Choosing software
Condominium software DPA: what the agreement must contain
By entrusting the condominium's data to software, the manager creates a relationship governed by Article 28 of the GDPR: whoever supplies and runs the platform processes personal data on behalf of the controller and becomes the data processor. This relationship must be formalized in a written agreement, often called a DPA or processor appointment agreement. Before signing a contract, it is worth checking that the vendor provides one and that it contains all the required elements. A missing or generic DPA is a real risk for the manager, who remains accountable to the owners.
Elements the agreement must include
- Subject matter, duration, nature and purpose of the processing
- Types of data and categories of data subjects involved
- Obligation to process data only on the controller's instructions
- Confidentiality commitment for those who access the data
- Technical and organizational security measures adopted
- Conditions for engaging sub-processors
- Assistance to the controller for data subject requests and breaches
- Deletion or return of data at the end of the relationship
- Willingness to provide evidence of compliance with obligations
Who is controller and who is processor
In the condominium the data controller is typically the condominium itself, while the manager acts under the mandate received. The software vendor, which hosts and runs the data, is the processor because it operates on behalf of the controller. Clarifying these roles is not a formality: it defines who answers for what and which instructions the vendor must follow.
Article 28 requires the relationship between controller and processor to be governed by a contract or other legal act. It is therefore not optional. If a vendor offers a subscription with no document on data processing, the manager signs unprotected and takes on a risk that could have been avoided.
The non-negotiable clauses
A complete agreement describes precisely what the vendor may and may not do with the data. It must bind the processor to handle data only on the controller's documented instructions, to guarantee the confidentiality of authorized personnel, and to adopt adequate security measures. It must also govern sub-processors, meaning any suppliers the platform relies on.
Equally important is assistance to the controller. The vendor must help the manager respond to owner requests, such as access or erasure, and manage any data breach. Finally it must set out what happens to the data on termination: return or deletion, according to the controller's choice.
- Processing only on the controller's instructions, never for the vendor's own purposes.
- Prompt notification to the controller in the event of a data breach.
- Return or deletion of data at the end of the contract, with written confirmation.
- The controller's right to obtain information and, where provided, checks on compliance.
What answer to expect from the vendor
A serious vendor provides the DPA without hesitation, often already attached to the contract, and agrees to discuss its content. The immediate availability of the document is itself a good sign of organizational maturity. By contrast, a vendor who does not know what a data processing agreement is, or treats it as a technicality, shows an approximate approach to compliance.
Read the text carefully even when it is off the shelf. Verify that the list of sub-processors is available and up to date, that the security measures are described and not merely stated, and that breach notification timelines are defined. An agreement that defers everything to external documents you cannot obtain offers no real guarantee.
After signing: keeping oversight
The DPA is not a task to file and forget. The list of sub-processors can change, security measures evolve, and the vendor should communicate updates. Keep the agreement together with the condominium's record of processing activities, so you can produce it in case of an inspection or an owner request.
AmministraPro provides managers with the processor appointment agreement and documents the security measures applied. You can review the privacy features on the /funzioni page and compare the plans on /prezzi.
Frequently asked questions
Is a DPA really mandatory for condominium software?
Yes. Article 28 of the GDPR requires the relationship between controller and processor to be governed by a contract or other legal act. Since the software vendor processes personal data on behalf of the condominium, the agreement is necessary. Its absence exposes the manager to liability.
Who is the data controller in the condominium?
As a rule the controller is the condominium, the entity that collects data for management purposes, while the manager acts under the mandate received. The software vendor is the processor. It is useful for the roles to be clarified in the agreement with the vendor as well.
Can I modify the clauses proposed by the vendor?
Many vendors use a standard DPA, but additions remain possible. It is reasonable to ask for clarification on the security measures, the list of sub-processors, and the breach notification timelines. A vendor open to discussion offers more assurance than one that refuses any dialogue.
What must the agreement provide for the end of the contract?
It must state that, when the relationship ends, the vendor returns or deletes the data according to the controller's choice, except where the law requires retention. It is good practice to obtain written confirmation that deletion has occurred and to check that it also covers backup copies.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
