Condominium Data Breach: 72-Hour Notification
A data breach can also hit a management firm. Here is when the 72-hour notification to the Garante is triggered, when to warn owners and how to document everything.
In this guide
A personal data breach can also strike a management firm: an email sent to the wrong recipient, a lost device, unauthorized access to the management software. When the breach presents a risk to the rights and freedoms of data subjects, the controller must notify it to the Garante without undue delay and, where possible, within 72 hours of becoming aware of it, as provided by Article 33 of EU Regulation 2016/679. In some cases the owner must be warned too.
What a data breach is
The Regulation defines a breach as the destruction, loss, alteration, unauthorized disclosure of or access to personal data, whether accidental or unlawful. No sophisticated cyberattack is needed: in a condominium the most common cases are mundane. A list of debtors sent by mistake to all owners, a lost USB stick with data, portal credentials in the wrong hands, confidential documents made accessible through a configuration error. Recognizing the event as a breach is the first step to handling it correctly.
When notification to the Garante is triggered
Article 33 requires notification to the Garante when the breach may entail a risk to the rights and freedoms of natural persons. If instead the breach is unlikely to present a risk, notification is not due, but the event must still be documented. The risk assessment must be done immediately, considering the type of data involved, the number of data subjects, the possibility that the data may be used harmfully and the reversibility of the breach. When in doubt, many choose to notify out of caution.
The 72-hour deadline
The 72-hour count runs from the moment the controller becomes aware of the breach, not from when the event occurred. If notification takes place beyond 72 hours, it must be accompanied by the reasons for the delay. Phased notification is allowed: if not all information is immediately available, you can notify what is known and supplement later. The key is not to wait for the complete picture before starting, because time is running.
- The 72 hours start from awareness, not from occurrence
- Notification not due if a risk is unlikely, but the event must be documented
- Phased notification allowed when information is missing
- Beyond 72 hours you must justify the delay
What the notification contains
The notification to the Garante must describe the nature of the breach, the categories and approximate number of data subjects and records involved, the contact details of the data protection officer or another contact point, the likely consequences of the breach and the measures taken or proposed to remedy it and mitigate its effects. Preparing a template in advance helps complete the notification quickly at the critical moment, when haste is the enemy of accuracy.
When to warn owners
If the breach entails a high risk to the rights and freedoms of data subjects, Article 34 requires communicating it to the data subjects themselves too, without undue delay, in clear and plain language. The communication serves to enable them to protect themselves, for example by changing a compromised password. The communication is not due if the controller has adopted measures that make the data unintelligible to the unauthorized, such as effective encryption, or if it has taken subsequent measures that avert the high risk.
The breach register
All breaches must be documented in an internal register, including those not notified because risk-free. The register must record the circumstances of the breach, its effects and the measures taken. It serves to demonstrate compliance to the Garante and to build the accountability required by the Regulation. Even a well-handled but undocumented event leaves the firm exposed in case of an audit.
Preventing and reacting with the right tools
The best defense is a mix of prevention and readiness: profiled access, strong credentials, backups, sends with separated recipients and a written procedure to activate in case of an incident. Management software that structures access and archives in an orderly way reduces both the probability of a breach and the time to reconstruct it. AmministraPro applies security measures to condominium data and keeps the archive traceable: the features are described on the /funzioni page and the plans on the /prezzi page, so you are ready if a data breach should occur.
Manage your buildings with AmministraPro
Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.
Written by the AmministraPro Editorial Team
The AmministraPro editorial team closely follows condominium law, accounting and digital tools for administrators and property firms.
Related reading
Photo of a badly parked car: can you post it?
An owner photographs the car left across the courtyard and posts it with its plate in the building's group. Here is why that can breach privacy and how to report it properly.
ReadDashcam in the condominium courtyard: privacy limits
A dashcam that keeps filming while the car is parked in the courtyard also captures neighbours and other cars. Here are the limits between personal security and unlawful surveillance.
ReadCondominium video surveillance: rules, privacy and resolution
Condominium video surveillance requires a resolution of the meeting and compliance with privacy rules. Here are the majority, the signs, the notice and the retention times.
Read