Salta al contenuto principale

Buyer's guide

How to assess the security of condominium software

Condominium management software holds particularly sensitive data: resident and owner records, financial transactions, meeting minutes, supplier contracts, and sometimes information related to arrears or disputes. Before choosing a platform, a property manager should evaluate not only its features but how solidly this data is protected. This guide lists concrete points to check: where data resides, how it is protected in transit and at rest, who can access it, what happens if a device is lost, how backups are handled, and what guarantees the vendor offers regarding GDPR. It is not a list of technical specifications to memorize, but a set of questions to ask whoever is proposing the software.

Checklist for evaluating condominium software security

  1. The vendor clearly states where data is hosted and under what guarantees
  2. Multi-factor authentication is available for accounts with access to accounting data
  3. Distinct roles and permissions exist for property manager, staff and residents
  4. Relevant actions (accounting changes, deletions) are traceable
  5. Backups are automatic, recurring, with a verifiable restore procedure
  6. Building data can be exported if the management software is changed
  7. The vendor provides a data processing agreement (DPA)
  8. A clear privacy notice explains the purposes and methods of processing
  9. Procedures exist for handling resident requests under the GDPR
  10. Vendor staff access to customer data is limited and logged

Where the data resides and who can access it

A first criterion concerns data location: software built on cloud infrastructure hosted by providers with data centers in Europe, or otherwise subject to guarantees adequate under the GDPR, offers stronger protection than local solutions with no redundancy. The property manager should be able to ask this question and receive an unambiguous answer.

Equally important is understanding who, within the vendor itself, can access customer data and for what purpose: limited, logged technical access justified by support needs is very different from unrestricted staff access.

Access control and roles

The security of condominium software depends largely on how user access is managed, not only on the technical robustness of the system. Some elements worth checking:

  • Multi-factor authentication available at least for the property manager and anyone with access to accounting data, so that a compromised password alone is not enough to get in
  • Distinct roles between property manager, office staff and residents: a resident accessing their own portal should not see the accounting data of other residents, and a junior staff member should not necessarily hold the same permissions as the firm's principal
  • Traceability of actions: knowing who changed a piece of data, when, and from which account is useful both for security and for responding to challenges raised at a meeting or during an accounting review

Backups, continuity, and what happens when something goes wrong

A property manager often handles dozens of buildings at once: even partial loss of accounting data or meeting minutes would have significant consequences, both operationally and in terms of accountability to the assembly. It is worth asking the vendor how backups are performed, whether they are automatic and recurring, and whether there is a tested restore procedure, not just a theoretical one.

Data portability also matters: in the event of switching software or ending an administration mandate, it must be possible to export the building's information in a usable format, since accounting records and minutes belong to the condominium, not to the software vendor.

GDPR compliance and roles of responsibility

The property manager processes residents' personal data as data controller, while the software vendor typically acts as data processor under Article 28 of Regulation (EU) 2016/679. It is therefore reasonable to expect the vendor to provide a data processing agreement (DPA), a clear privacy notice explaining how data is processed, and the ability to fulfill data subject requests (access, erasure, portability) required by the GDPR.

A vendor unable to provide this documentation clearly, or that treats it as a secondary detail, should raise concern: accountability toward residents and the assembly remains with the property manager, who therefore has a direct interest in choosing a solid partner on this front. AmministraPro addresses these aspects in a structured way, with distinct controller and processor roles clearly defined in the contractual documentation.

Frequently asked questions

Who is the data controller for residents' data, the property manager or the software vendor?

The data controller is the property manager, since they determine the purposes and methods of processing residents' personal data in carrying out their mandate. The software vendor typically acts as data processor under Article 28 of the GDPR, operating on the controller's instructions. This is why the contract with the vendor should include a data processing agreement (DPA), defining mutual obligations and guarantees.

What happens to the condominium's data if I switch software or stop using the platform?

A serious vendor must guarantee the ability to export accounting data, resident records and meeting minutes in a usable format, because this information belongs to the condominium, not to the software used to manage it. It is worth verifying this before signing a contract, explicitly asking which export formats are supported and whether there are time limits for recovering data after account deactivation.

Is multi-factor authentication really necessary for condominium software?

It is strongly recommended, especially for accounts with access to accounting data and resident payments. A password, however complex, can be intercepted or reused from other compromised services: a second verification factor significantly reduces the risk that unauthorized access will compromise the financial or personal data managed by the administration office.

How do I know if a resident can see other residents' accounting data?

You should verify that the software implements distinct roles with differentiated permissions: a resident accessing their own portal should be able to see their own shares, payments and meeting documents, but not the individual accounting data of other residents. This separation should be explicitly asked of the vendor during evaluation, not assumed.

How does AmministraPro handle these security aspects?

AmministraPro clearly defines controller and processor roles in its contractual documentation, provides a data processing agreement under Article 28 of the GDPR, and implements distinct roles and permissions for property managers, office staff and residents. Anyone evaluating the platform can review features and conditions on the dedicated features and pricing pages.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.