The DPO in a condominium: when you really must appoint one
Many managers wonder whether the condominium needs a data protection officer. In most cases the answer is no: here are the three conditions under Article 37 GDPR and where the condominium fits.
In this guide
Does a condominium have to appoint a DPO, the data protection officer? In the vast majority of cases, no. Appointment is mandatory only in the three exhaustive conditions of Article 37 of EU Regulation 2016/679, and an ordinary condominium falls into none of them. This does not mean the condominium is exempt from privacy obligations: it only means that the specific figure of the DPO is not imposed. Let us see why, and when it might still make sense.
What the DPO is and what it does
The DPO, or Data Protection Officer, is a figure introduced by the GDPR with tasks of overseeing compliance, advising the controller and acting as the contact point with the supervisory authority. It is an internal guarantee role that must have specialist expertise and act independently. It should not be confused with the data controller nor with the external processor who handles data on the controller's behalf.
The three cases where appointment is mandatory
Article 37 GDPR requires the designation of a DPO in three situations. The first concerns public authorities and bodies. The second applies when the controller's core activity consists of processing that requires regular and systematic monitoring of data subjects on a large scale. The third is triggered when the core activity consists of large-scale processing of special categories of data, such as health data, or of data relating to criminal convictions.
- A public authority or body that carries out processing.
- A core activity involving regular, systematic large-scale monitoring.
- A core activity involving large-scale processing of special or judicial data.
Why the ordinary condominium stays outside
The condominium is not a public body: it is a private management entity, without legal personality, that administers the common parts under Articles 1117 and following of the Italian Civil Code. Its core activity is neither the systematic monitoring of individuals nor large-scale processing of special data. The data it handles, names, thousandths (millesimi) shares, amounts due, contact details, serve the economic management and do not amount to surveillance. For this reason, under the current reading of the rules, the condominium is not required to appoint a DPO.
Does video surveillance change things?
A video surveillance system on the common parts does not in itself turn the condominium into an entity required to appoint a DPO. A camera at the entrance or in the hallway protects the security of the common parts and does not amount to large-scale monitoring in the sense required by Article 37. The other obligations remain fully applicable: privacy notice, signage, limited retention times and a proportionality assessment. The system calls for rigour, not necessarily a DPO.
Who the data controller is
In the condominium the data controller is the condominium itself, acting through its legal representative, the manager. It is the manager who must ensure compliance with the accountability principle of the GDPR: identifying the legal bases, informing data subjects, adopting adequate security measures and keeping data only for as long as strictly necessary. Even without a DPO, therefore, the chain of responsibility is well defined and rests on the manager as representative.
When it may still make sense to appoint one
Although not mandatory, the voluntary appointment of a DPO can be a prudent choice for complex situations, such as large super-condominiums with extensive technological systems, access-control equipment, digital concierge services and many concentrated processing operations. In these contexts a data protection officer helps to keep order and to demonstrate compliance. Voluntary designation, however, entails the same obligations as the mandatory one, so it should be considered with awareness and not as a mere label.
What the manager must do in any case
The absence of a DPO obligation does not lighten the substance. The manager must prepare the privacy notices, keep the record of processing activities where the conditions apply, limit access to data, formalise the relationship with suppliers who process data on the condominium's behalf and delete information when it is no longer needed. These are the steps that make the difference in the event of a complaint or an inspection, far more than the formal presence of a figure that is not required.
Managing privacy notices, the record of processing, profiled access and communications to owners in an orderly way is easier with software designed for the condominium: AmministraPro brings these tools together in a single environment. The available features are described on the features page and the plans, with their costs, on the pricing page.
Manage your buildings with AmministraPro
Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.
Written by the AmministraPro Editorial Team
The AmministraPro editorial team closely follows condominium law, accounting and digital tools for administrators and property firms.
Related reading
Photo of a badly parked car: can you post it?
An owner photographs the car left across the courtyard and posts it with its plate in the building's group. Here is why that can breach privacy and how to report it properly.
ReadDashcam in the condominium courtyard: privacy limits
A dashcam that keeps filming while the car is parked in the courtyard also captures neighbours and other cars. Here are the limits between personal security and unlawful surveillance.
ReadCondominium video surveillance: rules, privacy and resolution
Condominium video surveillance requires a resolution of the meeting and compliance with privacy rules. Here are the majority, the signs, the notice and the retention times.
Read