Salta al contenuto principale
All articles
Privacy4 min read

Condominium Data Breach: 72-Hour Notification

A data breach can also hit a management firm. Here is when the 72-hour notification to the Garante is triggered, when to warn owners and how to document everything.

In this guide

A personal data breach can also strike a management firm: an email sent to the wrong recipient, a lost device, unauthorized access to the management software. When the breach presents a risk to the rights and freedoms of data subjects, the controller must notify it to the Garante without undue delay and, where possible, within 72 hours of becoming aware of it, as provided by Article 33 of EU Regulation 2016/679. In some cases the owner must be warned too.

What a data breach is

The Regulation defines a breach as the destruction, loss, alteration, unauthorized disclosure of or access to personal data, whether accidental or unlawful. No sophisticated cyberattack is needed: in a condominium the most common cases are mundane. A list of debtors sent by mistake to all owners, a lost USB stick with data, portal credentials in the wrong hands, confidential documents made accessible through a configuration error. Recognizing the event as a breach is the first step to handling it correctly.

When notification to the Garante is triggered

Article 33 requires notification to the Garante when the breach may entail a risk to the rights and freedoms of natural persons. If instead the breach is unlikely to present a risk, notification is not due, but the event must still be documented. The risk assessment must be done immediately, considering the type of data involved, the number of data subjects, the possibility that the data may be used harmfully and the reversibility of the breach. When in doubt, many choose to notify out of caution.

The 72-hour deadline

The 72-hour count runs from the moment the controller becomes aware of the breach, not from when the event occurred. If notification takes place beyond 72 hours, it must be accompanied by the reasons for the delay. Phased notification is allowed: if not all information is immediately available, you can notify what is known and supplement later. The key is not to wait for the complete picture before starting, because time is running.

  • The 72 hours start from awareness, not from occurrence
  • Notification not due if a risk is unlikely, but the event must be documented
  • Phased notification allowed when information is missing
  • Beyond 72 hours you must justify the delay

What the notification contains

The notification to the Garante must describe the nature of the breach, the categories and approximate number of data subjects and records involved, the contact details of the data protection officer or another contact point, the likely consequences of the breach and the measures taken or proposed to remedy it and mitigate its effects. Preparing a template in advance helps complete the notification quickly at the critical moment, when haste is the enemy of accuracy.

When to warn owners

If the breach entails a high risk to the rights and freedoms of data subjects, Article 34 requires communicating it to the data subjects themselves too, without undue delay, in clear and plain language. The communication serves to enable them to protect themselves, for example by changing a compromised password. The communication is not due if the controller has adopted measures that make the data unintelligible to the unauthorized, such as effective encryption, or if it has taken subsequent measures that avert the high risk.

The breach register

All breaches must be documented in an internal register, including those not notified because risk-free. The register must record the circumstances of the breach, its effects and the measures taken. It serves to demonstrate compliance to the Garante and to build the accountability required by the Regulation. Even a well-handled but undocumented event leaves the firm exposed in case of an audit.

Preventing and reacting with the right tools

The best defense is a mix of prevention and readiness: profiled access, strong credentials, backups, sends with separated recipients and a written procedure to activate in case of an incident. Management software that structures access and archives in an orderly way reduces both the probability of a breach and the time to reconstruct it. AmministraPro applies security measures to condominium data and keeps the archive traceable: the features are described on the /funzioni page and the plans on the /prezzi page, so you are ready if a data breach should occur.

Topics:condominium data breachGarante notification 72 hoursArticle 33 GDPRcommunication to data subjectsdata breach register

Manage your buildings with AmministraPro

Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.

Written by the AmministraPro Editorial Team

The AmministraPro editorial team closely follows condominium law, accounting and digital tools for administrators and property firms.