Salta al contenuto principale
All articles
Privacy4 min read

The DPO in a condominium: when you really must appoint one

Many managers wonder whether the condominium needs a data protection officer. In most cases the answer is no: here are the three conditions under Article 37 GDPR and where the condominium fits.

In this guide

Does a condominium have to appoint a DPO, the data protection officer? In the vast majority of cases, no. Appointment is mandatory only in the three exhaustive conditions of Article 37 of EU Regulation 2016/679, and an ordinary condominium falls into none of them. This does not mean the condominium is exempt from privacy obligations: it only means that the specific figure of the DPO is not imposed. Let us see why, and when it might still make sense.

What the DPO is and what it does

The DPO, or Data Protection Officer, is a figure introduced by the GDPR with tasks of overseeing compliance, advising the controller and acting as the contact point with the supervisory authority. It is an internal guarantee role that must have specialist expertise and act independently. It should not be confused with the data controller nor with the external processor who handles data on the controller's behalf.

The three cases where appointment is mandatory

Article 37 GDPR requires the designation of a DPO in three situations. The first concerns public authorities and bodies. The second applies when the controller's core activity consists of processing that requires regular and systematic monitoring of data subjects on a large scale. The third is triggered when the core activity consists of large-scale processing of special categories of data, such as health data, or of data relating to criminal convictions.

  • A public authority or body that carries out processing.
  • A core activity involving regular, systematic large-scale monitoring.
  • A core activity involving large-scale processing of special or judicial data.

Why the ordinary condominium stays outside

The condominium is not a public body: it is a private management entity, without legal personality, that administers the common parts under Articles 1117 and following of the Italian Civil Code. Its core activity is neither the systematic monitoring of individuals nor large-scale processing of special data. The data it handles, names, thousandths (millesimi) shares, amounts due, contact details, serve the economic management and do not amount to surveillance. For this reason, under the current reading of the rules, the condominium is not required to appoint a DPO.

Does video surveillance change things?

A video surveillance system on the common parts does not in itself turn the condominium into an entity required to appoint a DPO. A camera at the entrance or in the hallway protects the security of the common parts and does not amount to large-scale monitoring in the sense required by Article 37. The other obligations remain fully applicable: privacy notice, signage, limited retention times and a proportionality assessment. The system calls for rigour, not necessarily a DPO.

Who the data controller is

In the condominium the data controller is the condominium itself, acting through its legal representative, the manager. It is the manager who must ensure compliance with the accountability principle of the GDPR: identifying the legal bases, informing data subjects, adopting adequate security measures and keeping data only for as long as strictly necessary. Even without a DPO, therefore, the chain of responsibility is well defined and rests on the manager as representative.

When it may still make sense to appoint one

Although not mandatory, the voluntary appointment of a DPO can be a prudent choice for complex situations, such as large super-condominiums with extensive technological systems, access-control equipment, digital concierge services and many concentrated processing operations. In these contexts a data protection officer helps to keep order and to demonstrate compliance. Voluntary designation, however, entails the same obligations as the mandatory one, so it should be considered with awareness and not as a mere label.

What the manager must do in any case

The absence of a DPO obligation does not lighten the substance. The manager must prepare the privacy notices, keep the record of processing activities where the conditions apply, limit access to data, formalise the relationship with suppliers who process data on the condominium's behalf and delete information when it is no longer needed. These are the steps that make the difference in the event of a complaint or an inspection, far more than the formal presence of a figure that is not required.

Managing privacy notices, the record of processing, profiled access and communications to owners in an orderly way is easier with software designed for the condominium: AmministraPro brings these tools together in a single environment. The available features are described on the features page and the plans, with their costs, on the pricing page.

Topics:condominium dpodata protection officerarticle 37 GDPRcondominium privacydpo appointment

Manage your buildings with AmministraPro

Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.

Written by the AmministraPro Editorial Team

The AmministraPro editorial team closely follows condominium law, accounting and digital tools for administrators and property firms.