Salta al contenuto principale

Practical guide

Data encryption in condominium software

Encryption is the technique that turns data into a sequence unreadable by anyone who does not hold the correct key to decrypt it. In condominium software it protects registries, bank details, amounts and owners' documents during two critical moments: when they travel over the network between the manager's device and the servers, and when they sit in storage. Article 32 of the GDPR expressly lists encryption among the technical measures appropriate to ensure the security of processing. For the manager, the data controller, understanding how the vendor encrypts data does not require advanced IT skills, but the ability to ask the right questions and get documentable answers.

Encryption in transit: protecting data while it travels

Every time the manager opens the software, data moves between their device and the vendor's servers across the network. Without protection, that traffic could be intercepted, for example on an untrusted public network. Encryption in transit, achieved through protected connections, makes that flow unreadable to anyone trying to capture it along the way.

A concrete sign of encryption in transit is the use of addresses that start with the secure protocol and the presence of the padlock in the browser. For a serious service this protection should always be on and impossible to disable, because it concerns every single operation, from reviewing a budget to sending a communication to owners.

Encryption at rest: protecting stored data

Encryption at rest applies when data sits still on the servers, stored in databases and document archives. If an attacker managed to access the infrastructure physically or logically, they would find unreadable information instead of registries and budgets in the clear. It is a second line of defence that complements the protection guaranteed in transit.

Some vendors apply additional encryption to specific, particularly sensitive fields, such as integration credentials for banks or tax portals, keeping them in encrypted form even inside the database. This approach further reduces the risk of unauthorised access, because even someone reading the archive would not obtain usable data.

Encryption keys: where they live and who controls them

Encryption is only as strong as the management of the keys that govern it. Keys should not be stored together with the data they protect, otherwise whoever accesses the archive also obtains the means to decrypt it. A careful vendor separates the custody of keys from the data and limits access to a small number of systems and people.

The manager does not need to know the cryptographic details, but it is useful to know that structured key management exists and that the vendor can describe it in understandable terms. This information is valuable when compiling the record of processing activities required by the GDPR, in the part documenting the security measures adopted.

Encryption is not everything: the role of access and passwords

Encryption protects data from those without the keys, but it does not stop an authorised user with valid credentials from seeing what they can access. That is why encryption should always sit alongside other measures: role-based access profiling, strong passwords, two-factor authentication and activity logging. They are complementary layers, not alternatives.

In practice, data that is encrypted but accessible to anyone with a weak password remains exposed. The security of condominium software comes from the coherent combination of several measures, each covering a different portion of the overall processing risk.

What to ask the vendor before you choose

A software like AmministraPro combines encryption, role-based access and orderly document retention, so the manager has several layers of protection without configuring each one individually. Anyone evaluating a product can review how data security is set up on the features page and compare the plans on the pricing page.

  • Whether data is encrypted in transit on all connections, without exceptions.
  • Whether there is encryption at rest for data stored on the servers.
  • Whether the most sensitive fields, such as integration credentials, receive additional protection.
  • How encryption keys are managed and kept separate from the data.
  • Whether the description of the measures is documentable and reusable in the record of processing activities.
  • How encryption integrates with role-based access and two-factor authentication.

Frequently asked questions

What does it mean that data is encrypted in transit and at rest?

Encrypted in transit means data is made unreadable while it travels over the network between the manager's device and the servers, so it cannot be intercepted along the way. Encrypted at rest means it stays unreadable even when stored on the servers, without the correct key. These are two complementary protections that cover different moments of the processing.

Is encryption required by the GDPR for condominium software?

Article 32 of the GDPR lists encryption among the technical measures appropriate to ensure the security of processing, but it does not impose it in absolute terms: the choice must be calibrated to the risk. Given the nature of condominium data, both personal and financial, encryption is a proportionate and highly recommendable measure for the manager as data controller.

If data is encrypted, do I still need strong passwords and 2FA?

Yes. Encryption protects data from those without the keys, but it does not stop a user with valid credentials from accessing what falls within their remit. Strong passwords, two-factor authentication and role-based access are complementary layers: without them, data that is encrypted but protected by a weak password remains exposed.

Do I need to know the technical details of encryption to choose software?

No. Advanced cryptographic expertise is not required. It is enough that the vendor can clearly and documentably state that data is encrypted in transit and at rest and how the keys are managed. This description also helps the manager fill in the security measures section of the record of processing activities.

Is an Excel file on the office PC encrypted?

Generally not, unless you manually enable a specific protection, often limited to an easily bypassed password. A local file offers neither structured encryption at rest nor traffic protection, and it is accessible to anyone with access to the computer. This is one reason why moving to software designed for security reduces the overall risk.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.