Board portals
A board portal is software, not a contract term. The contract term is what protects you after you sign.
A board portal is software your board uses to store documents, run agendas and minutes, and communicate between meetings. Before you sign, confirm three things: the association, not the vendor, owns the data; the data exports in a usable format; and your board, not the vendor, controls who has admin access.
What a board portal actually does
A board portal is internal, built for directors and (often) the manager, not for the general owner population. Typical functions: a shared document library for the declaration, bylaws, and contracts; a workspace for drafting agendas and minutes; a message thread for discussion between meetings; sometimes a way to record a board vote outside a live meeting.
That last function deserves a pause. Whether a vote cast through a portal counts as an official board action depends on your state's open-meeting statute and what your bylaws authorize, the same layered rule that governs virtual meetings and electronic voting. A portal that lets you click "approve" does not by itself make the click legally binding.
A board portal is a different product from an owner portal, which is owner-facing and, in some states, has its own posting requirements. Don't assume one satisfies the other.
The three questions to ask before you sign
Feature comparisons are how boards get sold. Contract terms are what determine whether the board can leave later. Ask the vendor, in writing, before signing: who owns the data, what format it exports in, and who controls the admin credentials.
"Your homeowners association's funds and documents belong to the board, not to whoever happens to be managing them at the moment."
Source: HOA Management Company Transition Checklist for Boards, RowCal
Treat that as sound practice to negotiate into the contract, not a right you can assume exists automatically; the specific legal backstop, if any, varies by state. A vendor that won't put data ownership and export terms in writing is telling you something about what happens if you ever try to leave, see avoiding vendor lock-in and data migrations. If the portal will also process dues payments, add a fourth question: any system that touches cardholder data is in scope for PCI DSS, even when a separate processor handles the actual charge, so ask the vendor how it satisfies that obligation.
Admin credentials are a compliance issue, not just IT
Someone on your board or your management company holds the login that can add, remove, or reconfigure users in the portal. That login is a bigger deal than it sounds. When a director rotates off the board or a management contract ends, removing that access is not housekeeping, it is the thing standing between an old login and owner personal data still sitting in the system.
"The disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach."
Source: California Civil Code section 1798.82, California Legislature
Whether your state has a breach notification law like California's, and what window it sets, varies, so check your own state's statute. Either way, know who currently holds admin access to your board portal, and have a written step to revoke it the day a role changes.
Check yourself
Answer before you read the explanation, recalling it is what makes it stick.
The board is comparing two board portal vendors. Vendor A's contract says nothing about what happens to board records if the association leaves. Vendor B's contract states the association owns all data and will provide an export within 30 days of cancellation. Which contract matches sound practice?
A property manager who administered the board portal is replaced mid-year. Six weeks later, the former manager can still log in and download the owner roster. What went wrong?
A board adds a "pay dues here" button to its board portal that connects to a card processor. A director says PCI compliance is the processor's problem alone. Why is that wrong?
- HOA Management Company Transition Checklist for Boards, RowCal
- California Civil Code section 1798.82, California Legislature
- PCI Data Security Standard (PCI DSS), PCI Security Standards Council
Technology
Ready to move records into a new system, or out of an old one? See data migrations for how that actually works.
Whether your association owns its portal data by default, how fast a vendor must return records after cancellation, and whether a payment integration inside the portal triggers PCI DSS all depend on the contract you sign and the state you're in.