Salta al contenuto principale
All articles
Privacy4 min read

Condominium Manager: Controller or Processor?

Condominium, manager and software provider play different GDPR roles. Clarifying who is controller and who is processor avoids wrong appointments and misallocated liability.

In this guide

For GDPR purposes, the condominium, the manager and the software provider do not share the same role. The condominium is the data controller when the purposes concern the collective management of common areas, while the manager acts as processor or as an independent controller depending on the activity. The software provider, which processes data on the manager's behalf, is almost always an external processor. Correctly identifying these roles is the premise for valid appointments and well-allocated responsibility.

Controller, processor, authorized person: the definitions

The GDPR distinguishes three figures. The controller decides the purposes and means of processing. The processor, under Article 28, processes data on behalf of the controller on the basis of a contract or other legal act. Authorized persons, once called incaricati, are those who operate under the authority of the controller or processor. In a condominium these figures intertwine and their exact attribution depends on who decides the purposes of each processing operation.

The condominium as controller

The Garante guidelines started with the measure of 10 April 2025, and published for consultation in Official Gazette no. 106 of 9 May 2025, clarify an important point: when the purposes of processing concern the collective management of common areas, for example installing cameras, running the website or portal, choosing suppliers, the controller is the condominium. Decisions are taken by resolution of the owners' meeting and the manager, in these cases, acts by operationally implementing what was resolved, therefore as the condominium's processor.

When the manager is an independent controller

The manager remains an independent controller for processing that concerns their professional organization rather than the collective management of the individual condominium. This includes keeping the firm's own accounts, employment relationships with staff, the firm's tax obligations and managing the contractual relationship with each condominium. The distinction matters because it determines who answers to the data subject and who must prepare the privacy notice, record of processing activities and security measures for that operation.

  • Condominium as controller: video surveillance, portal, supplier choice, common area management
  • Manager as processor: operational implementation of the meeting's resolutions
  • Manager as independent controller: firm accounting, employees, own obligations
  • Software provider: external processor on behalf of the manager or the condominium

The software provider as external processor

Whoever provides the cloud management software technically processes owners' data on the client's behalf. It is therefore a processor and must be appointed with an agreement under Article 28 GDPR, often called a data processing agreement. The agreement must set out the subject matter, duration, nature and purpose of processing, the type of data and categories of data subjects, and impose precise obligations on the processor: act only on the controller's instructions, ensure confidentiality, adopt security measures, assist the controller with data subject requests and data breaches, delete or return the data at the end of the relationship and allow audits.

Appointing authorized persons

Within the firm, staff who access owners' data must be authorized and instructed in writing. Good faith is not enough: clear instructions are needed on what they may process, with which tools and within which limits. It is good practice to differentiate access levels so that each person sees only the data needed for their task. This principle, least privilege, is also a security measure that reduces the impact of any incident.

Why allocating roles is decisive

Misallocating roles has practical consequences. If the manager considers themselves controller of processing that belongs to the condominium, they may take decisions reserved to the owners' meeting, for example on video surveillance. If they fail to appoint the software provider as processor, they remain exposed in case of a breach. Clarity of roles also enables correct responses to data subject requests, directing them to whoever actually has the power to decide them.

Setting it up from the start

In daily management it is worth keeping, for each condominium, the list of processing operations with their role, the appointment agreements with suppliers and internal authorizations. Tidy management software helps maintain this structure without adding workload. AmministraPro is designed for the professional firm and supports access separation and document archiving: the features are described on the /funzioni page, and the plans suited to sole practitioners or structured firms are shown on the /prezzi page, so you can start with a clear and sustainable allocation of roles.

Topics:condominium data controllerdata processorcondominium manager GDPRprocessor appointment Article 28condominium privacy roles

Manage your buildings with AmministraPro

Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.

Written by the AmministraPro Editorial Team

The AmministraPro editorial team closely follows condominium law, accounting and digital tools for administrators and property firms.