Regulation
GDPR in the condominium: what the manager must know
A condominium manager handles personal data of residents every day: registry details, ownership shares, arrears situations, sometimes images from surveillance systems. The European data protection regulation, the GDPR, applies to condominiums too, and the manager occupies a specific role within it. Good intentions are not enough: a correct privacy notice, clear rules on who can see which data, and orderly document handling, both paper and digital, are all required. This guide clarifies roles, the main obligations, and how management software can help keep everything organized, without replacing legal advice when a specific case calls for it.
Who is the data controller in a condominium
In a condominium, the data controller is the condominium itself, as a governance entity, represented by the assembly and, in day to day operations, by the manager. The manager acts as the person who processes data on behalf of the condominium in exercising the mandate received under articles 1129 and 1130 of the Italian Civil Code: keeping the resident registry, handling accounting, and communicating with residents and suppliers.
This means the manager is not an outside party receiving data for an unrelated service, but the figure who actually carries out the processing operations decided in the condominium's interest. From this follows the responsibility to process data only for condominium management purposes, with fairness and proportionality, avoiding the collection of information not needed for the mandate.
The privacy notice to residents: content and timing
The privacy notice should be delivered to residents at the start of the engagement, typically alongside the appointment letter or the first batch of documentation, and kept permanently available, for example attached to the condominium bylaws or published in the software's reserved area. It must state who processes the data, for what purposes (administrative, accounting and tax management, assembly communications), on what legal basis, for how long data is retained, and to whom it may be disclosed.
Recipients should include, where relevant, the condominium's accountant or tax adviser, the bank handling payments, suppliers for technical work, and, in case of arrears, any lawyer engaged for debt recovery. The notice is not a one time formality: it must be updated if purposes or parties involved change, for example when new communication tools or a video surveillance system are introduced.
Video surveillance: specific rules
Installing cameras in common areas requires an assembly resolution with the majorities required for innovations and, before that, a clearly visible sign informing anyone entering the filmed area. Footage should be kept for a limited period proportionate to the security purpose, and access to recordings must be restricted to those who genuinely need it, with a record of who viewed the footage and when.
The manager is not automatically authorized to view footage for purposes unrelated to security, such as checking a supplier's punctuality or settling a dispute between neighbors: use must remain consistent with the purpose stated on the sign and in the resolution. If law enforcement requests footage for a specific matter, handover should follow the applicable procedures, which is worth checking with a lawyer in non routine cases.
Sensitive data and delicate situations
Some information a manager encounters requires particular care: data on disabilities relevant to installing aids or removing architectural barriers, data on arrears and enforcement proceedings, communications about disputes between residents. This data should be shared only with those formally involved in the relevant decision, such as the assembly for resolutions concerning it, and not posted on common notice boards or condominium chats accessible to everyone.
Even assembly notices and minutes, which often name residents in arrears for debt recovery resolutions, need careful handling: naming them is legitimate because it serves the resolution, but circulating the same list outside the assembly context is not.
The role of management software
Management software such as AmministraPro helps the manager bring order to two areas the GDPR explicitly addresses: who accesses what, and how long data stays archived. Role based access lets the manager distinguish their own access from that of office collaborators, and reserved areas for each condominium keep one building's data from being visible to whoever manages another.
Centralized storage of registries, financial statements and minutes in one environment, with a record of changes, is easier to keep consistent with what the privacy notice states than spreadsheets scattered across several devices. This does not exempt the manager from preparing the correct notice and training any collaborators on proper data use, but it reduces the document sprawl that is among the most common causes of accidental breaches.
Frequently asked questions
Does a condominium manager have to appoint a data protection officer?
Appointing a data protection officer, a DPO, is generally not mandatory for the ordinary management of a condominium, since the GDPR conditions tied to large scale processing or special categories of data as a core activity typically do not apply. It remains worth assessing case by case, for instance for management firms handling a very large number of condominiums with more complex processing: in such cases checking with a privacy consultant is advisable.
Can residents ask to see the data the manager holds about them?
Yes, every resident has the right to access their own personal data processed by the manager, to request correction if inaccurate, and, within limits compatible with the condominium's accounting and tax obligations, to request deletion. The request should be fulfilled within a reasonable time without generic refusals: management software with a centralized registry makes it faster to locate and extract the requested data.
Is it acceptable to post the list of residents in arrears on the condominium notice board?
No, posting it on a notice board or in any space accessible to anyone, including visitors and suppliers, is not an appropriate way to communicate this. Information about arrears can be brought to the assembly's attention to the extent necessary for the debt recovery resolution, but indiscriminate disclosure exposes the manager and the condominium to a breach of the GDPR's proportionality and data minimization principles.
How long can accounting data and resident privacy notices be retained?
Retention periods for accounting and tax data follow the legal obligations under tax and civil law, which for accounting documentation generally require a multi year retention period. The privacy notice should state these criteria clearly, distinguishing between data needed for current management and data kept only for documentary obligations, avoiding retention beyond what is necessary.
Does software like AmministraPro remove the manager's obligation to draft a privacy notice?
No, no software removes the manager's legal obligation to prepare and deliver a privacy notice to residents, which remains their responsibility, possibly with a consultant's support. A tool like AmministraPro does help on the organizational side though, with centralized registries, role based access and orderly document retention, all of which make it easier to comply with what the notice itself states.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
