Salta al contenuto principale
All articles
Privacy3 min read

Processing condominium suppliers' data under the GDPR

The condominium processes not only owners' data but also suppliers': contacts, tax data, bank details. Here is the legal basis, the notice required and how long they may be kept under the GDPR.

In this guide

When privacy in the condominium comes up, people almost always think of owners' data, but the condominium also processes suppliers' data: the plumber, the cleaning firm, the lift maintainer. Names, contact details, VAT numbers, bank details and tax data end up in the accounts and must be handled in line with the GDPR. The legal basis is generally not consent but the contract and legal obligations, with retention times dictated by tax rules. Let us see how to proceed.

What supplier data the condominium processes

In dealing with a supplier the condominium collects and keeps a range of information: the personal data of the owner or contact person, telephone and email details, VAT number and tax code, bank details for payments, contracts, quotes and invoices. When the supplier is a natural person, such as a professional or a sole trader, this is personal data in every respect, subject to the rules of the GDPR.

Unlike in other contexts, the processing of a supplier's data is not based on consent. The two most solid legal bases, under Article 6 of the GDPR, are the performance of the supply contract, which requires processing the data to manage the engagement and pay the fee, and compliance with legal obligations, in particular tax and accounting ones, which require records to be registered and kept. Consent is not needed because the processing is necessary for these purposes.

The notice to the supplier

The supplier too has the right to receive a notice about the processing of their data. The condominium, through the manager, must set out the purposes, the legal bases, the retention times and the rights that can be exercised. The notice can be provided when the relationship begins, for example together with the contract or the order. It is an often-neglected step, but one that falls fully within the transparency obligations of the GDPR.

Retention times

Documents involving suppliers, such as invoices and contracts, cannot be deleted straight after payment: tax and civil rules require accounting records to be kept for a period of several years, typically ten, under Article 2220 of the Italian Civil Code. At the end of that term, or when the data is no longer necessary for any purpose, it must be deleted or made anonymous. Retention must therefore be calibrated on the legal obligation, not extended indefinitely.

  • Legal bases: performance of the contract and compliance with legal obligations.
  • No consent needed to manage the relationship and issue invoices.
  • Notice to be given when the supply relationship begins.
  • Retention of accounting documents for the period required by law.
  • Deletion or anonymisation once the terms expire.

When the supplier is a data processor

A delicate aspect concerns suppliers who, in order to perform their service, process owners' data on the condominium's behalf. This is the case, for example, of the concierge company, the management software provider or the consultant who processes data. In these situations the supplier acts as a data processor and the relationship must be governed by a specific appointment, required by Article 28 of the GDPR, which defines purposes, instructions and security measures. Not every supplier is a processor: only those who process others' data on the controller's behalf.

Security and access to data

Suppliers' data, including bank details, must be protected from unauthorised access. The manager must restrict access to the people who need it for management, use individual credentials and keep documents in secure environments. Bank details in particular are attractive to fraud and deserve specific care in how they are communicated and stored. Security is not a formal step but a substantive measure required by the GDPR.

Keeping the supplier register, contracts, invoices and their retention deadlines in a single secure environment, with controlled access, simplifies privacy and accounting obligations: AmministraPro manages the supplier register together with the condominium's accounting. The features are described on the features page and the plans on the pricing page.

Topics:processing condominium suppliers dataGDPR supplierscondominium tax data retentioncontract legal basissupplier processor

Manage your buildings with AmministraPro

Accounting, meetings, communications and AI in one Italian software, compliant with UNI 10801 and GDPR.

Written by the AmministraPro Editorial Team

The AmministraPro editorial team closely follows condominium law, accounting and digital tools for administrators and property firms.