Practical guide
The GDPR accountability file of a management firm
The accountability principle is at the heart of the GDPR: the controller and the processor must not only follow the rules but be able to demonstrate it at any time. For a condominium management firm this means building an organised file that gathers all evidence of compliance: registers, appointments, contracts, privacy notices, security measures, training records. Without this documentary set, compliance remains an unverifiable claim. This guide explains which documents to collect, how to order them and how to keep them current, with a practical checklist.
Documents to collect in the file
- An up-to-date record of processing activities for the firm's operations.
- Privacy notices given to owners and other data subjects.
- Data processing agreements with processors, including the software vendor.
- Appointments and instructions of internal authorised persons.
- A description of the technical and organisational security measures.
- A data breach register, even if empty.
- Evidence of staff training.
- The data retention and deletion policy.
- Any impact assessments and periodic review minutes.
What accountability means for the firm
Article 5(2) of the GDPR states that the controller is responsible for compliance with the processing principles and must be able to demonstrate it. Acting correctly is not enough: you must be able to prove it with concrete documents. In a condominium the controller is the body of participants, but it is the administrator, through their organisation, who produces and keeps most of the operational evidence.
The accountability file is the container of this evidence. It is not a one-off task but a living archive that grows and updates with the firm's activity. Keeping it organised means being able to respond quickly to a complaint, an owner's request or a supervisory check, without having to reconstruct everything from scratch under pressure.
The core documents
The first block concerns the mapping of processing: the record of activities, which describes what data the firm processes, for what purposes, on what legal bases and for how long. Linked to this are the notices provided to data subjects, which make processing transparent to owners.
The second block concerns relationships with the other parties involved. Vendors processing data on behalf of the controller, such as the software provider, must be governed by a data processing agreement; internally, staff must be appointed as authorised persons and instructed. The file keeps a copy of all these acts, with their dates.
- Processing block: record of activities and privacy notices.
- Relationships block: processor agreements and appointments of authorised persons.
- Security block: technical and organisational measures, breach register.
- Lifecycle block: retention and deletion policy.
- Verification block: training evidence, impact assessments, periodic reviews.
Security, lifecycle and verification
The third block documents the security measures adopted: access control, encryption, backup, credential management. They should be described so that an outsider understands how the firm protects data. The data breach register belongs here too, and must be kept even when no incidents occurred, because its very existence is evidence of organisation.
The fourth block concerns the data lifecycle, with rules on how long to keep data and how to delete or return it when the mandate ends. The last block is verification: staff training evidence, any impact assessments for riskier processing and the minutes of periodic reviews showing that the firm monitors and updates its system.
Keeping the file up to date over time
A file completed once and then forgotten loses value: if the documents do not reflect the real organisation, in case of a check they can even turn against the firm. It helps to set a periodic review, at least annual, in which each document is checked for currency and the revision date is recorded.
Centralising documents in a single digital environment, with reliable dates and controlled access, greatly simplifies maintaining the file. Software that gathers records, documents, communications and deadlines lets you keep many of these proofs together and retrieve them quickly: AmministraPro's features are shown on the /funzioni page and the plans on the /prezzi page.
Frequently asked questions
Is the accountability file expressly required by law?
The GDPR does not use the term file, but Article 5 requires the controller to be able to demonstrate compliance with the processing principles. The file is the practical tool for fulfilling this duty, gathering in an orderly way the documents that prove the firm's compliance.
Should it be kept on paper or digitally?
Both are allowed, but the digital format with reliable dates and controlled access is more practical to update, search and protect. What matters is that the documents are complete, consistent with the real organisation and quickly retrievable in case of a request or check.
Who must keep it, the administrator or the condominium?
The controller is the condominium, but the administrator, who concretely organises the processing, produces and keeps most of the operational evidence. In practice it is the firm that maintains the file for each condominium managed and for the firm's own activities.
How often should the file be reviewed?
There is no fixed deadline, but a review at least annually is a reasonable practice, supplemented by immediate updates when procedures, vendors, staff or regulations change. Each revision should be dated, to show that the file is alive and not a document frozen in time.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
