Salta al contenuto principale
All articles
Privacy

GDPR and privacy in the condominium: the administrator's obligations

GDPR in the condominium imposes precise rules on the administrator regarding the processing of owners' data. Here is who the controller is, what data may be processed, when consent is needed and how to handle arrears and video surveillance.

Leggi questo articolo in italiano

GDPR in the condominium concerns the administrator every day, since they process owners' personal data to carry out their role: personal records, shares, arrears, consumption, sometimes video surveillance images. The European regulation 2016/679 and the guidance of the Italian Data Protection Authority (Garante) set precise rules on what may be processed, how and for how long. Knowing them protects owners and shields the administrator from disputes.

Who is the data controller in the condominium

In the condominium context the data controller is normally the condominium itself, as a management entity, while the administrator is the party who actually processes the data to carry out the mandate. The administrator must therefore organise the processing in a lawful, fair and transparent way, limiting access to the data to those who genuinely need it and adopting measures adequate to protect it.

What data the administrator can process

The administrator can process the data needed to manage the condominium: personal and contact details of owners, land registry data of the units, thousandth shares, accounting information on expenses and payments. The principle of minimisation requires collecting only the data essential to the management purposes and avoiding information that goes beyond the purpose. For example, it is not permitted to collect data on owners' lifestyle habits or to request documents unrelated to the management, such as health information, except within the limits in which a specific legal purpose justifies it.

When consent is needed and when it is not

For the ordinary management of the condominium the administrator does not need the owners' consent: the legal basis is the performance of the obligations connected with managing the common parts. Consent becomes necessary when the data is used for purposes unrelated to condominium management, for example for promotional communications or for purposes other than those for which it was collected.

The communication of data to external parties must also be assessed carefully. Passing information to suppliers, consultants or professionals engaged by the condominium is lawful when it is necessary to carry out the task, but it must be limited to the essential data. When the administrator relies on staff or suppliers who process data on their behalf, it is advisable to govern the relationship with an agreement that defines the roles and responsibilities in the processing.

The privacy notice to owners

The administrator must provide owners with a privacy notice that clearly states the purposes of the processing, the legal basis, the data retention periods and the rights the data subject can exercise, such as access, rectification and erasure. The notice is the document by which the condominium demonstrates that it processes data transparently.

Arrears and posting on the notice board

One of the most delicate aspects concerns owners in arrears. The administrator can communicate information on arrears within the condominium, but the Garante has clarified that data on defaulters cannot be posted on the notice board or in other common spaces accessible to third parties too. Posting it in an area open to the outside breaches the principles of relevance and proportionality. The same principle applies to meeting minutes intended for absentees, which must not be displayed publicly. The correct route is to communicate information on arrears individually to the owners entitled to it, for example by sending the financial statement or during the meeting, and not by public display.

Video surveillance of common parts

Installing cameras on common parts requires a resolution of the meeting with the majority set by law. The presence of the system must be signalled with visible signs placed in the filmed areas or nearby. Recording must be limited to common spaces, the retention of images must be reduced to the strictly necessary time and access to the footage must be limited to authorised persons.

Data breaches and data retention

In the event of a personal data breach that entails a risk to the data subjects, the GDPR requires notifying the Garante within 72 hours of discovery and, in the most serious cases, informing the data subjects too. The administrator must also keep data only for the time needed for the management purposes and legal obligations, avoiding retaining documentation beyond the applicable periods. On termination of the appointment, the data and documents must be handed over to the new administrator or to the condominium, without the outgoing administrator keeping copies beyond what is strictly necessary to defend against any disputes.

Managing condominium privacy with software

Complying with the GDPR means controlling who accesses the data, for which purposes and for how long it is kept. Condominium management software helps limit access by role, send communications to individual owners without exposing the data to others and keep documents in a structured way. AmministraPro manages personal records and communications with role-based access, so that each owner sees only their own data. You can see how it works on the features page or compare the plans in the pricing section.

Manage your buildings with AmministraPro

Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.