Salta al contenuto principale

Practical guide

Data breach in a condominium: what to do

Property managers handle sensitive personal data every day: resident registries, arrears records, banking details for direct debits, and sometimes even health related data linked to reserved parking spaces or lift access. When this data is lost, stolen, or disclosed by mistake, for instance a mass email sent with every recipient's address visible to everyone else, or unauthorized access to the management software, a personal data breach occurs under Regulation (EU) 2016/679 (GDPR). The regulation sets strict deadlines and precise obligations for the data controller, which in most condominiums is the property manager. This guide walks through what to do in the first hours and in the days following a breach.

First step: assess the severity of the breach

Not every incident must be notified: the GDPR requires notification only when the breach is likely to result in a risk to the rights and freedoms of the residents involved. The property manager must reconstruct what happened: which data was involved, how many people are affected, whether the data was merely exposed or actually accessed by a third party, and what concrete consequences could follow, for example a risk of identity theft if banking details or identity documents were involved.

This assessment should be documented in writing even when the conclusion is that the risk is low or absent: if the supervisory authority ever investigates, the lack of a written assessment is already a point against the manager, regardless of how serious the original incident was.

  • Type of data involved: personal details, banking data, health data, arrears records
  • Number of residents affected and whether the incident is reversible
  • Likelihood that the data was actually read or used by a third party
  • Possible consequences for the individuals: discrimination, identity theft, reputational harm

Notifying the supervisory authority within 72 hours

When a breach is likely to result in a risk to residents, Article 33 of the GDPR requires notifying the competent data protection supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If the notification is submitted later, the delay must be justified.

The notification must describe the nature of the breach, the categories and approximate number of residents and data records involved, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. If not all information is available immediately, the GDPR allows phased notification, provided this is done without undue further delay.

When and how to inform residents

Article 34 of the GDPR requires communicating the breach directly to the affected individuals, meaning the residents, when it is likely to result in a high risk to their rights and freedoms, for example if banking data, health data, or documents suitable for fraudulent use were exposed.

The communication must use clear and plain language, describe the nature of the breach, and provide at least a contact point for further information, along with the likely consequences and the measures taken. It can be delivered through an individual communication, such as a letter or a dedicated certified email, while simply posting a notice on the building noticeboard is not on its own sufficient to ensure that every affected resident is actually informed.

Technical and organizational measures to adopt immediately

After notifying the incident, the property manager must act to contain it and reduce the risk of recurrence: change any compromised access credentials, review the access permissions on the management software, check logs to understand the actual extent of unauthorized access, and consider involving a cybersecurity consultant for more serious incidents.

It is also advisable to update the record of processing activities and the risk assessment tied to that specific processing operation, so that the recorded breach becomes an opportunity to improve the internal procedures of the management practice.

Prevention: reducing the risk before it happens

Prevention starts with simple organizational choices: limit access to sensitive data to staff who genuinely need it, avoid sending mass communications with every recipient's email address visible to the others, use dedicated channels such as certified email for formal communications, and rely on management software that logs access and separates the roles of those who administer data from those who merely consult it.

Management software built for condominium administration, such as AmministraPro, helps on this front because it centralizes registries, communications, and documents in a single environment with access controls, reducing the scattering of data across spreadsheets, personal email accounts, and untracked chats, which are among the most frequent causes of accidental breaches.

Frequently asked questions

Is every IT error in a condominium a data breach that must be reported?

No. A personal data breach occurs when there is a security incident leading to the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data. However, the obligation to notify the supervisory authority only applies when the breach is likely to result in a risk to the rights and freedoms of the residents involved: an error corrected immediately, where no one actually saw the data, may not require notification, but it should still be assessed and documented in writing.

What happens if the property manager fails to report a significant breach?

Failing to meet the notification obligations under Articles 33 and 34 of the GDPR exposes the data controller, in most cases the property manager, to administrative fines from the supervisory authority, along with potential reputational damage toward residents and the risk of compensation claims from individuals who suffered concrete harm.

Does the property manager need to inform every resident or only those affected?

The communication required under Article 34 of the GDPR must be addressed to the individuals actually affected by the breach, not necessarily every resident in the building. However, if it is not possible to reliably identify who was affected, or if the number of affected individuals is very large, a broader communication may be preferable to make sure no one is left uninformed.

Can condominium management software prevent data breaches?

Software such as AmministraPro does not eliminate the risk of human error, but it significantly reduces the opportunities for a data breach to occur, because it centralizes data in a single environment with access controls, avoids scattering registries and documents across untracked tools such as shared spreadsheets or personal email, and makes it easier to keep an orderly record of communications sent to residents.

Is an external consultant needed to handle a data breach in a condominium?

It is not a legal requirement in every case, but for breaches involving a large number of residents, banking or health data, or prolonged unauthorized access, it is advisable for the property manager to work with a data protection consultant, both to properly assess the risk and to draft the notification to the supervisory authority and the communication to affected residents.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.