Salta al contenuto principale
All articles
Privacy

Who is the data controller in an Italian condominium

The data controller in a condominium is the condominium itself, while the administrator acts as its representative. Here is how the GDPR splits the roles and what obligations follow.

Leggi questo articolo in italiano

Establishing who is the data controller in a condominium is the starting point for applying the GDPR correctly to condominium management. Obligations, responsibilities and the cost of compliance all depend on this classification. The question comes up often because several parties coexist in a condominium: the community of owners, the administrator and their staff, external suppliers. Let us see how the Regulation distributes the roles and what follows in practice.

What data controller means

The data controller is the party that decides the purposes and means of the processing of personal data, that is, who sets why and how data are collected and used. It is the central figure of the GDPR, the one that bears the main responsibility for ensuring the lawfulness of the processing, informing data subjects and adopting adequate security measures. Correctly identifying the controller is therefore the first step to building compliant management.

In a condominium the controller is the condominium

In a condominium the data controller is the condominium itself, understood as the community of participants, and not the administrator as an individual. It is the condominium, as a management entity, that determines the purposes of processing the owners' data, from personal details to thousandth shares, from arrears to consumption. The administrator is not the autonomous controller of that data: they act on behalf of and in the interest of the condominium community.

The administrator's dual role

The administrator's position is twofold. On one hand, as legal representative of the condominium, they actually exercise the controller's functions: they collect the data, issue the privacy notice, respond to data subjects' requests. On the other, for the activities they carry out at their own office with their own means, they may take on the role of data processor, that is, a party that processes data on behalf of the controller and according to its instructions.

Appointment as data processor

To formalise this second capacity, the meeting should appoint the administrator as data processor with a written agreement under article 28 of the GDPR, setting out the instructions, purposes and security measures to apply. The written act is not a superfluous formality: it clarifies the boundary between the activities carried out as the controller's representative and those carried out with the administrator's own professional organisation.

External data processors

Besides the administrator, third parties often operate in a condominium who process data on behalf of the controller: the company managing a video surveillance system, the payroll consultant for the condominium's employees, the provider of the management software. These parties act as external data processors and must be bound by a contract defining their tasks, instructions and security guarantees, again under article 28 of the GDPR.

The obligations arising from the controller's role

Having clarified that the controller is the condominium, the administrator who exercises its functions must handle a series of concrete obligations.

  • Give owners a clear privacy notice about the processing of their data.
  • Process only the data necessary to manage the common parts.
  • Appoint data processors, internal and external, in writing.
  • Adopt security measures adequate to protect the data.
  • Allow data subjects to exercise their rights.

Who bears the cost of compliance

Because the data controller is the condominium, the cost of privacy obligations relating to the management of the common parts normally falls on the condominium and not on the administrator personally. What belongs instead to the administrator's professional organisation, and therefore to their costs, is bringing their own office into line as a data processor. Distinguishing the roles also helps to allocate expenses correctly.

Video surveillance and more sensitive data

Some processing requires special attention, and the video surveillance of common parts is the most frequent case. Here too the controller remains the condominium, which must install the system only after a resolution of the meeting, display the information signs before the area filmed, limit the recording to what is strictly necessary and keep the footage for a short period, then delete it automatically. The company that technically manages the system acts as an external data processor. The same rigour applies to other sensitive data that may arise in the management, such as health data in requests to remove architectural barriers: it must be processed only when necessary and with reinforced security measures.

Condominium privacy with management software

GDPR-compliant management software helps to meet the controller's obligations: it profiles access to data, stores the privacy notices issued, limits the visibility of information to those entitled to it and tracks operations. The software provider acts as an external data processor and must offer security guarantees and an adequate contract, so as to fit correctly into the chain of responsibilities.

AmministraPro processes the condominium's data with profiled access, managed privacy notices and adequate security measures, as an external data processor serving the condominium as controller. You can see how it works on the features page or compare the plans in the pricing section.

Manage your buildings with AmministraPro

Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.