and will it confirm that in writing?
- Do the chargers keep working on another network, or do they become inert?
If the vendor is acquired or stops trading, what governs the data then? It is question 22 on the written list every bidder should answer, and the answer belongs in the contract rather than on a call.
Put the answers in the contract. Asking at termination is asking too late.
Several of these choices are made earlier than boards expect, when the ownership model is picked. The planning sequence covers that, and the differences between products on exactly these terms are set out in what to compare before choosing.
Common questions
Can the board see when residents come and go?
With a networked system, session records imply it. Whether the board should hold that access is a policy decision, and it should be made explicitly rather than by default. Aggregate views answer most billing questions without it.
Do we need a privacy notice?
Your obligations depend on your state. A short notice is worth writing regardless, because it prevents the argument more reliably than it satisfies any statute. Have counsel review the wording once.
Is a standalone charger more private?
Considerably, because it collects almost nothing. The trade is that you lose per-resident billing, remote diagnosis and load management. Some boards run both: networked ports in shared areas, standalone units at assigned spaces.
Who is responsible if the vendor has a breach?
Read the contract, because the default allocation may not be what you assume. This is worth a lawyer's eye before signing rather than after an incident. Ask specifically whether the vendor carries cyber liability coverage and at what limit.







