Salta al contenuto principale
All articles
Privacy

The condominium privacy notice: template and contents

A condominium processes residents' personal data every day, and to do so it must inform them. Here is what the condominium privacy notice must contain under the GDPR and how to structure it correctly.

Leggi questo articolo in italiano

The condominium privacy notice is the document by which owners are informed of how their personal data is collected and processed in the management of the building. Names, thousandth shares, amounts due, contact details and sometimes video surveillance images: the volume of information passing through the administrator's hands is considerable, and the General Data Protection Regulation requires the data subjects to be told about it. Here is who must provide it, what it must contain and how to set it up in a compliant way.

Who is the data controller

In the condominium context the data controller is the condominium, as the entity that determines the purposes and means of processing residents' data. The administrator acts as legal representative of the condominium and actually carries out the processing in the exercise of the mandate. The individual owners, on the other hand, are the data subjects, that is the natural persons to whom the data refers. It is also good practice for the owners' meeting to resolve and put in writing the mandate given to the administrator, specifying the purposes, duration and categories of data processed, so as to formalise the relationship from a data protection standpoint too. Clarifying these roles is the prerequisite for drafting a correct notice.

Why the notice is mandatory

The obligation to inform data subjects is set out in articles 13 and 14 of the GDPR. Article 13 applies when data is collected directly from the data subject, article 14 when it comes from another source. In both cases the notice must be provided in a concise, transparent, intelligible form and in clear language. It is not a formality: it is the tool that lets an owner know what happens to their data and exercise their rights.

When the notice must be given

The notice must be brought to the data subject's attention at the very moment the data is collected. In practice it is given when the property unit is purchased or when someone enters the condominium, and made available to all owners in any case. Many administrators attach it to the first suitable communication or publish it in the reserved area, so they can prove at any time that it was made available.

The contents of the condominium privacy notice

A complete notice must set out the elements required by the GDPR. In particular it must state the identity and contact details of the controller, that is the condominium, and of the administrator who represents it; the purposes of the processing and the related legal basis; the categories of data processed; the recipients or categories of recipients to whom data may be disclosed; the retention period; the rights of the data subject and how to exercise them; and the right to lodge a complaint with the supervisory authority.

Purposes and legal basis

Typical purposes are the administrative and accounting management of the condominium, the allocation and recovery of expenses, legal obligations and the management of relations with suppliers and utilities. The legal basis must be identified case by case among the performance of legal obligations, the management of the condominium relationship and, where relevant, legitimate interest.

Categories of data and retention

The categories of data processed must be indicated, such as identity and contact data, thousandth shares and accounting data, as well as any video surveillance images if a system is in place. The retention period must be defined consistently with the purposes and legal time limits, avoiding unjustified indefinite retention.

The rights of owners

The notice must explain the rights the GDPR grants to the data subject: access to their data, rectification, erasure in the cases provided for, restriction and objection to processing, and portability where applicable. It must state whom to contact to exercise them, normally the administrator, and recall the right to lodge a complaint with the supervisory authority, which in Italy is the Garante for the protection of personal data. The controller must respond to the data subject's request without undue delay and in any case within one month, save for justified extensions. A clear section on these points reduces disputes and strengthens residents' trust.

Managing the notice with software

Management software helps keep privacy obligations under control: it collects owners' data in a structured way, allows the notice to be attached and distributed in the reserved area, and tracks who has accessed it. Automating the availability of the document makes it easier to prove compliance, which in data protection matters is as important as compliance itself.

AmministraPro stores owners' data with profiled access and a reserved area for each resident, where documents and communications such as the privacy notice can be published. You can see how it works on the features page or compare the plans in the pricing section.

Manage your buildings with AmministraPro

Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.