Software choice
How to assess the GDPR compliance of a condominium platform
When a manager adopts a platform, they entrust a vendor with residents' personal data: names, shares, arrears situations, sometimes sensitive information linked to resolutions such as barrier removal. Under the GDPR the condominium is the data controller and the manager the processor, while the software vendor that stores and processes the data becomes in turn a processor, to be appointed with a contract compliant with Article 28 of EU Regulation 2016/679. Assessing GDPR compliance is therefore not a technical detail but a precise selection criterion. This guide explains what to ask the vendor and how to verify it before entrusting it with the data.
What to verify on GDPR compliance
- The vendor provides a data processing agreement under Article 28
- It is clear where the data is stored and in which data centres
- Any sub-processors handling the data on the vendor's behalf are indicated
- Data is encrypted and the technical security measures are described
- A permission system limits data access by role
- It is tracked who accesses the data and with what privileges
- The vendor supports obligations such as the processing register under Article 30
- The app shows each resident only their own data, by minimization
- There is a process to respond to data access or deletion requests
GDPR roles: who is controller and who is processor
The first step in assessing compliance is understanding the roles. In the condominium the data controller is the condominium itself, while the manager acts as processor and, in exercising the mandate, gives instructions on the security measures to adopt. When the manager entrusts the data to management software, the vendor that stores and processes it becomes in turn a processor and must be formally appointed.
This chain of roles is formalised with a contract under Article 28 of the GDPR, which must state the subject, duration and purpose of the processing, the categories of data, the processor's obligations, the security measures and any sub-processors. A serious vendor provides this agreement without the manager having to insist: its presence and completeness are a first indicator of compliance.
Where the data is stored and who accesses it
A concrete question to ask during the choice is where the data is physically stored. Knowing in which data centres it resides, whether within the European Union or elsewhere, is relevant because transferring data outside the European Economic Area is subject to precise GDPR rules. A vendor that answers vaguely on this point should be treated with caution.
Equally important is who has access to the data. Ask the vendor which of its staff have administration privileges, whether an access log tracks who consults the data and with which permissions, and what measures prevent unauthorised access. Access traceability is not a technical nicety: it is proof that the vendor controls who touches residents' data.
Technical security measures
The GDPR requires technical and organisational measures appropriate to protecting the data. In a platform these measures translate into verifiable aspects: encryption of the data, both in transmission and at rest, regular backups to avoid losing data in case of a failure, and robust authentication for account access, ideally with a second factor.
The permission system is a security measure as much as encryption, because limiting data access to those who truly need it is the minimization principle under the GDPR. A well designed platform lets you assign collaborators permissions differentiated by role and shows each resident, through the app or resident area, only their own data and the shared documents, never the accounting position of others.
Support for the manager's obligations
Compliance is not only the software's: the manager remains a processor and has their own obligations, such as keeping the processing register required by Article 30 of the GDPR. A good vendor does not just be compliant, but supports the manager by providing documentation useful for completing the register, information on the measures adopted and templates for the privacy notice to residents.
The rights of data subjects should also be considered: a resident can request access to their data or its rectification, and the platform should facilitate handling these requests. Verifying that the vendor has a process for managing any data breaches and notifying them within the times required by the Regulation completes the assessment of compliance as a selection topic and not just a formal obligation.
How to verify it during the choice
GDPR compliance is assessed with precise questions, not generic statements. During the choice it is worth asking the vendor for the Article 28 contract, the documentation on security measures, the list of sub-processors and the location of the data centres. The answers, in clarity and completeness, say a lot about the vendor's seriousness.
It is also useful to check alignment with UNI 10801, the Italian technical standard for condominium managers, whose 2024 version includes guidance on the correct handling of personal data: not a legal obligation but a quality reference in the sector. AmministraPro encrypts data, offers a role based permission system and supports the manager's privacy obligations; the features and pricing pages let you verify the measures available at each level before entrusting the data.
Frequently asked questions
Is the platform vendor a controller or a processor?
It is a processor. In the condominium the controller is the condominium itself and the manager acts as processor; when they entrust the data to management software, the vendor that stores and processes it becomes in turn a processor and must be appointed with a contract compliant with Article 28 of the GDPR. Verifying that this agreement exists and is complete is the first step in assessing the vendor's compliance.
Why does it matter to know where the data is stored?
Because transferring personal data outside the European Economic Area is subject to precise GDPR rules, and a condominium has the right to know where its data ends up. A vendor that clearly states in which data centres the data resides, and whether within the European Union, gives an added guarantee. A vague answer on this point is a signal that advises caution in the choice.
Is data encryption mandatory for condominium software?
The GDPR does not impose encryption as an absolute obligation, but requires technical measures appropriate to the risk, and encryption is among the most effective for protecting personal data. For a platform that stores shares, arrears and sometimes sensitive data, encryption both in transmission and at rest is a reasonable measure to expect. Ask the vendor how data is protected, both in transit and when stored.
Does the permission system relate to GDPR compliance?
Yes, directly. Limiting data access to those who truly need it is the GDPR minimization principle. A compliant platform lets you assign collaborators permissions differentiated by role and shows each resident only their own data, never the accounting position of others. Software that exposes all data to anyone with access violates this principle and is a risk to assess during the choice.
Does the platform shield me from privacy obligations?
No: the manager remains a processor and has their own obligations, such as the processing register under Article 30 and the privacy notice to residents. A good vendor does not replace the manager but supports them, providing documentation on the measures adopted and tools to handle data subject requests. Compliance is a shared responsibility: the software helps, but ownership of the obligations remains with the manager and the condominium.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
